Dynamic SSO Session Scope Configuration for Shared Workstations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access management solutions for single sign-on (SSO) sessions lack the ability to dynamically restrict access to specific resources at runtime, leading to potential unauthorized access by other users sharing a computer.

Innovation Solution

An access management system that allows users to select and restrict access to specific resources during the SSO login process, using scope information to configure the session and deny access to unauthorized resources, thereby enhancing security and reducing manual configuration needs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SSO provides broad access to multiple resources after initial login, then user convenience is improved, but security against unauthorized access by other users sharing the computer deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic session scope configuration that allows users to adjust their access permissions at runtime based on their current needs. The session scope can be modified from broad to restricted access, enabling the system to adapt between convenience and security requirements as conditions change. This is achieved through configurable session scopes that can be set during login or modified during the session.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If access management systems use shared authentication resources for multiple applications, then system complexity is reduced, but the ability to restrict access to specific resources deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidaccess restriction capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication session into configurable scopes that can independently control access to different resource types. Instead of treating the SSO session as a monolithic unit, the system divides access permissions into configurable categories (e.g., application scopes, resource types) that can be selectively enabled or disabled. This allows fine-grained access control within the shared authentication framework.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access control qualities to different resources within the same SSO session. Each resource or resource category can have its own access permissions configured independently, allowing the system to provide customized access levels for different applications or resource types while maintaining a single shared authentication mechanism.

Inventive Principle:
Principle #3Local quality

3Reliability

If access management solutions configure specific authentication sessions to restrict access, then security is improved, but ease of operation deteriorates due to manual configuration requirements

Engineering Contradiction:
ImprovesecurityVSAvoidease of configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables users to self-configure their own session scopes without requiring administrative intervention. The system provides user-friendly interfaces that allow end-users to select their desired access scope during login or modify it during the session. This self-service capability eliminates the need for manual administrative configuration while maintaining security controls.

Inventive Principle:
Principle #25Self-service

4Manufacturing precision

If resources are designated ahead of time for restricting access, then access control precision is improved, but adaptability to different user scenarios deteriorates

Engineering Contradiction:
Improveaccess control precisionVSAvoidruntime flexibility
Core Design Contradiction:
Manufacturing precisionVSAdaptability or versatility

Solution Approach 1:

The patent transforms static, pre-configured access control into a dynamic system where session scopes can be adjusted at runtime. Users can modify their access permissions based on their current situation, such as switching between broad access when alone and restricted access when sharing the computer. The system maintains precise control over which resources are accessible while adapting to changing user needs throughout the session.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10693859B2Restricting access for a single sign-on (SSO) session
Publication Date: 2020.06.23 ORACLE INT CORP
  • US10693859B2 patent drawing
  • US10693859B2 patent drawing
  • US10693859B2 patent drawing

AI summary

Techniques are disclosed for restricting access to resources accessible in a SSO session. An access management system may provide access one or more resources by implementing an SSO system to provide a SSO session. An SSO session may provide an authenticated user with access to protected resources to which the user is entitled to access. In some instances, a user sharing a computer with other users may want to access a particular protected resource so as to restrict other users sharing the computer from accessing other protected resources accessible to the user in an SSO session. The access management system may enable the user to dynamically choose, such as during login, the protected resources which to restrict and/or permit. Upon successful authentication, a session may be established for only those protected resources that are permitted based on the user's selection, while the other resources are restricted.