Unified Credential Authentication Across Enterprise Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in accessing multiple domains of an enterprise with different credentials, leading to complexity for both users and enterprises, as they need to remember distinct logins across various websites, and enterprises struggle to present themselves as a single entity.

Innovation Solution

A method that allows users to access multiple domains of an enterprise by receiving user credentials at one domain, determining their association with other domains, and authenticating them seamlessly, without requiring users to remember specific domain names, using a unified profile that shares and updates credentials across domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users are required to use distinct credentials for each domain, then security and structured access control are improved, but user complexity and difficulty of operation increase

Engineering Contradiction:
Improvesecure accessVSAvoiduser complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple domain-specific credentials into a single unified credential system. Users authenticate once with a single set of credentials, and the system validates access across multiple domains (e.g., ABXZ.com, ABXZ.net, ABXZWireless.com) without requiring separate logins for each domain, thereby reducing user complexity while maintaining security through centralized authentication.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified credential system provides universal access across all enterprise domains. A single user identification and password can be used to access any domain within the enterprise ecosystem, making the authentication system multi-functional and eliminating the need for domain-specific credentials, thus improving ease of operation without compromising security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If users are required to remember distinct logins for each domain, then access control precision is improved, but user burden and time consumption increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidtime to authenticate
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by validating user credentials against a centralized authentication server before granting access to any specific domain. This preliminary validation establishes user identity and permissions once, eliminating the need for repeated authentication attempts across multiple domains and reducing the time users spend logging in while maintaining precise access control through pre-established security policies.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If enterprises maintain separate authentication systems for each domain, then domain independence and security management are improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improvedomain independenceVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized authentication server as an intermediary between users and multiple enterprise domains. This intermediary handles all authentication requests, credential validation, and access control decisions centrally, eliminating the need for each domain to maintain separate authentication systems. The intermediary preserves domain independence by routing users to appropriate domains while reducing overall system complexity through centralized management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8677451B1Enabling seamless access to a domain of an enterprise
Publication Date: 2014.03.18 CELLCO PARTNERSHIP INC
  • US8677451B1 patent drawing
  • US8677451B1 patent drawing
  • US8677451B1 patent drawing

AI summary

A user is allowed to access any of a number of domains associated with an enterprise using a credential for any one of the domains. An exemplary method includes steps of receiving, from a user and at a first domain of the enterprise, a user identification and a password; determining, at the first domain, whether the user identification is associated with the first domain; and upon determination that the user identification is not associated with the first domain, determining, at the first domain, whether the user identification is associated with a second domain of the enterprise. The user identification and the password are authenticated at the first domain, upon determination that the user identification is associated with the second domain. Upon successful authentication, the user is enabled to access the second domain of the enterprise. The user identification does not need to include a character directly reflecting a domain name.