Multi-domain Authorization via Meta Policy Decision Point

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-domain authorisation and authentication systems face challenges such as reliance on cookies and proxies, which are insecure and inefficient, and limitations in browser capabilities to manage X.509 attribute certificates, making it difficult to achieve seamless cross-domain single sign-on and secure information exchange.

Innovation Solution

The introduction of a meta Policy Decision Point (MPDP) that acts as a centralized location for a user's authorisation and authentication information, allowing users to manage their online persona and securely share session information across domains, using X.509 certificates and CRMF protocols for secure communication and credential management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If X.509 attribute certificates are used for cross-domain authentication, then security is improved, but browser capability limitations make it difficult to manage certificates and achieve seamless single sign-on

Engineering Contradiction:
ImprovesecurityVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a Policy Information Point (PIP) as an intermediary component that mediates between the browser and the certificate management system. The PIP handles the complex tasks of X.509 attribute certificate generation, validation, and management, while presenting a simplified interface to the browser. This intermediary resolves the contradiction by maintaining high security through proper certificate handling while reducing the operational burden on browsers and users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If cookies and proxies are used for multi-domain authentication, then ease of implementation is improved, but security and efficiency deteriorate

Engineering Contradiction:
Improveease of implementationVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces the mechanical proxy-based authentication system with a digital certificate-based system using X.509 attribute certificates. Instead of relying on proxies to intercept and forward authentication requests, the system uses cryptographically secure certificates for direct authentication. This substitution maintains ease of implementation through standardized protocols while significantly improving security by eliminating proxy-related vulnerabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If multiple passwords are required for different domains, then domain security control is improved, but user convenience deteriorates

Engineering Contradiction:
Improvedomain security controlVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal authentication mechanism using X.509 attribute certificates that can be used across multiple domains. The attribute certificates contain domain-specific attributes that enable the same certificate to serve multiple authentication purposes across different domains. This multi-functionality allows users to maintain strong domain-specific security controls while experiencing improved convenience through reduced password management burden.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If centralized credential management is implemented, then user experience is improved, but system complexity increases

Engineering Contradiction:
Improveuser experienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the credential management system into distinct functional components: the Policy Information Point (PIP) for certificate management, the Policy Decision Point (PDP) for authentication decisions, and the attribute certificates themselves as portable credentials. This segmentation allows centralized management functionality to be distributed across multiple independent components, improving user experience through unified credential management while reducing overall system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7444666B2Multi-domain authorization and authentication
Publication Date: 2008.10.28 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7444666B2 patent drawing
  • US7444666B2 patent drawing
  • US7444666B2 patent drawing

AI summary

A method of multi-domain authorization/authentication on a computer network comprises: a user making a request to a policy enforcement point of a computer for access to information on the computer; providing a location address for a user's authorization and/or authentication information, a policy decision point of the service on the computer network then verifying the authorization/authentication information; and the user being given access by the PEP to the information or the service requested, if the request is accepted, wherein the user's authorization/authentication and/or further information is located on a meta policy decision point (MPDP).