SSO Management Proxy for Cross-Domain Session Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Cross Domain Single Sign On (CDSSO) technologies face issues with asynchronous session lifetimes across integrated applications, leading to disrupted service continuity and poor user experience due to incomplete logout processes, which can compromise security.

Innovation Solution

A Single Sign On management proxy system synchronizes session lifetimes, handles session expiration, and ensures seamless logout across multiple domains by processing user requests and responses, maintaining consistent session management and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional Cross Domain Single Sign On technology is used, then user can access multiple application systems, but session lifetimes are not synchronous across domains leading to service discontinuity

Engineering Contradiction:
Improvecross domain access capabilityVSAvoidservice continuity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a domain trust relationship mechanism as an intermediary between different application systems. This trust relationship acts as a mediator that enables session synchronization across domains without requiring direct integration between each system pair. The intermediary trust framework allows session information to be shared and validated across domain boundaries, ensuring service continuity while maintaining the versatility of cross-domain access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If automatic redirection is used for logout across applications, then logout process is automated, but user experience deteriorates and security issues arise

Engineering Contradiction:
Improvelogout automationVSAvoiduser experience
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The patent implements a feedback mechanism in the logout process where the system monitors user actions and provides appropriate responses. When a user logs out from one application, the system receives feedback about this action and automatically propagates the logout signal to other related applications through the domain trust relationship. This feedback-driven approach maintains automation while improving user experience by ensuring consistent logout behavior across all domains without forcing unwanted redirects.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8621589B2Cross domain single sign on
Publication Date: 2013.12.31 SERVICENOW INC
  • US8621589B2 patent drawing
  • US8621589B2 patent drawing
  • US8621589B2 patent drawing

AI summary

The present application provides a method and system for Cross Domain Single Sign On. The method comprises: receiving a request from a user to a service provider; processing the user request prior to relaying the request to the service provider; forwarding the processed request to the corresponding service provider according to the type of request; in response to receiving a response to the request from the service provider, processing the response, and forwarding the processed response to the user. By adopting the method and system of the present application, a Single Sign On management proxy is introduced as a united management system for a session lifetime of the user. The SSO management proxy manages operations of logging in, checking a session expiration and recovering, logging out, URL mapping, error processing, and access control, and effectively improves the availability, security, functional continuity of the service as well as the user's experience.