Access Gateway for Multi-System Authentication Assurance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-resource computing environments often lack the computational capabilities to support contemporary authentication techniques, such as multi-factor authentication, especially in legacy systems with insufficient memory or processing power, and struggle to manage access requests from multiple devices effectively.

Innovation Solution

An access gateway is introduced to control access to multiple computing resource systems by determining a cumulative assurance level from multiple authentication factors received from various devices, allowing or denying access based on this level and requesting additional factors as needed to meet threshold authentication levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is implemented in legacy computing systems, then security is improved, but the system becomes incompatible due to insufficient computing capabilities

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

An access gateway is introduced as an intermediary component between user devices and legacy computing resources. The gateway performs multi-factor authentication processing and presents simplified authentication results to legacy systems, enabling enhanced security without requiring modifications to the legacy resources themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into distinct functional components: the access gateway handles complex multi-factor authentication logic, while legacy computing resources maintain their existing simplified authentication interfaces. This segmentation allows each component to operate within its capability constraints while achieving overall system security goals.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multi-factor authentication processing is performed directly on computing resources, then authentication security is improved, but processing overhead increases beyond available computational capacity

Engineering Contradiction:
Improveauthentication securityVSAvoidcomputational capacity
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The access gateway serves as a dedicated intermediary that offloads computationally intensive multi-factor authentication processing from legacy computing resources. The gateway possesses sufficient processing power to handle complex authentication operations while presenting minimal overhead to the legacy systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication gateway creates and manages authentication sessions and data structures, allowing legacy systems to authenticate users without directly processing complex multi-factor authentication data. The gateway maintains copies of authentication state information needed by legacy resources.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11190517B2Access control based on combined multi-system authentication factors
Publication Date: 2021.11.30 AT&T INTELLECTUAL PROPERTY I L P
  • US11190517B2 patent drawing
  • US11190517B2 patent drawing
  • US11190517B2 patent drawing

AI summary

An access gateway may control access of user devices to remote computer resource systems in a multi-resource computing environment. The access gateway may determine an assurance level associated with a user of the multi-resource environment, where the assurance level is based on multiple authentication factors included in multiple previous access requests. The access gateway may receive, from a user device, an additional access request to access an additional resource system in the multi-resource environment. Based on a comparison of the assurance level with a threshold authentication level for the additional resource system, the access gateway may allow or deny access to the additional resource system. In addition, based on the comparison, the access system may request additional authentication data from the user device.