Session Security Alignment for Cloud Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, existing single-sign-on solutions struggle to align security token validity periods across different services and systems, leading to potential security vulnerabilities and unnecessary re-authentication, especially when dealing with complex systems and varying security requirements.

Innovation Solution

A computer-implemented method that synchronizes the validity periods of security tokens by setting the second authentication token's validity period equal to the predefined session time specified in the first authentication token, ensuring aligned and secure access to system resources without requiring manual alignment of system settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional single-sign-on solutions are used in cloud computing environments, then users can access multiple systems with one login, but security token validity periods become misaligned across different services causing security vulnerabilities and re-authentication issues

Engineering Contradiction:
Improvesingle sign-on accessVSAvoidsecurity token alignment
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically adjusts the validity period of the second authentication token based on the predefined session time from the first authentication token. Instead of using fixed or default validity periods, the solution makes the token validity dynamic and adaptive to the specific session requirements, ensuring alignment between different authentication tokens across services.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention changes the validity period parameter of the second authentication token to match the predefined session time from the first authentication token. This parameter adjustment ensures that both tokens remain valid for the same duration, preventing security vulnerabilities and re-authentication issues while maintaining single sign-on functionality.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If different validity periods are used for authentication tokens in cloud services, then each service can optimize security independently, but misalignment causes unexpected re-authentication and user inconvenience

Engineering Contradiction:
Improveservice-specific security configurationVSAvoidre-authentication time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary alignment of validity periods by setting the second authentication token's validity period equal to the predefined session time from the first authentication token before the session begins. This preliminary action prevents misalignment issues during the session, eliminating the need for re-authentication and saving user time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual alignment of token validity periods is performed, then security can be maintained, but configuration burden and complexity increase significantly

Engineering Contradiction:
Improvesecurity alignmentVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs automatic alignment of authentication token validity periods without requiring manual configuration. The server automatically sets the second authentication token's validity period based on the predefined session time from the first authentication token, eliminating the need for administrators to manually configure and maintain token alignment across multiple services.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10623185B2Align session security for connected systems
Publication Date: 2020.04.14 WORKDAY INC
  • US10623185B2 patent drawing
  • US10623185B2 patent drawing
  • US10623185B2 patent drawing

AI summary

Granting an aligned secured access to a resource for a client system. A first authentication token and a first validity time period value are received from a first server. The first authentication token includes an authorization for accessing the system resource and the predefined session time. The first authentication token including the predefined session time is sent from the client system to a second server. A second validity period value of a second validity period of a second authentication token for a service provided by the second server to the client system is set equal to the received predefined session time. The second authentication token for the second validity period is sent from the second server to the client system such that an aligned secured access is granted for the client system to the resource.