Authentication Adapter Bridge for Incompatible Protocol Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital networks face challenges in authenticating elements that support incompatible authentication protocols, leading to vulnerabilities and difficulties in secure data access, especially when one protocol is weaker than the other.

Innovation Solution

A digital authentication architecture that includes an authentication adapter bridge (AAB) providing an authentication pipeline to facilitate authentication between client nodes and target applications, even when they support different protocols, by generating and executing a series of authentication tests to satisfy the target application's protocol, and issuing tokens for secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If direct communication is used for authentication between client nodes and target applications, then authentication speed is improved, but security vulnerabilities increase due to interception and redirection risks

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity vulnerabilities
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication adapter bridge as an intermediary component that mediates authentication between client nodes and target applications. This bridge establishes secure communication channels, preventing direct exposure to interception and redirection attacks while maintaining authentication efficiency through standardized protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication protocols are made compatible between different elements, then ease of operation is improved, but adaptability decreases when elements support weaker authentication protocols

Engineering Contradiction:
Improveauthentication compatibilityVSAvoidprotocol strength adaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The authentication adapter bridge is designed with multi-functionality to handle multiple authentication protocols simultaneously. It can adapt to different protocol requirements (Kerberos, OAuth, SAML, etc.) and perform protocol conversion, enabling universal compatibility while maintaining the ability to enforce stronger authentication standards when needed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If a multi-tiered authentication pipeline is implemented to handle incompatible protocols, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidauthentication architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication adapter bridge serves as a centralized intermediary that consolidates the complexity of multi-protocol handling in a single component rather than distributing complexity across multiple client nodes and target applications. This centralization simplifies the overall system architecture while maintaining high adaptability to different authentication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If authentication is performed inline without direct interaction between client nodes and target applications, then security is improved, but authentication time increases due to additional intermediary steps

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication adapter bridge performs preliminary actions by pre-establishing secure communication channels and caching authentication states. This allows inline authentication to proceed efficiently without requiring full protocol negotiation each time, reducing authentication time while maintaining security through the intermediary architecture.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11601431B2Split-tiered point-to-point inline authentication architecture
Publication Date: 2023.03.07 BANK OF AMERICA CORP
  • US11601431B2 patent drawing
  • US11601431B2 patent drawing
  • US11601431B2 patent drawing

AI summary

Systems and methods for authenticating presumptively incompatible elements in a digital network are provided. A method may include receiving an access request from a client node in the network. The access request may be requesting access to an application in the network. The access request may be associated with a uniform resource identifier (“authURI”). The method may include extracting a target application from the URI. The method may include determining an authentication protocol that is supported by the target application. The method may include generating, based on the authentication protocol, a series of one or more authentication tests that, in combination, satisfy the authentication protocol. The authentication tests may satisfy the authentication protocol even when the client node natively supports a different authentication protocol. The method may include executing the series of authentication tests to authenticate the client node vis-à-vis the target application.