Intermediary Authentication Server for Cross-Protocol Credential Translation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network authentication mechanisms require users to separately authenticate in each authentication domain, which is cumbersome, and the Kerberos Constrained Delegation mechanism cannot be used to access services not configured for cross-domain authentication.
Innovation Solution
A method and system that facilitate authenticated communication between a user device and a service by using an intermediary to obtain credentials based on different authentication protocols, allowing the user device to communicate with services using authentication messages compatible with the service's protocol, even if the service is not configured for cross-domain authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If Kerberos Constrained Delegation is used for cross-domain authentication, then authentication efficiency is improved, but compatibility with services not configured for KCD is lost
Solution Approach 1:
The patent introduces an intermediary authentication server that acts as a mediator between the user device and the service. This intermediary receives authentication requests, obtains credentials from the KCD-configured domain, and translates them into appropriate authentication formats for the target service, thereby enabling compatibility with services not natively supporting KCD
Solution Approach 2:
The authentication system is designed to support multiple authentication protocols and modes simultaneously. The intermediary server can handle both KCD-based authentication for compatible services and alternative authentication methods for non-compatible services, making the system universally applicable across different service types
2Reliability
If separate authentication is required in each authentication domain, then service security is improved, but user convenience deteriorates
Solution Approach 1:
The patent merges multiple authentication operations into a single unified authentication process. The intermediary server consolidates the authentication requests to different domains, allowing the user to authenticate once while the system handles subsequent credential translations automatically, thus maintaining security while improving convenience
3Adaptability or versatility
If protocol translation is performed by the user device, then authentication flexibility is improved, but device complexity increases
Solution Approach 1:
The patent offloads the protocol translation functionality from the user device to an intermediary authentication server. The device only needs to communicate with the intermediary using a standard protocol, while the intermediary handles the complex protocol translation and credential transformation, thereby reducing device complexity while maintaining authentication flexibility
Data Source
AI summary
Embodiments provide methods, devices and computer program arranged to facilitate authenticated communication between a user device and a service associated with a network. One embodiment comprises an apparatus which, in response to authenticating a user device on the basis of a first authentication protocol, transmits a request for a credential of a first type to an authentication server associated with the network via a communications link therebetween, the credential of the first type being for use by the apparatus to obtain a credential of a second type on behalf of the user device from the authentication server. Subsequently, the apparatus transmits a request for a credential of a second type to the authentication server via the communications link therebetween, the credential of the second type being for use by the user device in establishing authenticated communication with the service. The credential of the second type is then transmitted to the user device.


