Aggregator System for Multi-Party Authentication Rule Reconciliation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing client device authentication becomes complex when multiple interested parties have conflicting rules for revoking authentication, as existing systems lack a mechanism to reconcile and prioritize these rules effectively.

Innovation Solution

An aggregator system is introduced that stores authentication and rules information for multiple interested parties, reconciles conflicts, and defines criteria for revoking authentication based on prioritized rules, ensuring consistent management of client device authentication across multiple stakeholders.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple interested parties define different rules for revoking authentication, then the security coverage is improved, but the system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an aggregator system that acts as an intermediary between multiple interested parties and the authentication system. This aggregator receives rules from various parties (carrier, merchant, financial institution, etc.), reconciles conflicts between them, and generates unified authentication criteria. By placing this intermediary layer, the patent manages the complexity of multiple conflicting rules without compromising the comprehensive security coverage that multiple parties provide.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If rules from multiple interested parties are reconciled, then the authentication management becomes consistent, but the processing time increases

Engineering Contradiction:
Improveauthentication consistencyVSAvoidprocessing time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The aggregator system performs preliminary reconciliation of rules from multiple interested parties before authentication decisions are required. By pre-processing and storing the reconciled authentication criteria, the system avoids performing complex rule conflicts resolution during time-critical authentication operations. This preliminary action ensures consistent authentication management while minimizing processing time during actual authentication events.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If authentication criteria are defined based on prioritized rules, then the decision-making clarity is improved, but the rule management complexity increases

Engineering Contradiction:
Improvedecision-making clarityVSAvoidrule management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent transforms the complex multi-party rule set into a simplified prioritized criterion structure by changing the parameter representation. Instead of managing multiple conflicting rules from different parties, the aggregator converts them into a single set of prioritized authentication criteria with clear decision logic. This parameter transformation maintains decision-making clarity while the aggregator handles the underlying rule management complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11159525B2Multi-dimensional framework for defining criteria that indicate when authentication should be revoked
Publication Date: 2021.10.26 BOKU IDENTITY INC
  • US11159525B2 patent drawing
  • US11159525B2 patent drawing
  • US11159525B2 patent drawing

AI summary

Methods and systems are presented for defining criteria that indicate when authentication for an identified client device should be revoked based on rules associated with interested parties. Authentication information is stored that indicates that an identified client device is authenticated. Rules that are associated with a plurality of interested parties and include rules of different rule types may also be stored. Criteria may be defined based on the rules and the authentication information, the criteria indicating when authentication of the identified client device should be revoked. Authentication of the identified client device may be revoked based on the criteria.