VLAN Tagged Application Single Sign-On Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users are required to repeatedly authenticate with each application when accessing multiple applications, which is inconvenient and increases processing load on servers and network traffic.
Innovation Solution
A processor-implemented method that leverages a virtual local area network (VLAN) identifier to provide application single sign-on (SSO) by associating a client device with a VLAN, allowing the authentication server to link the VLAN tag with user identification and authentication levels, enabling seamless access to applications without separate authentication for each application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users authenticate with each application separately, then each application can verify user credentials independently, but users experience repeated authentication inconvenience and server processing load increases
Solution Approach 1:
The patent merges multiple authentication operations into a single authentication action. When a user authenticates to access an application, the authentication server not only verifies credentials for that specific application but also automatically authenticates the user for all other applications in the system. This combining of authentication operations eliminates repeated login requirements while maintaining security through a centralized authentication mechanism that tracks user credentials across all applications.
2Reliability
If users authenticate with each application separately, then application-specific authentication control is maintained, but server processing load and network traffic increase
Solution Approach 1:
The patent implements preliminary authentication where the authentication server performs a single comprehensive verification of user credentials that establishes authentication status for all applications in advance. Instead of repeatedly verifying credentials for each application access, the server performs the authentication action once and caches the result, allowing subsequent application accesses to proceed without repeating the full authentication process. This preliminary action significantly reduces server processing load while maintaining authentication control.
3Reliability
If traditional authentication methods are used for each application, then application security is maintained, but user convenience and system efficiency deteriorate
Solution Approach 1:
The patent combines multiple authentication time costs into a single authentication event. By merging the authentication process across all applications, the system eliminates the need for users to spend time repeatedly entering credentials for each application. The single authentication action establishes a time-bound authentication token that validates user identity across the entire application suite, dramatically reducing the total time users spend on authentication activities while maintaining security through the centralized authentication server.
Data Source
AI summary
A processor-implemented method for providing application single sign on leveraging a virtual local area network identifier is provided. The method comprises an authentication server providing a client device access to a network via association with a virtual local area network and a credential. The method also comprises the device invoking an application hosted on an application server and the application server identifying a virtual local area network tag associated with the device. The method also comprises the application server sending a message to the authentication server requesting linkage of the tag with a user identification associated with the device. The method also comprises the authentication server linking the tag with the user identification associated with the device and sending a message to the application server containing the identification. The method also comprises the application server using the identification to authenticate the device with the application and the device receiving access.


