Zero-Touch Federated SSO for Autonomous Endpoint Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single sign-on (SSO) systems in distributed computing environments, such as Storage-as-a-Service, face security risks due to account duplication and lack of access control autonomy, requiring manual configuration and central identity management, which can lead to delays and vulnerabilities.

Innovation Solution

Implementing an orchestration engine for federated authentication that enables endpoints to use their own identity services, allowing decentralized authorization and programmatically establishing trust between endpoints and customer identity providers, eliminating the need for manual configuration and central identity services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a central identity server/service is used for single sign-on management, then users can access multiple applications with one set of credentials, but user accounts are duplicated in the provider's identity service creating security risks

Engineering Contradiction:
Improvesingle sign-on accessVSAvoidsecurity risk from account duplication
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the identity verification function from the central provider identity service and relocates it to the customer's own identity service. The endpoint system now directly trusts and verifies credentials against the customer identity service, removing the duplicated account management from the provider's identity service and eliminating the security risk of account duplication while preserving single sign-on functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If manual configuration is performed for identity service integration, then single sign-on can be implemented, but errors and security risks increase

Engineering Contradiction:
Improvesingle sign-on implementationVSAvoidconfiguration accuracy
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent implements self-service by enabling the endpoint system to automatically establish trust relationships and configure identity verification. The system programmatically defines the trust relationship between the endpoint, customer identity service, and provider services without requiring manual configuration. This automation eliminates human errors in configuration while maintaining secure single sign-on implementation.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual configuration is performed by IAM experts, then identity service integration can be achieved, but deployment time is delayed

Engineering Contradiction:
Improveidentity service integrationVSAvoiddeployment delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-defining trust relationships and identity verification mechanisms at the system design level. The endpoint system is pre-configured with the ability to programmatically establish trust with customer identity services, eliminating the need for time-consuming manual configuration during deployment. This allows rapid deployment while maintaining reliable identity service integration through automated processes.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If a central authorization service is used, then identity and access control are simplified, but breaching the identity service impacts all customers

Engineering Contradiction:
Improveaccess control managementVSAvoidimpact scope of security breach
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized authorization model into distributed authorization units at each endpoint. Each endpoint independently verifies credentials against the customer identity service and enforces access control locally. This segmentation isolates security breaches to individual endpoints rather than affecting all customers through a central service, while each endpoint maintains its own access control policies through automated credential verification.

Inventive Principle:
Principle #1Segmentation

5Ease of operation

If endpoints use provider's identity service for single sign-on, then seamless authentication is achieved, but endpoints cannot exercise their own access control policies

Engineering Contradiction:
Improveauthentication seamlessnessVSAvoidaccess control autonomy
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by enabling each endpoint to have its own access control policies and verification requirements while using the customer identity service for authentication. The endpoint system locally enforces its specific access control rules after verifying credentials, allowing each endpoint to have customized security requirements while maintaining seamless single sign-on through the federated identity verification process.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250328623A1System and method for distributed autonomy through zero touch seamless single sign-on
Publication Date: 2025.10.23 DELL PROD LP
  • US20250328623A1 patent drawing
  • US20250328623A1 patent drawing
  • US20250328623A1 patent drawing

AI summary

The disclosure relates to federated single sign-on authentication and to access control autonomy. A service may be configured such that a customer identity service has trust with an orchestration engine of the service. When endpoints are deployed, trust between the endpoints and the customer identity service is established by the orchestration engine on day 0. This allows the endpoints to retain access control autonomy and verify user or application identities. The endpoints may be configured to issue authorization tokens based on identity verifications. The authentication of multiple customers or their users is decentralized with respect to the service while allowing each customer's identity service to be a sole source of ground truth for authentication purposes.