Team Authentication Mode Assignment via SSO Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online services face challenges in managing user authentication options, particularly for teams where administrators need to balance between native authentication and third-party single-sign-on, as users often default to native authentication due to cost concerns and security complexities with multiple password management.

Innovation Solution

A service that allows administrators to specify and manage sign-on options for team members, including native-only, single-sign-on only, or both, based on user roles, with tools for testing and configuring single-sign-on providers to ensure seamless authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators implement third-party single-sign-on authentication for teams, then security is improved and password management complexity is reduced, but system complexity increases and cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a single-sign-on provider as an intermediary authentication service between users and multiple online services. This mediator handles the complex password management and authentication processes, allowing users to authenticate once and access multiple services without directly managing multiple passwords, thereby improving security while reducing user-facing complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The single-sign-on provider serves multiple functions: it acts as an authentication server, a password management system, and an access control mechanism across multiple services. By consolidating these functions into a single universal system, the patent reduces overall system complexity while maintaining enhanced security

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If administrators require users to use third-party single-sign-on providers, then security is improved, but ease of operation deteriorates due to setup complexity and cost concerns

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic authentication mode selection where users can switch between native authentication and single-sign-on authentication based on their needs. The system adapts to user preferences and circumstances, allowing easy transition between authentication methods rather than forcing a single static approach, thereby maintaining security while improving ease of operation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system allows users to independently choose and configure their preferred authentication method without requiring administrator intervention for each change. Users can self-manage their authentication preferences and switch between modes as needed, reducing operational complexity while maintaining security benefits

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If administrators provide both native authentication and single-sign-on options, then adaptability is improved, but device complexity increases due to management overhead

Engineering Contradiction:
ImproveadaptabilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into two independent but interoperable components: native authentication handled by the service provider and single-sign-on authentication handled by third-party providers. This segmentation allows administrators to manage each authentication type separately through distinct configuration interfaces, reducing management complexity while maintaining adaptability to support both methods simultaneously

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11106778B2Toggle between accounts
Publication Date: 2021.08.31 DROPBOX INC
  • US11106778B2 patent drawing
  • US11106778B2 patent drawing
  • US11106778B2 patent drawing

AI summary

Techniques are described for enabling administrators of teams that use a particular service to specify which sign-on options, of multiple possible sign-on options, are assigned to the members of the teams to which the administrators belong. For example, an administrator may assign a sign-on option, which allows members of the team to use either native authentication or third-party single-sign-on authentication. Upon successful authentication of a member using third party single sign-on authentication, the member is automatically assigned to use only the third party single sign-on authentication.