Web Authentication Gateway for Single Sign-On
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single sign-on solutions for web-based applications in corporate networks require significant modifications to systems and user machines, and face challenges with system interoperability and the need for multiple authentications across interconnected applications.
Innovation Solution
A web authentication tool provides a common secure login process for all internal and external web applications, using a single login to access multiple applications by redirecting users to a secure enterprise server for authentication, which then formats and encrypts the authentication information for external applications, allowing seamless access without re-entering credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If system-level authentication services are incorporated to enable single sign-on, then authentication security is improved, but device complexity increases due to required modifications to systems and user machines
Solution Approach 1:
The patent introduces a gateway server as an intermediary component that mediates between external web applications and the corporate network authentication system. This gateway server handles authentication requests by redirecting users to the authentication server, obtaining authentication tokens, and forwarding them to external applications. This intermediary approach enables single sign-on functionality without requiring modifications to external applications or user machines, thus improving authentication security while avoiding increased device complexity.
2Adaptability or versatility
If comprehensive system-wide authentication infrastructure is implemented, then authentication coverage is improved, but ease of operation deteriorates due to workflow interruptions for password entry
Solution Approach 1:
The patent implements preliminary authentication action by requiring users to authenticate once at the gateway server before accessing external web applications. The authentication server issues a token that is stored and automatically reused for subsequent authentication requests to multiple external applications. This preliminary authentication eliminates the need for users to repeatedly enter passwords during workflow, thereby improving ease of operation while maintaining comprehensive authentication coverage across all connected applications.
3Adaptability or versatility
If multiple authentication protocols are supported for different applications, then adaptability is improved, but device complexity increases due to multiple client-side software requirements
Solution Approach 1:
The patent creates a universal authentication gateway that can handle multiple authentication protocols and external application types through a single interface. The gateway server acts as a protocol translator, converting various authentication requests from different external applications into a standardized format that the authentication server can process. This universal approach allows the system to support diverse authentication protocols and applications without requiring different client-side software for each protocol, thereby maintaining adaptability while reducing device complexity.
Data Source
AI summary
A method, system, and computer readable medium for facilitating user authentication for accessing an application hosted on an external web site by users in an enterprise network. A request is received from a user a request is received from a user to access the application on the external web site. The user is redirected to a secure web page on an enterprise server to log in to the enterprise server. Authentication information for the user is formatted in compliance with a login specification for the application hosted on the external web site. The authentication information is encrypted in compliance with the login specification for the application hosted on the external web site. The user is then directed to the application hosted on the external web site, wherein the user can access the application without having to reenter login information.


