Unified Access Role Adaptation Across OIDC and SAML Providers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud service providers face challenges in managing unified access and authorization for third-party software and applications, as they lack control over user authentication protocols like OIDC and SAML, which vary in implementation and metadata usage, leading to inconsistent authorization management across different software and applications.
Innovation Solution
A unified access system that includes a Role Adaptor and Policy Register, enabling centralized management of user roles and authorization through OIDC or SAML federation, allowing cloud providers to delegate authentication to customer-chosen identity providers and manage policies across multiple software and applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the customer chooses their own identity provider (e.g., Azure Active Directory, Google Sign-In, okta), then the customer has flexibility in selecting authentication services, but the cloud provider loses control over what information is passed to software and applications
Solution Approach 1:
The patent introduces an intermediary component between the identity provider and the software/application that standardizes authorization information. This intermediary translates various identity provider formats into a unified authorization structure, allowing customers to choose any identity provider while maintaining consistent authorization management across all applications.
2Ease of operation
If OIDC or SAML protocols are used for federation, then user authentication can be delegated to identity providers, but these protocols are not well designed to delegate management of user authorizations and metadata usage varies between software and applications
Solution Approach 1:
The patent transforms the authorization information structure by extracting and standardizing key parameters from varied OIDC/SAML metadata. It changes the parameter representation from provider-specific formats to a unified authorization model that consistently represents user roles and permissions across all software and applications.
3Adaptability or versatility
If different identity providers are used across customer personnel, then each provider can be optimized for specific needs, but unified management of user authorizations becomes difficult across all software and applications
Solution Approach 1:
The patent creates a universal authorization management layer that works with multiple identity providers simultaneously. This multi-functional system handles authorization standardization across diverse providers, enabling efficient centralized management while maintaining compatibility with various identity provider implementations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and system are devised for providing, by a cloud provider to a customer, a unified access by a user (111) of the customer to a Service Provider (101;) hosted by the cloud provider, wherein the customer establishes a trusted relationship with an Identity Provider (1101). They involve populating, by an administrator (1091) of the customer, a Policy Register (107) with a policy associated with the user, comprising an approved role for the user, and upon a user request to login to the Service Provider (101;): delegating the user authentication and authorization to a Unified Access provider (100) managed by the cloud provider; delegating the user authentication to the Identity Provider (1101); receiving a user identity information authenticated by the Identity Provider (1101), and the policy from the Policy Register (107); adapting the received user identity information so as to include the approved role for the user; and sending the adapted user identity information to the Service Provider (101;). Both delegations may be through either OIDC or SAMI, federation.