Polymorphic Identity Provider Configuration for SaaS Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing shared authorization or authentication protocols face challenges in managing complexity across multiple cloud-hosted software as a service (SaaS) applications, particularly due to varying implementations and frequent changes, leading to unwieldy and unmanageable communication specifications between servers on different domains.

Innovation Solution

The implementation of an identity-provider computer system that breaks down configuration specifications into reusable configuration components with polymorphic properties, allowing for dynamic formation of reply-configuration specifications based on a graph of configuration components, enabling efficient communication of authorization determinations across multiple service providers while accommodating changes and heterogeneity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional shared authorization protocols are used across multiple cloud-hosted SaaS applications, then authentication can be performed across different domains, but the complexity of managing communication specifications becomes unwieldy and unmanageable

Engineering Contradiction:
Improveauthentication across multiple domainsVSAvoidconfiguration management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the configuration specification into reusable configuration components that can be independently managed and combined. Each configuration component represents a modular unit that can be selectively assembled based on the specific service provider and authentication scenario, transforming a monolithic complex specification into manageable segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic configuration specification formation by evaluating relationships between configuration components at runtime. The system dynamically determines which configuration components to combine based on the specific service provider context, allowing the configuration to adapt flexibly to different authentication scenarios without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

2Reliability

If configuration specifications are customized for each service provider implementation, then authentication accuracy is improved, but the time and resources required to manage frequent changes increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoidconfiguration management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-defining reusable configuration components that encapsulate common authentication patterns and relationships. These pre-configured components can be quickly assembled and modified when service provider implementations change, eliminating the need to create entire configuration specifications from scratch and reducing the time required to adapt to frequent changes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables parameter changes by allowing configuration components to be dynamically selected and combined based on service provider-specific parameters. When service provider implementations change, only the relevant configuration component parameters need to be updated rather than the entire specification, making the system responsive to frequent changes while maintaining authentication accuracy.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive configuration specifications are maintained for all service providers, then complete authorization control is achieved, but the system becomes difficult to maintain and scale

Engineering Contradiction:
Improveauthorization controlVSAvoidsystem maintainability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements universality by creating reusable configuration components that can serve multiple service providers across different domains. A single configuration component can be instantiated and combined in various contexts to provide authorization control for different service providers, eliminating the need to maintain separate comprehensive specifications for each provider while preserving complete authorization control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies the nested doll principle by organizing configuration components in a hierarchical structure where smaller configuration elements are nested within larger assemblies. This nested organization allows comprehensive authorization control to be built from fundamental reusable components, making the system easier to maintain by allowing changes at any level of the hierarchy without affecting the entire configuration.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10387498B2Polymorphic configuration management for shared authorization or authentication protocols
Publication Date: 2019.08.20 CA TECH INC
  • US10387498B2 patent drawing
  • US10387498B2 patent drawing
  • US10387498B2 patent drawing

AI summary

Provided is a process including: receiving, from a first service-provider computer system, via a network, with an identity-provider computer system, a request to authenticate a user computing device; forming, with the identity-provider computer system, a first reply-configuration specification from a first plurality of configuration components; determining, with the identity-provider computer system, whether to provide authentication; forming, with the identity-provider computer system, based on the first reply-configuration specification, a reply to the request, the reply including a result of the authentication determination; and sending, with the identity-provider computer system, the reply.