Polymorphic Identity Provider Configuration for SaaS Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing shared authorization or authentication protocols face challenges in managing complexity across multiple cloud-hosted software as a service (SaaS) applications, particularly due to varying implementations and frequent changes, leading to unwieldy and unmanageable communication specifications between servers on different domains.
Innovation Solution
The implementation of an identity-provider computer system that breaks down configuration specifications into reusable configuration components with polymorphic properties, allowing for dynamic formation of reply-configuration specifications based on a graph of configuration components, enabling efficient communication of authorization determinations across multiple service providers while accommodating changes and heterogeneity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional shared authorization protocols are used across multiple cloud-hosted SaaS applications, then authentication can be performed across different domains, but the complexity of managing communication specifications becomes unwieldy and unmanageable
Solution Approach 1:
The patent segments the configuration specification into reusable configuration components that can be independently managed and combined. Each configuration component represents a modular unit that can be selectively assembled based on the specific service provider and authentication scenario, transforming a monolithic complex specification into manageable segments.
Solution Approach 2:
The patent implements dynamic configuration specification formation by evaluating relationships between configuration components at runtime. The system dynamically determines which configuration components to combine based on the specific service provider context, allowing the configuration to adapt flexibly to different authentication scenarios without manual reconfiguration.
2Reliability
If configuration specifications are customized for each service provider implementation, then authentication accuracy is improved, but the time and resources required to manage frequent changes increase
Solution Approach 1:
The patent performs preliminary action by pre-defining reusable configuration components that encapsulate common authentication patterns and relationships. These pre-configured components can be quickly assembled and modified when service provider implementations change, eliminating the need to create entire configuration specifications from scratch and reducing the time required to adapt to frequent changes.
Solution Approach 2:
The patent enables parameter changes by allowing configuration components to be dynamically selected and combined based on service provider-specific parameters. When service provider implementations change, only the relevant configuration component parameters need to be updated rather than the entire specification, making the system responsive to frequent changes while maintaining authentication accuracy.
3Reliability
If comprehensive configuration specifications are maintained for all service providers, then complete authorization control is achieved, but the system becomes difficult to maintain and scale
Solution Approach 1:
The patent implements universality by creating reusable configuration components that can serve multiple service providers across different domains. A single configuration component can be instantiated and combined in various contexts to provide authorization control for different service providers, eliminating the need to maintain separate comprehensive specifications for each provider while preserving complete authorization control.
Solution Approach 2:
The patent applies the nested doll principle by organizing configuration components in a hierarchical structure where smaller configuration elements are nested within larger assemblies. This nested organization allows comprehensive authorization control to be built from fundamental reusable components, making the system easier to maintain by allowing changes at any level of the hierarchy without affecting the entire configuration.
Data Source
AI summary
Provided is a process including: receiving, from a first service-provider computer system, via a network, with an identity-provider computer system, a request to authenticate a user computing device; forming, with the identity-provider computer system, a first reply-configuration specification from a first plurality of configuration components; determining, with the identity-provider computer system, whether to provide authentication; forming, with the identity-provider computer system, based on the first reply-configuration specification, a reply to the request, the reply including a result of the authentication determination; and sending, with the identity-provider computer system, the reply.


