SSO Proxy Access Regulation for Cloud Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users managing multiple cloud computing services face the inconvenience of managing numerous login credentials and the tedious process of logging into each service individually, highlighting the need for enhanced access regulation.

Innovation Solution

A single sign-on (SSO) proxy system that acts as an intermediary to regulate access to cloud services by evaluating additional criteria such as geographic location, time, device type, and application limitations before forwarding authentication requests to the SSO service, thereby providing additional security and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single sign-on service is used to authenticate users for multiple cloud services, then the ease of operation is improved, but the device complexity increases due to the need for an intermediary proxy system

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an SSO proxy system that acts as an intermediary between user systems and cloud services. The proxy receives authentication requests, evaluates them against predefined criteria (geographic location, time, device type, application), and forwards approved requests to the SSO service. This intermediary approach maintains ease of operation for users while adding structured access control, resolving the contradiction by embedding complexity in the proxy layer rather than requiring changes to user interaction flows.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access criteria evaluation is added to the SSO process, then the security is improved, but the productivity decreases due to additional processing steps

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The SSO proxy system performs preliminary evaluation of authentication requests against access criteria before forwarding them to the SSO service. By pre-filtering requests based on geographic location, time, device type, and application parameters, the system enhances security without requiring the SSO service itself to process additional logic. This preliminary action approach improves security while minimizing impact on overall authentication productivity, as the proxy handles evaluation efficiently in advance.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple access criteria are enforced, then the security is improved, but the ease of operation deteriorates due to stricter access control

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The SSO proxy system operates autonomously to evaluate authentication requests against predefined access criteria without requiring user intervention. The proxy automatically checks geographic location, time, device type, and application parameters, making security decisions in the background. This self-service approach enforces multiple access criteria to improve security while maintaining ease of operation, as users experience no additional steps or friction in the authentication process.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11418498B2Single sign on proxy for regulating access to a cloud service
Publication Date: 2022.08.16 PALO ALTO NETWORKS INC
  • US11418498B2 patent drawing
  • US11418498B2 patent drawing
  • US11418498B2 patent drawing

AI summary

Embodiments disclosed herein provide systems, methods, and computer readable media for using a single sign-on proxy to regulate access to a cloud service. In a particular embodiment, a method provides receiving an authentication request from a user system directed to a SSO service and determining whether the authentication request satisfies at least one criterion for allowing access to the cloud service associated with the SSO service. Upon determining that the authentication request satisfies the at least one criterion, the method provides forwarding the authentication request to the SSO service.