Single Sign-On Server Analyzer Reduces Processing Load

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing single sign-on methods require extensive comparison of multiple modules with network messages for each login, leading to increased processing load on the single sign-on server and complicating the registration of authentication information.

Innovation Solution

A server apparatus with an analyzer unit that determines the authentication scheme and extracts provisional authentication information from login data, storing it for efficient access and reducing server load by using representative authentication information for user access to web servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single sign-on modules are used to store knowledge and a single sign-on server analyzes log-in communication, then single sign-on can be implemented without knowledge of lower-layer technology, but the processing load on the server increases due to extensive comparison of multiple modules with network messages

Engineering Contradiction:
Improveease of single sign-on implementationVSAvoidserver processing load
Core Design Contradiction:
Ease of operationVSPower

Solution Approach 1:

The system performs preliminary analysis of log-in communication messages to extract authentication scheme information and provisional authentication information before actual single sign-on operations. This pre-processing stores authentication patterns in advance, reducing the need for extensive real-time comparison during user logins and thereby decreasing server processing load while maintaining ease of implementation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of authentication information in the form of provisional authentication data that represents variable information. Instead of storing and comparing entire authentication sequences, the system uses representative copies that capture essential authentication patterns, reducing processing requirements while preserving single sign-on functionality

Inventive Principle:
Principle #26Copying

2Loss of information

If a manager collects and analyzes entire log files and URL information from web servers, then necessary authentication information can be gathered, but the complexity of the registration process increases due to required expertise in OS, database, HTML, and HTTP

Engineering Contradiction:
Improvecompleteness of authentication information collectionVSAvoidcomplexity of registration process
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system enables automatic extraction of authentication information from log-in communication messages without requiring manual analysis by managers. The analyzer unit automatically identifies authentication schemes and provisional authentication information from raw communication data, eliminating the need for managers to have expertise in multiple technologies and simplifying the registration process while ensuring complete information collection

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The analyzer unit acts as an intermediary between raw log files and the single sign-on system. It processes and transforms unstructured communication messages into structured authentication information, bridging the gap between raw data and usable authentication credentials without requiring manual intervention or specialized knowledge

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8863263B2Server apparatus and program for single sign-on
Publication Date: 2014.10.14 FUJITSU LTD
  • US8863263B2 patent drawing
  • US8863263B2 patent drawing
  • US8863263B2 patent drawing

AI summary

A server apparatus includes an analyzer unit which analyzes log-in information for a server received from a client, determines an authentication scheme of the server, and extracts, from the log-in information, provisional authentication information in a form representative of variable information. The analyzer unit stores, in the storage device, information representative of the authentication scheme and the provisional authentication information as the variable information. The analyzer unit also stores, in the storage device, as the variable information, authentication information of a user for the server that is associated with representative authentication information of the user.