SAML-Based Authentication Federation for Cross-Domain SSO
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for cross-domain single sign-on (SSO) face challenges in sharing authentication results due to limitations in HTTP cookie usage and varying access management methods across different domains, leading to inefficiencies and manual processes in account registration and federation, particularly in large organizations using software as a service (SaaS).
Innovation Solution
An authentication federation system and ID provider device that automates account registration and federation by using a policy-based approach, where user attributes and service usage are stored and managed to determine service access permissions, enabling seamless and non-manual service use across domains through a standardized framework.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If HTTP cookie is used for authentication result sharing, then authentication can be simplified within a single domain, but authentication result cannot be shared across different domains
Solution Approach 1:
The patent introduces a SAML-based authentication federation system as an intermediary mechanism between different domains. Instead of relying on HTTP cookies that are domain-specific, the system uses SAML assertions as a mediator to convey authentication information across domain boundaries, enabling cross-domain SSO while maintaining authentication simplicity.
Solution Approach 2:
The patent changes the fundamental parameter of authentication result transmission from HTTP cookies to SAML assertions. This parameter change enables the authentication mechanism to function across multiple domains rather than being limited to a single domain, resolving the contradiction between simplicity and cross-domain capability.
2Reliability
If access management products are implemented for each domain, then authentication can be managed within individual domains, but additional measures are needed and introduction becomes complex
Solution Approach 1:
The patent implements a universal SAML-based authentication federation system that can be applied across multiple domains without requiring domain-specific access management products. This multi-functional approach allows the same framework to serve different domains, reducing integration complexity while maintaining reliable authentication management.
Solution Approach 2:
By changing from vendor-specific access management implementations to a standardized SAML parameter set, the system achieves cross-domain compatibility without requiring additional domain-specific measures, thereby reducing overall system complexity.
3Reliability
If account federation is performed manually, then account registration can be controlled, but manual processes reduce efficiency and increase time consumption
Solution Approach 1:
The patent implements automated account federation where the system automatically registers and federates accounts across domains without manual intervention. The SAML authentication framework enables self-service account management, maintaining reliable control over account registration while significantly improving efficiency and reducing time consumption.
Solution Approach 2:
The system performs preliminary account federation actions automatically during the authentication process, rather than requiring manual account registration before SSO. This preliminary automated action ensures account readiness while improving overall productivity.
4Adaptability or versatility
If individual accounts are created for each service provider, then user access can be managed separately, but account federation preparations are required before SSO can start
Solution Approach 1:
The patent eliminates the need for preliminary account federation preparations by implementing automated account creation as part of the SAML authentication flow itself. The system performs the necessary account setup actions in advance during the authentication process, eliminating preparation time while maintaining flexible service access management.
Solution Approach 2:
The system enables self-service account federation where accounts are automatically created and federated without manual preparation. This self-service mechanism provides adaptability for service access while eliminating the time loss associated with manual account federation setup.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
According to one embodiment, the ID provider device stores pieces of policy information for each service provider ID. The ID provider device outputs a policy evaluation request including the user ID used in the log-in processing and the service provider ID in the authentication federation request when the log-in processing is successful. The ID provider device reads the policy information in accordance with the service provider ID in the policy evaluation request. The ID provider device judges whether to permit the transmission of the service data in accordance with whether environmental conditions of the user for the execution of a service conform to the read policy information.