Single Request Response Authentication Protocol for Electronic Documents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication protocols for electronic documents in enterprise environments require multiple roundtrip communications between clients and servers, leading to increased latency and reduced authentication bandwidth, complicating load balancing and increasing the burden on servers.

Innovation Solution

A single request and single response authentication protocol is implemented, where the client system sends a single request to authenticate user credentials to a remote server, and the server responds with authentication information, such as a license to access the document, reducing latency and enhancing server authentication capacity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple roundtrip authentication communications are used, then authentication security and verification can be enhanced, but latency increases and authentication bandwidth decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication credentials and configuration information are embedded within the electronic document itself during document creation. This preliminary action allows the client to perform authentication with a single request without needing multiple roundtrip communications, as all necessary verification data is already present in the document.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The electronic document acts as an intermediary carrier that transports authentication credentials, configuration information, and rights management data from the server to the client. This intermediary approach eliminates the need for separate authentication communication rounds by embedding all necessary information within the document structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple roundtrip authentication requests are processed, then comprehensive authentication verification is achieved, but server authentication bandwidth is reduced

Engineering Contradiction:
Improveauthentication verificationVSAvoidauthentication bandwidth
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

All authentication credentials, rights management policies, and configuration data are pre-loaded into the electronic document during document generation. This preliminary preparation enables the server to authenticate clients with a single response operation, dramatically increasing authentication bandwidth without compromising verification security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication verification data is extracted from separate communication exchanges and embedded directly within the electronic document structure. This extraction allows the server to send all necessary authentication information in a single response, eliminating multiple communication rounds and maximizing authentication throughput.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If multiple roundtrip authentication communications are implemented, then thorough credential verification is performed, but system complexity and load balancing difficulty increase

Engineering Contradiction:
Improvecredential verificationVSAvoidauthentication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple authentication verification functions are merged into a single embedded credential structure within the electronic document. This combination consolidates what would require multiple separate communication rounds into one integrated authentication process, simplifying the protocol while maintaining thorough verification security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The complex authentication credentials, rights management policies, and configuration information are all preliminarily organized and embedded within the document structure. This preliminary structuring simplifies the authentication protocol by providing all verification data in a single accessible location, reducing system complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9338166B2System and method for a single request and single response authentication protocol
Publication Date: 2016.05.10 ADOBE INC
  • US9338166B2 patent drawing
  • US9338166B2 patent drawing
  • US9338166B2 patent drawing

AI summary

Various embodiments of a system and method for a single request and single response authentication protocol are described. A client may send to an authentication server a request to authenticate the identity of a user attempting to access an electronic document protected by a rights management policy. The single request may be generated according to rights management configuration information included within the document. Such rights management information may include one or more parameters for requesting authentication from an authentication server. In response to the request, an authentication server may send a single response to the client. The single response may include information indicating that the identity is authenticated (e.g., a license to access the document, or an encryption key to decrypt the document). The client system may be configured to, in response to the single response, provide access to the document according to the rights management policy.