Multi-domain Authorization via Meta Policy Decision Point
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current multi-domain authorisation and authentication systems face challenges such as reliance on cookies and proxies, which are insecure and inefficient, and limitations in browser capabilities to manage X.509 attribute certificates, making it difficult to achieve seamless cross-domain single sign-on and secure information exchange.
Innovation Solution
The introduction of a meta Policy Decision Point (MPDP) that acts as a centralized location for a user's authorisation and authentication information, allowing users to manage their online persona and securely share session information across domains, using X.509 certificates and CRMF protocols for secure communication and credential management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If X.509 attribute certificates are used for cross-domain authentication, then security is improved, but browser capability limitations make it difficult to manage certificates and achieve seamless single sign-on
Solution Approach 1:
The patent introduces a Policy Information Point (PIP) as an intermediary component that mediates between the browser and the certificate management system. The PIP handles the complex tasks of X.509 attribute certificate generation, validation, and management, while presenting a simplified interface to the browser. This intermediary resolves the contradiction by maintaining high security through proper certificate handling while reducing the operational burden on browsers and users.
2Ease of manufacture
If cookies and proxies are used for multi-domain authentication, then ease of implementation is improved, but security and efficiency deteriorate
Solution Approach 1:
The patent replaces the mechanical proxy-based authentication system with a digital certificate-based system using X.509 attribute certificates. Instead of relying on proxies to intercept and forward authentication requests, the system uses cryptographically secure certificates for direct authentication. This substitution maintains ease of implementation through standardized protocols while significantly improving security by eliminating proxy-related vulnerabilities.
3Reliability
If multiple passwords are required for different domains, then domain security control is improved, but user convenience deteriorates
Solution Approach 1:
The patent implements a universal authentication mechanism using X.509 attribute certificates that can be used across multiple domains. The attribute certificates contain domain-specific attributes that enable the same certificate to serve multiple authentication purposes across different domains. This multi-functionality allows users to maintain strong domain-specific security controls while experiencing improved convenience through reduced password management burden.
4Ease of operation
If centralized credential management is implemented, then user experience is improved, but system complexity increases
Solution Approach 1:
The patent segments the credential management system into distinct functional components: the Policy Information Point (PIP) for certificate management, the Policy Decision Point (PDP) for authentication decisions, and the attribute certificates themselves as portable credentials. This segmentation allows centralized management functionality to be distributed across multiple independent components, improving user experience through unified credential management while reducing overall system complexity through modular design.
Data Source
AI summary
A method of multi-domain authorization/authentication on a computer network comprises: a user making a request to a policy enforcement point of a computer for access to information on the computer; providing a location address for a user's authorization and/or authentication information, a policy decision point of the service on the computer network then verifying the authorization/authentication information; and the user being given access by the PEP to the information or the service requested, if the request is accepted, wherein the user's authorization/authentication and/or further information is located on a meta policy decision point (MPDP).


