Multi-tenant SSO with Virtual IDP Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional multi-tenant single sign-on (SSO) systems face challenges such as contract trust issues, complex configuration, synchronization difficulties, and technical costs related to user attribute management, especially in shared identity provider models, which complicate authentication and access control across multiple service providers.
Innovation Solution
A system and method for multi-tenant SSO identity management with dynamic attribute retrieval, utilizing a virtual IDP framework that includes virtualized public, managed, and exclusive IDPs, allowing for secure and efficient credential management and attribute synchronization through a service provider plug-in hub, eliminating the need for federation and reducing technical complexities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a shared identity provider model is used for multi-tenant SSO, then authentication credentials can be reused across multiple service providers, but contract trust issues and complex configuration arise
Solution Approach 1:
The patent segments the shared identity provider into multiple virtual IDPs, each virtual IDP representing a specific service provider or tenant. This segmentation allows credentials to be reused across service providers while isolating configuration complexity into manageable, provider-specific units rather than requiring complex global configuration.
Solution Approach 2:
The patent introduces a SSO dispatcher as an intermediary component that manages authentication requests between users, virtual IDPs, and service providers. The dispatcher handles credential verification, attribute retrieval, and authentication token management, thereby reducing the configuration burden on individual service providers and simplifying the overall SSO setup.
2Reliability
If federation is implemented for SSO across service providers, then access control can be established, but synchronization difficulties and technical costs increase
Solution Approach 1:
The patent creates virtual copies of identity provider functionality through virtual IDPs that can be deployed independently for each service provider or tenant. These virtual IDPs maintain local copies of authentication logic and attribute schemas, eliminating the need for continuous synchronization with a central federation authority while maintaining reliable access control.
Solution Approach 2:
The patent performs preliminary configuration of authentication attributes, schemas, and credentials during the virtual IDP setup phase rather than requiring ongoing synchronization. Attribute schemas are defined in advance, and credentials are pre-configured, allowing rapid deployment without continuous federation synchronization overhead.
3Adaptability or versatility
If user attributes are dynamically retrieved for each service provider, then authentication flexibility improves, but attribute management complexity increases
Solution Approach 1:
The patent implements local quality by allowing each virtual IDP to have its own customized attribute schema and credential verification logic tailored to specific service provider requirements. This enables flexible, adaptive authentication for each provider while keeping attribute management localized to individual virtual IDPs rather than requiring centralized management of all attributes across all providers.
Solution Approach 2:
The patent enables dynamic retrieval of user attributes from the service provider's own data sources during authentication, allowing attribute schemas to be flexible and adaptable to different service providers' needs. The SSO dispatcher dynamically queries attributes based on the specific virtual IDP and service provider context, providing versatility without requiring pre-configured static attribute management.
Data Source
AI summary
A system and method for multi-tenant single sign-on (SSO) identity management with dynamic attribute retrieval, the system includes at least one service provider, at least one service provider plug-in, and a service automation platform. A method for multi-tenant SSO identity management with dynamic attribute retrieval, includes the steps of receiving a link to a service provider at an SSO dispatcher, the SSO dispatcher identifying a service, requesting at the SSO dispatcher, user attributes for the at least one service provider, assembling at a service provider handler implementation, a response query, retrieving identity provider credentials from the service automation platform, signing at the SSO dispatcher, a package for a user's authentication, and redirecting the package to the service provider.


