Protocol-Agnostic Identity Claim Policy Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems require users to generate separate identity claim policies for each application and use different user interfaces for various authentication protocols, making it cumbersome and error-prone.

Innovation Solution

A protocol-agnostic approach that allows users to define a set of identity claim policies using a single user interface, which can be applied to multiple applications regardless of the authentication protocol implemented, along with transformations to ensure compatibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate identity claim policies are generated for each application and protocol-specific user interfaces are used, then protocol compatibility and application-specific customization are improved, but system complexity and user operation difficulty increase

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal user interface that can handle multiple authentication protocols (SAML, OIDC, etc.) through a single standardized configuration system. The policy definition interface abstracts protocol-specific details, allowing users to define identity claim policies without needing to understand or switch between different protocol interfaces. This multi-functional interface resolves the contradiction by providing protocol-agnostic policy management while maintaining support for various protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary layer (the standardized policy definition interface) between the user and the protocol-specific implementation details. This intermediary translates high-level policy definitions into protocol-specific configurations automatically. The mediator handles the complexity of protocol differences internally while presenting a unified interface to users, thus reducing perceived system complexity while maintaining protocol adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate identity claim policies are generated for each application, then application-specific security requirements are met, but time consumption and operational burden increase

Engineering Contradiction:
Improvesecurity accuracyVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the configuration of identity claim policies across multiple applications into a single unified interface. Users can define policies once and apply them to multiple applications simultaneously, or selectively apply the same policy framework to different applications. This combining approach maintains security accuracy by allowing application-specific customization when needed, while dramatically reducing configuration time through bulk operations and policy reuse.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent enables users to define standardized identity claim policies in advance that can be reused across multiple applications. By creating master policy templates beforehand, users avoid repeating the same configuration work for each application. The system stores these predefined policies and automatically applies them when needed, significantly reducing operational burden and configuration time while maintaining security requirements.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If multiple protocol-specific user interfaces are provided, then protocol-specific functionality is optimized, but ease of operation and learning curve deteriorate

Engineering Contradiction:
Improveprotocol functionalityVSAvoidinterface usability
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements a single universal user interface that provides protocol-agnostic policy definition capabilities. This interface understands multiple protocols (SAML, OIDC, and others) and automatically handles protocol-specific requirements without requiring users to switch interfaces or learn multiple systems. The universal interface maintains protocol functionality by translating standardized policy definitions into protocol-specific configurations, thus preserving productivity while dramatically improving ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of requiring users to adapt to protocol-specific interfaces (traditional approach), the patent inverts the approach by having the system adapt to a single user-friendly interface. The system internally maps the unified user interface to various protocol implementations, reversing the adaptation burden from the user side to the system side. This inversion maintains full protocol functionality while providing a consistent, easy-to-use interface.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP4066458B1Protocol-agnostic claim configuration and verification
Publication Date: 2025.05.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4066458B1 patent drawingFigure 1
  • EP4066458B1 patent drawingFigure 2A
  • EP4066458B1 patent drawingFigure 2B

AI summary

Protocol-agnostic configuration of an identity claim policy that is to be implemented in one or more applications according to one of multiple identity authentication protocols and verification of the protocol-agnostic claims configuration. First, one or more protocol-agnostic identity claim policies are generated and applied to one or more applications. Each of the one or more applications implement one of the multiple identity authentication protocols. For each of the one or more applications, the implemented identity authentication policy is determined. Based on the determined identity authentication protocol, one or more identity claims of the corresponding application that corresponds to the at least one identity claim policy is then construed.