SAML-Based Authentication Federation for Cross-Domain SSO

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for cross-domain single sign-on (SSO) face challenges in sharing authentication results due to limitations in HTTP cookie usage and varying access management methods across different domains, leading to inefficiencies and manual processes in account registration and federation, particularly in large organizations using software as a service (SaaS).

Innovation Solution

An authentication federation system and ID provider device that automates account registration and federation by using a policy-based approach, where user attributes and service usage are stored and managed to determine service access permissions, enabling seamless and non-manual service use across domains through a standardized framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If HTTP cookie is used for authentication result sharing, then authentication can be simplified within a single domain, but authentication result cannot be shared across different domains

Engineering Contradiction:
Improveauthentication simplicityVSAvoidcross-domain compatibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a SAML-based authentication federation system as an intermediary mechanism between different domains. Instead of relying on HTTP cookies that are domain-specific, the system uses SAML assertions as a mediator to convey authentication information across domain boundaries, enabling cross-domain SSO while maintaining authentication simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the fundamental parameter of authentication result transmission from HTTP cookies to SAML assertions. This parameter change enables the authentication mechanism to function across multiple domains rather than being limited to a single domain, resolving the contradiction between simplicity and cross-domain capability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If access management products are implemented for each domain, then authentication can be managed within individual domains, but additional measures are needed and introduction becomes complex

Engineering Contradiction:
Improveauthentication managementVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal SAML-based authentication federation system that can be applied across multiple domains without requiring domain-specific access management products. This multi-functional approach allows the same framework to serve different domains, reducing integration complexity while maintaining reliable authentication management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

By changing from vendor-specific access management implementations to a standardized SAML parameter set, the system achieves cross-domain compatibility without requiring additional domain-specific measures, thereby reducing overall system complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If account federation is performed manually, then account registration can be controlled, but manual processes reduce efficiency and increase time consumption

Engineering Contradiction:
Improveaccount registration controlVSAvoidaccount federation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements automated account federation where the system automatically registers and federates accounts across domains without manual intervention. The SAML authentication framework enables self-service account management, maintaining reliable control over account registration while significantly improving efficiency and reducing time consumption.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary account federation actions automatically during the authentication process, rather than requiring manual account registration before SSO. This preliminary automated action ensures account readiness while improving overall productivity.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If individual accounts are created for each service provider, then user access can be managed separately, but account federation preparations are required before SSO can start

Engineering Contradiction:
Improveservice access flexibilityVSAvoidpreparation time for SSO
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent eliminates the need for preliminary account federation preparations by implementing automated account creation as part of the SAML authentication flow itself. The system performs the necessary account setup actions in advance during the authentication process, eliminating preparation time while maintaining flexible service access management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service account federation where accounts are automatically created and federated without manual preparation. This self-service mechanism provides adaptability for service access while eliminating the time loss associated with manual account federation setup.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2639727B1Authentication collaboration system and id provider device
Publication Date: 2018.02.28 KK TOSHIBA
  • EP2639727B1 patent drawingFigure 1
  • EP2639727B1 patent drawingFigure 2
  • EP2639727B1 patent drawingFigure 3

AI summary

According to one embodiment, the ID provider device stores pieces of policy information for each service provider ID. The ID provider device outputs a policy evaluation request including the user ID used in the log-in processing and the service provider ID in the authentication federation request when the log-in processing is successful. The ID provider device reads the policy information in accordance with the service provider ID in the policy evaluation request. The ID provider device judges whether to permit the transmission of the service data in accordance with whether environmental conditions of the user for the execution of a service conform to the read policy information.