Virtual Machine Logon Federation via Credential Provider
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service providers and virtual machine users face security concerns when accessing resources outside their standard security domain, particularly due to the need for multiple credentials and lack of secure, trusted access methods.
Innovation Solution
A credential provider system utilizing SAML or ADFS endpoints to authenticate virtual machine users' credentials from an existing identity provider, issuing security tokens for authorized access to resources in external security domains, thereby eliminating the need for separate credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If virtual machine users access resources outside their standard security domain, then access to external resources is enabled, but security risks and credential management complexity increase
Solution Approach 1:
The patent introduces a credential provider as an intermediary component that sits between the virtual machine user and external security domains. This credential provider obtains security tokens from trusted identity providers and uses these tokens to authenticate users when accessing external resources, thereby enabling cross-domain access while maintaining security through a trusted mediation layer rather than direct user credential exposure
2Adaptability or versatility
If virtual machine users access resources outside their standard security domain, then access to external resources is enabled, but the number of credentials required increases
Solution Approach 1:
The patent implements a universal credential provider that can obtain security tokens from multiple different identity providers (such as Active Directory Federation Services, Security Assertion Markup Language providers, or other trusted identity sources). This single credential provider component serves multiple functions by supporting various identity providers and handling different authentication protocols, thereby eliminating the need for users to manage separate credentials for each external security domain
3Reliability
If traditional authentication methods are used for external security domains, then security is maintained through credential verification, but user convenience and access simplicity deteriorate
Solution Approach 1:
The patent enables the credential provider to automatically obtain security tokens from identity providers and manage authentication credentials without requiring user intervention. The system performs self-service authentication by automatically acquiring tokens, managing their validity periods, and using them for seamless access to external resources, thereby maintaining strong security verification while eliminating the need for users to manually manage multiple credentials or logins
Data Source
AI summary
Systems and methods are described for providing federated access to end-users of virtual machines. The method includes receiving a request from a user to access a resource outside of the user's original security domain. The user's existing security credentials are forwarded to an authentication entity, which determines if the user's credentials are authentic. If it is determined that the user's credentials are authentic, the user's target identity provider generates a security token that provides the virtual machine user with access to the resource, the resource residing in an external security domain. The user may log on to the virtual machine with access to the desired resource, subject to the privileges identified in the security token.


