Unified Authentication Server for Single Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face complexity and security risks due to the need to remember multiple passwords for various Internet services, leading to increased errors and management overhead, as well as inefficiencies and security vulnerabilities when forgetting passwords.

Innovation Solution

Implementing a unified authentication method through an authentication server that allows users to authenticate once, creating a user account and storing information for multiple systems, and providing a token for seamless access across authorized resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users authenticate separately for each service, then each service can verify user identity independently, but users must remember multiple passwords and authentication becomes complex

Engineering Contradiction:
Improveauthentication securityVSAvoiduser authentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple separate authentication systems into a single unified authentication server. This server consolidates user credentials and provides centralized authentication, allowing users to authenticate once and access multiple services without remembering multiple passwords, thereby resolving the contradiction between authentication security and user convenience

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified authentication server implements multi-functionality by serving as the single authentication point for multiple different services. It can authenticate users for various services simultaneously while maintaining the security requirements of each service, making the authentication system universal across the entire service ecosystem

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If users remember multiple passwords, then each service can be accessed securely, but the probability of error increases and management overhead increases

Engineering Contradiction:
Improveservice access securityVSAvoidpassword management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the password management function from individual services and centralizes it in a single authentication server. Users only need to manage one set of credentials stored securely in the authentication server, eliminating the time and errors associated with managing multiple passwords across different services

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If users forget a password, then security is compromised, but the user must wait for administrator help to regain access

Engineering Contradiction:
Improveauthentication securityVSAvoiduser work efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The unified authentication server implements centralized feedback mechanisms where users can receive immediate assistance through a single contact point. When users forget their credentials, the system provides streamlined recovery processes through the authentication server, reducing wait times and maintaining productivity while preserving security through controlled credential reset procedures

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8776201B2Method for implementing unified authentication
Publication Date: 2014.07.08 LENOVO (BEIJING) LTD
  • US8776201B2 patent drawing
  • US8776201B2 patent drawing
  • US8776201B2 patent drawing

AI summary

A method for implementing unified authentication for user logon, the method comprising the steps of: establishing an authentication server; creating a user authentication account number in the authentication server; storing user information which the user uses in a plurality of systems into the authentication server; associating, in the authentication server, the created user authentication account number with the user information which the user uses in the plurality of systems; and providing an authentication flag to the client of the user by the authentication server based on the association between the user authentication account number and the user information which the user uses in the plurality of systems established in the authentication server so that the user can log on the plurality of systems using the authentication flag. The present invention is applied to provide a unified mechanism of user logon authentication in integration and mergence of the service processes provided by a plurality of Internet information systems or Internet providers, and thus the user can access all authorized application systems or service providers with only one logon authentication.