Standardized User Authentication Format for Heterogeneous Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In heterogeneous computer environments, existing authentication methods struggle to identify and authorize users consistently across different repositories, leading to ambiguities and difficulties in credential recognition and management.

Innovation Solution

A method involving unique prefixes, abstract repository names, and user identifiers is introduced to create a standardized authentication scheme, allowing identification of user repository types and origins, enabling consistent user authentication and authorization across diverse systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple different authentication formats are used across heterogeneous systems, then each system can maintain its own authentication strategy, but user identification becomes ambiguous and complex

Engineering Contradiction:
Improveauthentication strategy flexibilityVSAvoiduser identification complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication format that can represent users from multiple different authentication systems (LDAP, Active Directory, UNIX, etc.) through a single standardized structure. The normalized format includes components such as authentication scheme, domain, user ID, and optional attributes, which can accommodate various authentication strategies while maintaining a consistent representation across all systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication format is divided into distinct segments or components, including authentication scheme identifier, domain name, user identifier, and optional attributes. This segmentation allows each component to be independently defined and managed, making it easier to handle different authentication strategies while maintaining overall structure and consistency.

Inventive Principle:
Principle #1Segmentation

2Productivity

If user credentials are passed between systems in heterogeneous environments, then delegation can occur, but credential recognition fails due to format inconsistencies

Engineering Contradiction:
Improvetask delegation capabilityVSAvoidcredential recognition accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a standardized authentication format as an intermediary representation that credentials can be converted to when passing between heterogeneous systems. This intermediate format acts as a universal language that both sending and receiving systems can understand, ensuring reliable credential recognition while enabling task delegation across different authentication domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If mapping is used to translate user IDs between systems, then some compatibility is achieved, but information is lost about the user's original authentication origin

Engineering Contradiction:
Improvesystem compatibilityVSAvoidauthentication origin information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The authentication format is designed to nest or embed information about the original authentication system within the standardized structure. Components such as the authentication scheme identifier and domain name are preserved within the normalized format, allowing the original authentication origin to be tracked and identified even after conversion to the universal format.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS8296853B2Method and system for authenticating a user
Publication Date: 2012.10.23 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8296853B2 patent drawing
  • US8296853B2 patent drawing

AI summary

Method of authenticating a user in a heterogeneous computer environment. The method may include defining a set of unique prefixes, each prefix identifying a type of user repository; defining a set of abstract repository names, each abstract repository name identifying an address of a user repository; and authenticating the user in the heterogeneous computer environment by assigning a sequence comprising a unique prefix, a reference to an abstract repository name and a unique identifier for the user within the user repository indicated by the reference to the abstract repository name.