SSO Authentication Mediation Across JWT, SAML, and OAuth

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems face complexity, increased costs, compatibility issues, and user resistance due to multiple authentication processes, complicating integration, maintenance, and compliance efforts.

Innovation Solution

A single sign-on (SSO) authentication system that translates and bridges different authentication processes between entities, using a server with processors to facilitate communication and validation across various authentication protocols like JWT, SAML, and OAuth, ensuring seamless access and data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication processes are implemented to cater to varying security levels, then security flexibility is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity flexibilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication service that mediates between entities with different authentication processes. This service translates and bridges authentication requests between JWT, SAML, and OAuth protocols, allowing entities to maintain their preferred authentication methods while achieving mutual authentication without direct complex integration between them.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication service is designed to support multiple authentication protocols (JWT, SAML, OAuth) within a single system, enabling it to handle diverse authentication requirements universally. This multi-functional capability allows the system to cater to varying security levels while presenting a unified interface to users.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple authentication processes are integrated, then authentication options are improved, but compatibility issues increase

Engineering Contradiction:
Improveauthentication optionsVSAvoidintegration compatibility
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent employs an intermediary service that acts as a compatibility layer between different authentication protocols. This mediator translates authentication requests and responses between JWT, SAML, and OAuth, resolving compatibility issues without requiring direct integration between entities using different protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication service dynamically adjusts protocol parameters and formats based on the specific authentication process being used. It transforms authentication requests into the appropriate format for the target protocol and converts responses back to the original entity's expected format, maintaining compatibility across different authentication systems.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple authentication systems are implemented, then security coverage is improved, but maintenance difficulty increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidmaintenance difficulty
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The patent combines multiple authentication system functionalities into a single centralized authentication service. By merging JWT, SAML, and OAuth capabilities into one system, it reduces the number of separate systems that need maintenance while maintaining comprehensive security coverage across all entities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication service automatically handles protocol translation, validation, and coordination without requiring manual intervention for routine operations. This self-service capability reduces maintenance burden by eliminating the need for manual configuration and coordination between multiple authentication systems.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If multiple authentication processes are used, then security adaptability is improved, but user resistance increases

Engineering Contradiction:
Improvesecurity adaptabilityVSAvoiduser experience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The intermediary authentication service transparently handles the complexity of multiple authentication protocols, presenting a simplified authentication experience to users. Users authenticate through their preferred method without needing to understand or navigate the complexities of multiple authentication systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication complexity from the user interaction layer. The complex protocol translation and coordination happen in the background through the intermediary service, while users experience a simple, unified authentication interface that adapts to their preferences without exposing the underlying complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12526268B2Single sign-on (SSO) authentication system for enabling digital communication between multiple entities
Publication Date: 2026.01.13 LUMENORE INC
  • US12526268B2 patent drawing
  • US12526268B2 patent drawing
  • US12526268B2 patent drawing

AI summary

A system and a method for a single sign-on (SSO) authentication process that enables digital communication between multiple entities. The system includes a server with one or more processors. These processors receive a first authentication request from a first entity to access a second entity, which employs a first authentication process. Based on the request, the processors generate a second authentication request corresponding to the second authentication process used by the second entity. The second authentication request is then communicated to the second entity. After receiving a first response from the second entity, the processors generate a second response corresponding to that first response. This second response is communicated back to the first entity. Upon validating the second response, the processors allow communication between the first and second entities.