Proxy Server Dual-Session Credential Bridging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single sign-on systems require proxy servers to use a common communications protocol for both establishing and transmitting access credentials, which can disrupt the first communications session and limit protocol flexibility, and do not efficiently manage password changes across multiple terminals.
Innovation Solution
A method that establishes a first communications session between a terminal and a server using any chosen protocol, while a second communications session with a different protocol is used to convey access credentials, allowing the proxy server to verify and transmit these credentials without interrupting the first session, and enables synchronized password changes across all terminals associated with a user.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the proxy server uses a common communications protocol for both establishing the communications session and transmitting access credentials, then the system is simpler to implement, but the first communications session may be disrupted and protocol flexibility is limited
Solution Approach 1:
The patent segments the communication process into two distinct sessions: a first communications session for service communication and a second communications session for credential transmission. This segmentation allows each session to use appropriate protocols independently, preventing disruption to the first session while maintaining system manageability.
Solution Approach 2:
The proxy server acts as an intermediary that manages two separate communications sessions. It receives credentials in the second session and provides them to the server without interrupting the first session between the terminal and server, thus mediating between the need for secure credential transmission and uninterrupted service communication.
2Device complexity
If the proxy server uses a common communications protocol for both establishing the communications session and transmitting access credentials, then the implementation is simpler, but protocol flexibility is limited
Solution Approach 1:
By dividing the communication into separate sessions, the system can select different protocols for each session based on requirements. The first session can use protocols optimized for service communication while the second session uses protocols optimized for secure credential transmission.
Solution Approach 2:
The system dynamically selects protocols for different communication sessions based on their specific requirements. This dynamic approach allows the system to adapt to different service and credential transmission needs without being constrained by a single protocol.
3Productivity
If the proxy server transmits access credentials during the first communications session, then the credential transmission is integrated, but it interrupts the session and reduces efficiency
Solution Approach 1:
The patent separates credential transmission from the main service communication by creating a distinct second communications session. This allows the first session to proceed without interruption, maintaining high efficiency, while credential transmission is handled separately through the proxy server.
Solution Approach 2:
The proxy server mediates credential transmission independently of the service communication session. It receives credentials from the terminal through the second session and provides them to the server without interfering with or interrupting the ongoing first session between terminal and server.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the invention are concerned with providing access credentials associated with a user of a service to a server hosting the service, e.g. enabling single sign on by the user to a number of servers. The embodiments include functionality for establishing a first data connection with a terminal associated with the user and a second data connection with the server, and bridging the first and second data connections in order to establish a first communications session, using a first communications protocol, between the terminal and the server. A second communications session, using a second communications protocol, is also established with the server, via which a request for access credentials associated with the user is received. This request includes information received by the server in the first communications session, which is used to identify access credentials of the user that are transmitted to the server via the second communications session.