Intermediary Authentication Server for Cross-Protocol Credential Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network authentication mechanisms require users to separately authenticate in each authentication domain, which is cumbersome, and the Kerberos Constrained Delegation mechanism cannot be used to access services not configured for cross-domain authentication.

Innovation Solution

A method and system that facilitate authenticated communication between a user device and a service by using an intermediary to obtain credentials based on different authentication protocols, allowing the user device to communicate with services using authentication messages compatible with the service's protocol, even if the service is not configured for cross-domain authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If Kerberos Constrained Delegation is used for cross-domain authentication, then authentication efficiency is improved, but compatibility with services not configured for KCD is lost

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidservice compatibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary authentication server that acts as a mediator between the user device and the service. This intermediary receives authentication requests, obtains credentials from the KCD-configured domain, and translates them into appropriate authentication formats for the target service, thereby enabling compatibility with services not natively supporting KCD

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is designed to support multiple authentication protocols and modes simultaneously. The intermediary server can handle both KCD-based authentication for compatible services and alternative authentication methods for non-compatible services, making the system universally applicable across different service types

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate authentication is required in each authentication domain, then service security is improved, but user convenience deteriorates

Engineering Contradiction:
Improveservice securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple authentication operations into a single unified authentication process. The intermediary server consolidates the authentication requests to different domains, allowing the user to authenticate once while the system handles subsequent credential translations automatically, thus maintaining security while improving convenience

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If protocol translation is performed by the user device, then authentication flexibility is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication flexibilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent offloads the protocol translation functionality from the user device to an intermediary authentication server. The device only needs to communicate with the intermediary using a standard protocol, while the intermediary handles the complex protocol translation and credential transformation, thereby reducing device complexity while maintaining authentication flexibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10148651B2Authentication system
Publication Date: 2018.12.04 MALIKIE INNOVATIONS LTD
  • US10148651B2 patent drawing
  • US10148651B2 patent drawing
  • US10148651B2 patent drawing

AI summary

Embodiments provide methods, devices and computer program arranged to facilitate authenticated communication between a user device and a service associated with a network. One embodiment comprises an apparatus which, in response to authenticating a user device on the basis of a first authentication protocol, transmits a request for a credential of a first type to an authentication server associated with the network via a communications link therebetween, the credential of the first type being for use by the apparatus to obtain a credential of a second type on behalf of the user device from the authentication server. Subsequently, the apparatus transmits a request for a credential of a second type to the authentication server via the communications link therebetween, the credential of the second type being for use by the user device in establishing authenticated communication with the service. The credential of the second type is then transmitted to the user device.