Zero-Touch Federated SSO for Autonomous Endpoint Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single sign-on (SSO) systems in distributed computing environments, such as Storage-as-a-Service, face security risks due to account duplication and lack of access control autonomy, requiring manual configuration and central identity management, which can lead to delays and vulnerabilities.
Innovation Solution
Implementing an orchestration engine for federated authentication that enables endpoints to use their own identity services, allowing decentralized authorization and programmatically establishing trust between endpoints and customer identity providers, eliminating the need for manual configuration and central identity services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a central identity server/service is used for single sign-on management, then users can access multiple applications with one set of credentials, but user accounts are duplicated in the provider's identity service creating security risks
Solution Approach 1:
The patent extracts the identity verification function from the central provider identity service and relocates it to the customer's own identity service. The endpoint system now directly trusts and verifies credentials against the customer identity service, removing the duplicated account management from the provider's identity service and eliminating the security risk of account duplication while preserving single sign-on functionality.
2Ease of operation
If manual configuration is performed for identity service integration, then single sign-on can be implemented, but errors and security risks increase
Solution Approach 1:
The patent implements self-service by enabling the endpoint system to automatically establish trust relationships and configure identity verification. The system programmatically defines the trust relationship between the endpoint, customer identity service, and provider services without requiring manual configuration. This automation eliminates human errors in configuration while maintaining secure single sign-on implementation.
3Reliability
If manual configuration is performed by IAM experts, then identity service integration can be achieved, but deployment time is delayed
Solution Approach 1:
The patent applies preliminary action by pre-defining trust relationships and identity verification mechanisms at the system design level. The endpoint system is pre-configured with the ability to programmatically establish trust with customer identity services, eliminating the need for time-consuming manual configuration during deployment. This allows rapid deployment while maintaining reliable identity service integration through automated processes.
4Ease of operation
If a central authorization service is used, then identity and access control are simplified, but breaching the identity service impacts all customers
Solution Approach 1:
The patent segments the centralized authorization model into distributed authorization units at each endpoint. Each endpoint independently verifies credentials against the customer identity service and enforces access control locally. This segmentation isolates security breaches to individual endpoints rather than affecting all customers through a central service, while each endpoint maintains its own access control policies through automated credential verification.
5Ease of operation
If endpoints use provider's identity service for single sign-on, then seamless authentication is achieved, but endpoints cannot exercise their own access control policies
Solution Approach 1:
The patent applies local quality by enabling each endpoint to have its own access control policies and verification requirements while using the customer identity service for authentication. The endpoint system locally enforces its specific access control rules after verifying credentials, allowing each endpoint to have customized security requirements while maintaining seamless single sign-on through the federated identity verification process.
Data Source
AI summary
The disclosure relates to federated single sign-on authentication and to access control autonomy. A service may be configured such that a customer identity service has trust with an orchestration engine of the service. When endpoints are deployed, trust between the endpoints and the customer identity service is established by the orchestration engine on day 0. This allows the endpoints to retain access control autonomy and verify user or application identities. The endpoints may be configured to issue authorization tokens based on identity verifications. The authentication of multiple customers or their users is decentralized with respect to the service while allowing each customer's identity service to be a sole source of ground truth for authentication purposes.


