Multi-IDP SSO Engine for Unified Workflow Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for complex multi-step workflow journeys, such as electronic lending, are inefficient due to operational redundancies, disjointed processing, high latency, and inconsistent user experiences, lacking integration of disparate operations and systems, and inadequate authentication and data protection technologies.

Innovation Solution

A unified platform comprising integrated frameworks for authentication, dynamic user interface, workflow state management, active data loss prevention, and orchestration, enabling seamless operation across multiple systems and devices, with a modular and scalable architecture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple independent solutions and systems are implemented for complex multi-step workflow journeys, then each specialized processing operation can be performed with its own protocol and standards, but operational redundancies occur, processing becomes disjointed and inefficient, and operating costs increase

Engineering Contradiction:
Improvespecialized processing capabilityVSAvoidprocessing efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent combines multiple independent workflow management systems into a single unified workflow engine that can handle diverse workflow types (student lending, credit card, personal loan, etc.) through a common architecture. This unification eliminates operational redundancies and enables seamless integration while maintaining specialized processing capabilities through configurable workflow definitions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified workflow engine is designed with universal functionality to manage multiple types of workflows across different lending products and operational requirements. It provides a single system that can adapt to various protocols, standards, and processing needs through configuration rather than requiring separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple independent systems are used for different workflow journeys, then each system can be optimized for its specific protocol, but integration between systems becomes difficult and manual coordination is required

Engineering Contradiction:
Improveprotocol complianceVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The unified workflow engine acts as an intermediary layer between different lending systems and operational protocols. It provides a standardized interface that translates between various protocols and standards, enabling integration without requiring direct connections between all systems while maintaining protocol compliance through configurable mappings.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate authentication systems are implemented for each workflow, then security can be tailored to specific requirements, but authentication becomes repetitive and user experience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system is designed with universal functionality to serve multiple workflow types and security requirements through a single unified interface. It implements protocol-agnostic authentication that can adapt to different security protocols (OAuth, SAML, JWT, etc.) while providing consistent single sign-on experience across all lending products and systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Speed

If data is stored in multiple separate databases for different workflows, then data access can be optimized for specific workflows, but data consistency becomes difficult to maintain and latency increases

Engineering Contradiction:
Improvedata access speedVSAvoiddata consistency
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The data architecture segments data storage by workflow type and operational requirements while maintaining a unified data model. This allows optimized access paths for different workflows through configurable data routing, while the underlying unified structure ensures data consistency across all segments through centralized data management and transaction coordination.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12375468B2Single sign-on (SSO) multi-identity provider (IDP) engine
Publication Date: 2025.07.29 CITIZENS FINANCIAL GROUP
  • US12375468B2 patent drawing
  • US12375468B2 patent drawing
  • US12375468B2 patent drawing

AI summary

A unified platform may comprise a combination of independent frameworks that have been integrated and configured to collaboratively operate seamlessly. In some aspects, the unified platform may comprise one or more of an authentication and authorization framework, a dynamic user interface framework, a workflow state management framework, a notification and active data loss and prevention (DLP) engine framework, and an orchestration engine framework. Each of the frameworks included in the unified platform may comprise one or more of the plurality of computing devices executing computer-readable program instructions.