Single Sign-On Policy Server for Disparate Data Stores

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single sign-on systems are not feasible when authentication and authorization information is maintained in multiple disparate data stores, leading to issues with determining the correct authorization information and role-based access, as users may have different IDs and roles across various applications, and data format discrepancies complicate the creation of a unified data store for single sign-on.

Innovation Solution

A system that includes a policy server and a consolidated data store to synchronize internal and external authorization information from multiple data stores, translating and assigning unique identifying attributes to ensure seamless access across multiple applications, using a synchronization component to manage data from disparate formats and maintain role-based authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If multiple disparate data stores are used to maintain authentication and authorization information for different applications, then each application can have its own data store for straightforward access, but users cannot achieve single sign-on capability and must authenticate separately for each application

Engineering Contradiction:
Improvesingle sign-on capabilityVSAvoiddata store architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges multiple disparate data stores into a unified data store that consolidates authentication and authorization information from multiple applications. This unified data store enables single sign-on capability by providing a centralized location for user credentials and authorization data, eliminating the need for separate authentication for each application while managing the complexity through unified data structure and access protocols.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a unified data store as an intermediary component between multiple applications and their respective authentication/authorization data stores. This intermediary consolidates data from disparate sources and provides standardized access interfaces, enabling single sign-on without requiring applications to directly interact with multiple separate data stores, thus reducing operational complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a unified data store is created to enable single sign-on, then users can access multiple applications with one authentication, but data format discrepancies from different source data stores complicate the creation and synchronization process

Engineering Contradiction:
Improvemulti-application accessVSAvoiddata store synchronization
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent applies parameter changes by transforming data from various source formats into a standardized unified format within the consolidated data store. The system modifies data parameters including data structure, encoding formats, and normalization rules to accommodate diverse source data stores while maintaining a consistent interface for single sign-on functionality across all applications.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements preliminary action through a synchronization component that proactively synchronizes and standardizes data from multiple source data stores before they are needed for authentication. This advance synchronization process handles format conversions and data normalization in advance, reducing the complexity during actual authentication operations and enabling seamless multi-application access.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If application-specific data stores are maintained, then authorization information can be easily tailored to each application, but users must provide authentication credentials for each application separately

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidrepeated authentication time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent merges the authentication functionality across multiple application-specific data stores into a unified authentication mechanism. By consolidating user credentials and authorization information in a single unified data store, the system enables users to authenticate once and gain access to multiple applications, dramatically improving authentication efficiency and eliminating the time loss from repeated authentication across different applications.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7496954B1Single sign-on system and method
Publication Date: 2009.02.24 T MOBILE INNOVATIONS LLC
  • US7496954B1 patent drawing
  • US7496954B1 patent drawing
  • US7496954B1 patent drawing

AI summary

A system for single sign-on to a plurality of computing applications is provided. The system includes a plurality of enterprise applications, a policy server, and an authentication data store maintaining authentication information for the enterprise applications. The system also includes internal and external user authorization data stores that maintain user authorization information for the enterprise applications. A synchronization component synchronizes to a consolidated data store information from the internal and external authorization data stores and eliminates duplicate user information. To access a first enterprise application, the user's information is authenticated against the authentication data store and authorized against the consolidated authorization data store. To access a second enterprise application, the user is not required to sign on again since the previously entered user information is used to authenticate the user, and the consolidated data store is automatically checked to determine the user's authorization level for the second enterprise application.