Remote User Directory Authentication via Web API Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Migrating management and provisioning of computing resources from on-premise devices to service provider networks while maintaining control over user account information for authentication and authorization is challenging, as existing solutions require maintaining parallel databases and sending sensitive information over networks.
Innovation Solution
A service provider network receives user account information from a subscriber's on-premise user directory via web APIs to authenticate and authorize client devices, allowing subscribers to manage their user account information while leveraging the service provider's computing resources for service delivery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user account information is stored in on-premise directories and accessed by service provider networks, then subscribers maintain control over authentication data, but security risks increase due to network transmission of sensitive information
Solution Approach 1:
The patent extracts only the necessary authentication credentials (username and password) from the on-premise user directory and transmits them to the service provider network for verification. This minimizes the amount of sensitive data transmitted over the network while still enabling authentication, thereby reducing security risks associated with data transmission.
Solution Approach 2:
The service provider network acts as an intermediary between the client device and the on-premise user directory. It receives authentication requests, verifies credentials against the user directory, and returns authentication results without requiring direct access to or storage of the entire user directory, thus reducing network exposure of sensitive information.
2Reliability
If parallel databases are maintained for user authentication, then service provider networks can authenticate users independently, but device complexity and resource requirements increase
Solution Approach 1:
The service provider network maintains a universal authentication mechanism that works with on-premise user directories without requiring separate parallel databases. The authentication system is designed to query external user directories directly, eliminating the need for duplicating user data across multiple databases and reducing overall system complexity.
3Measurement precision
If complete user directory data is transmitted to service provider networks, then authentication accuracy improves, but loss of time and computing resources increase
Solution Approach 1:
The system extracts only the essential authentication elements (username and password) from the complete user directory data and transmits them to the service provider network. This extraction approach maintains authentication accuracy by ensuring the necessary credentials are verified while dramatically reducing the volume of data transmitted and the time required for the authentication process.
Data Source
AI summary
Techniques for a service provider network to authenticate client devices and determine authorizations for users by sending requests for information in remotely managed user directories. The service provider network may provide computing infrastructure to service requests from users who have accounts with a subscriber of the service provider network. The subscriber may maintain user information for the various user accounts usable to authenticate client devices and/or determine authorizations of users. The service provider network may receive a request from a client device to execute a workflow for a service of the subscriber that is supported by resources of the service provider network. The service provider network may send a request to a subscriber device for user account information for authentication and determining authorization. For instance, the service provider network may request a public key to authenticate the client device, and/or authorization information indicating permissions granted for a user account.


