Multi-tenant SSO with Virtual IDP Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multi-tenant single sign-on (SSO) systems face challenges such as contract trust issues, complex configuration, synchronization difficulties, and technical costs related to user attribute management, especially in shared identity provider models, which complicate authentication and access control across multiple service providers.

Innovation Solution

A system and method for multi-tenant SSO identity management with dynamic attribute retrieval, utilizing a virtual IDP framework that includes virtualized public, managed, and exclusive IDPs, allowing for secure and efficient credential management and attribute synchronization through a service provider plug-in hub, eliminating the need for federation and reducing technical complexities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a shared identity provider model is used for multi-tenant SSO, then authentication credentials can be reused across multiple service providers, but contract trust issues and complex configuration arise

Engineering Contradiction:
Improveauthentication credential reuseVSAvoidconfiguration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the shared identity provider into multiple virtual IDPs, each virtual IDP representing a specific service provider or tenant. This segmentation allows credentials to be reused across service providers while isolating configuration complexity into manageable, provider-specific units rather than requiring complex global configuration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a SSO dispatcher as an intermediary component that manages authentication requests between users, virtual IDPs, and service providers. The dispatcher handles credential verification, attribute retrieval, and authentication token management, thereby reducing the configuration burden on individual service providers and simplifying the overall SSO setup.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If federation is implemented for SSO across service providers, then access control can be established, but synchronization difficulties and technical costs increase

Engineering Contradiction:
Improveaccess controlVSAvoidsynchronization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates virtual copies of identity provider functionality through virtual IDPs that can be deployed independently for each service provider or tenant. These virtual IDPs maintain local copies of authentication logic and attribute schemas, eliminating the need for continuous synchronization with a central federation authority while maintaining reliable access control.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs preliminary configuration of authentication attributes, schemas, and credentials during the virtual IDP setup phase rather than requiring ongoing synchronization. Attribute schemas are defined in advance, and credentials are pre-configured, allowing rapid deployment without continuous federation synchronization overhead.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If user attributes are dynamically retrieved for each service provider, then authentication flexibility improves, but attribute management complexity increases

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidattribute management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements local quality by allowing each virtual IDP to have its own customized attribute schema and credential verification logic tailored to specific service provider requirements. This enables flexible, adaptive authentication for each provider while keeping attribute management localized to individual virtual IDPs rather than requiring centralized management of all attributes across all providers.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent enables dynamic retrieval of user attributes from the service provider's own data sources during authentication, allowing attribute schemas to be flexible and adaptable to different service providers' needs. The SSO dispatcher dynamically queries attributes based on the specific virtual IDP and service provider context, providing versatility without requiring pre-configured static attribute management.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10749856B2System and method for multi-tenant SSO with dynamic attribute retrieval
Publication Date: 2020.08.18 CLOUDBLUE LLC
  • US10749856B2 patent drawing
  • US10749856B2 patent drawing
  • US10749856B2 patent drawing

AI summary

A system and method for multi-tenant single sign-on (SSO) identity management with dynamic attribute retrieval, the system includes at least one service provider, at least one service provider plug-in, and a service automation platform. A method for multi-tenant SSO identity management with dynamic attribute retrieval, includes the steps of receiving a link to a service provider at an SSO dispatcher, the SSO dispatcher identifying a service, requesting at the SSO dispatcher, user attributes for the at least one service provider, assembling at a service provider handler implementation, a response query, retrieving identity provider credentials from the service automation platform, signing at the SSO dispatcher, a package for a user's authentication, and redirecting the package to the service provider.