User Account Management Device for Single Sign-On Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user account management devices in computer access security allow users to access all accounts and share passwords, compromising security by requiring users to remember multiple passwords and allowing access from any workstation, leading to insecure management of user accounts.
Innovation Solution
A user account management device that cooperates with a single sign-on device to create and manage user accounts centrally, using primary authentication to allow access to applications without sharing passwords, ensuring secure and transparent account management by interfacing directly with the single sign-on device, thus avoiding password transmission to users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users are given access to all their user accounts and passwords, then users can conveniently access multiple applications, but security is compromised as users can share passwords and access from any workstation
Solution Approach 1:
The patent introduces a single sign-on device as an intermediary between users and multiple applications. This device stores user credentials securely and provides authentication without exposing passwords to users. The single sign-on device acts as a mediator that enables convenient access to multiple applications while maintaining security by never transmitting passwords to users or allowing password sharing.
2Reliability
If a single sign-on device is used to securely manage access, then security is improved, but users cannot directly access applications without the single sign-on device
Solution Approach 1:
The single sign-on device provides self-service functionality by automatically authenticating users across multiple applications without requiring manual password entry. The device stores credentials securely and performs authentication operations autonomously, eliminating the need for users to directly access applications with passwords while maintaining convenient access through automatic authentication.
3Device complexity
If user account management is centralized, then account creation and rights management are simplified, but the system becomes more complex requiring integration with single sign-on devices
Solution Approach 1:
The user account management device is designed with universal functionality to work with single sign-on devices. It can create user accounts, manage rights, and interface with single sign-on systems through standardized protocols. This multi-functional design allows the system to perform multiple roles (account creation, rights management, single sign-on integration) without requiring separate specialized systems, thereby reducing overall complexity while maintaining versatility.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a device (MG_PROV) for managing the accounts (CPT) of users of a plurality of applications (APP), which can co-operate with at least one single sign-on device (SSO) that can provide access to at least one application (APP) for at least one user (U) by means of a primary authentication (CFP). The management device (MG_PROV) comprises: a unit (M_RD11) for the primary reading of an identity directory (A_ID) comprising referrer identifiers (UMA) relating to the users (U) of the plurality of applications (APP); a unit (M_CR11) for the primary creation of at least one user account (CPT) for an application (APP); a unit for the primary association (M_ASSOC1) of the created user account (CPT) with the referrer identifier (UMA) of the user (U) for which the user account (CPT) was created; a unit (M_IDT) for determining a reference user database used by the single sign-on device (SSO); a unit (M_RD12) for the secondary reading of an application association table (APP_TAB) comprising the identifiers of the applications provided (APP_ID) and the corresponding application references (APP_SSO) of the applications managed by at least one single sign-on device (SSO); and a unit (M_TX) for sending the single sign-on device (SSO) a message (MSG) containing (i) the created user account (CPT), (ii) a user reference (U_SSO) of the single sign-on device (SSO) corresponding to the user account created (CPT), and (iii) an application reference (APP_SSO) of the single sign-on device (SSO) corresponding to the application (APP) for which the user account (CPT) was created.