Proxy Single Sign-On Identity Service Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience and incompatibility issues when attempting to complete transactions over the Internet, as they often need to separately authenticate with multiple secure parties and manage various identifiers and passwords, especially when these parties are not designed to interact with each other.

Innovation Solution

The implementation of single sign-on techniques using proxy services, where an identity service authenticates a principal and supplies an authentication statement for seamless access to multiple services, allowing proxying of external services and reducing the need for multiple authentications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users separately authenticate with each secure party (vendor, bank, etc.) to complete transactions, then security and independent authentication for each service is maintained, but user convenience and transaction efficiency deteriorate due to multiple authentication requirements and password management

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an identity service as an intermediary between users and multiple secure parties. This identity service acts as a mediator that users authenticate with once, and it then handles authentication with multiple other services on the user's behalf, eliminating the need for users to separately authenticate with each service while maintaining security through the intermediary's management of authentication credentials

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The identity service is designed with universal functionality to handle authentication across multiple different secure parties and services. Instead of requiring separate authentication mechanisms for each service, the identity service provides a single authentication interface that works universally with multiple services, allowing users to access vendor, bank, and other secure parties through one authentication process

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If users maintain separate accounts with multiple services (vendor, bank, etc.), then each service can securely interact with the user independently, but system complexity and time to manage identifiers and passwords increase

Engineering Contradiction:
Improveservice independenceVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate authentication accounts and credentials into a single unified identity service account. Instead of maintaining separate identifiers and passwords for each service (vendor, bank, etc.), users maintain one identity service account that consolidates all authentication credentials, significantly reducing system complexity while preserving the ability to access multiple services

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If services are not preconfigured to interact with each other before transactions commence, then service deployment flexibility is maintained, but transaction completion fails when services need to interact

Engineering Contradiction:
Improveservice deployment flexibilityVSAvoidtransaction completion
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The identity service performs preliminary authentication and establishes trust relationships in advance, creating authentication statements and credentials before transactions commence. This preliminary action ensures that when users need to interact with multiple services during a transaction, the authentication framework is already in place, enabling seamless service interaction without requiring preconfiguration between each service pair

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The identity service acts as a mediator that enables services to interact dynamically during transactions without requiring preconfiguration. Instead of services needing to be预先 configured to communicate with each other, the identity service mediates their interactions by providing authentication statements and credentials on-demand, maintaining deployment flexibility while ensuring transaction reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If users are forced to abort transactions or sign up for new services to complete transactions, then service compatibility requirements are enforced, but productivity and transaction efficiency deteriorate

Engineering Contradiction:
Improveservice compatibilityVSAvoidtransaction efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The identity service provides universal authentication functionality that works across multiple different services and vendors without requiring users to sign up for new services or abandon existing transactions. This universal interface allows users to complete transactions with any service that integrates with the identity service, dramatically improving transaction efficiency while maintaining service compatibility through the intermediary's standardized authentication mechanism

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8327426B2Single sign on with proxy services
Publication Date: 2012.12.04 NETSKOPE INC
  • US8327426B2 patent drawing
  • US8327426B2 patent drawing
  • US8327426B2 patent drawing

AI summary

Techniques for proxing services with a single sign on are provided. A principal authenticates to a first identity service. The first identity service is in a trusted relationship with a second identity service. An authentication request is sent to the second identity service and the request includes an authentication response supplied by the first identity service in response to successful authentication of the principal to the first identity service. In response to the authentication request and the accompanying response, the principal is authenticated for access to the second identity service. Furthermore, targeted services accessible to the second identity service are proxied from and to the principal during interactions between the principal and an external service of that principal.