Unified Access Role Adaptation Across OIDC and SAML Providers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud service providers face challenges in managing unified access and authorization for third-party software and applications, as they lack control over user authentication protocols like OIDC and SAML, which vary in implementation and metadata usage, leading to inconsistent authorization management across different software and applications.

Innovation Solution

A unified access system that includes a Role Adaptor and Policy Register, enabling centralized management of user roles and authorization through OIDC or SAML federation, allowing cloud providers to delegate authentication to customer-chosen identity providers and manage policies across multiple software and applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the customer chooses their own identity provider (e.g., Azure Active Directory, Google Sign-In, okta), then the customer has flexibility in selecting authentication services, but the cloud provider loses control over what information is passed to software and applications

Engineering Contradiction:
Improvecustomer flexibility in choosing identity providerVSAvoidauthorization management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component between the identity provider and the software/application that standardizes authorization information. This intermediary translates various identity provider formats into a unified authorization structure, allowing customers to choose any identity provider while maintaining consistent authorization management across all applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If OIDC or SAML protocols are used for federation, then user authentication can be delegated to identity providers, but these protocols are not well designed to delegate management of user authorizations and metadata usage varies between software and applications

Engineering Contradiction:
Improveauthentication delegationVSAvoidauthorization management consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms the authorization information structure by extracting and standardizing key parameters from varied OIDC/SAML metadata. It changes the parameter representation from provider-specific formats to a unified authorization model that consistently represents user roles and permissions across all software and applications.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If different identity providers are used across customer personnel, then each provider can be optimized for specific needs, but unified management of user authorizations becomes difficult across all software and applications

Engineering Contradiction:
Improveidentity provider selectionVSAvoidauthorization management efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent creates a universal authorization management layer that works with multiple identity providers simultaneously. This multi-functional system handles authorization standardization across diverse providers, enabling efficient centralized management while maintaining compatibility with various identity provider implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4440042B1Method and system for providing unified access to service providers
Publication Date: 2026.02.25 OVH
  • EP4440042B1 patent drawingFigure 1
  • EP4440042B1 patent drawingFigure 2
  • EP4440042B1 patent drawingFigure 3

AI summary

A method and system are devised for providing, by a cloud provider to a customer, a unified access by a user (111) of the customer to a Service Provider (101;) hosted by the cloud provider, wherein the customer establishes a trusted relationship with an Identity Provider (1101). They involve populating, by an administrator (1091) of the customer, a Policy Register (107) with a policy associated with the user, comprising an approved role for the user, and upon a user request to login to the Service Provider (101;): delegating the user authentication and authorization to a Unified Access provider (100) managed by the cloud provider; delegating the user authentication to the Identity Provider (1101); receiving a user identity information authenticated by the Identity Provider (1101), and the policy from the Policy Register (107); adapting the received user identity information so as to include the approved role for the user; and sending the adapted user identity information to the Service Provider (101;). Both delegations may be through either OIDC or SAMI, federation.