Authentication Broker Risk Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication brokering systems do not effectively share authentication-related risk information among participants, leading to incomplete authentication decisions, as resource providers and authentication brokers operate independently without exchanging contextual or risk-related data.

Innovation Solution

Implementing a system where authentication brokers issue security tokens that include authentication risk data, allowing resource providers to share and utilize this data for enhanced authentication procedures, thereby modifying their decisions based on collective risk assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication brokers and resource providers operate independently with separate security domains, then each entity maintains its own security control and authentication decisions are made locally, but authentication risk information is not shared and authentication decisions are incomplete

Engineering Contradiction:
Improveauthentication decision completenessVSAvoidauthentication risk information sharing
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements feedback loops where authentication risk information flows bidirectionally between resource providers and authentication brokers. Resource providers send authentication context information to brokers, and brokers return risk assessments that influence subsequent authentication decisions. This continuous feedback mechanism ensures that authentication decisions are based on complete information while maintaining separate security domains.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent segments authentication risk information into distinct components that can be independently managed and shared. Different types of risk information (device risk, behavioral risk, contextual risk) are separated and exchanged selectively between security domains, allowing each entity to maintain control over their own security policies while benefiting from shared risk data.

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication procedures use basic token validation only, then the authentication process is simple and fast, but security is insufficient against sophisticated attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary authentication risk assessments before final authentication decisions are made. Resource providers and authentication brokers evaluate multiple risk factors (device characteristics, authentication patterns, contextual information) in advance to establish a baseline risk level. This preliminary action allows the system to maintain simple token validation for low-risk scenarios while applying more sophisticated checks only when necessary.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic authentication procedures that adapt their complexity based on real-time risk assessments. When risk levels are low, the system uses simple token validation for fast authentication. When risk levels increase or anomalies are detected, the system dynamically introduces additional verification steps and risk factor evaluations, making the authentication procedure more complex only when security demands it.

Inventive Principle:
Principle #15Dynamics

3Reliability

If contextual factors and risk data are evaluated during authentication, then authentication decisions are more informed and secure, but the authentication process takes more time and computational resources

Engineering Contradiction:
Improveauthentication decision qualityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial evaluation of contextual factors and risk data based on the specific authentication scenario. Not all risk factors are evaluated for every authentication request - only those relevant to the current context are assessed. This selective approach allows the system to make informed authentication decisions without always incurring the full computational overhead of evaluating every possible risk factor.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent pre-computes and caches risk assessments for commonly encountered scenarios, device types, and authentication patterns. When the same or similar authentication contexts occur again, the system retrieves pre-evaluated risk data instead of performing complete real-time analysis, significantly reducing authentication processing time while maintaining decision quality for standard scenarios.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10652282B2Brokered authentication with risk sharing
Publication Date: 2020.05.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10652282B2 patent drawing
  • US10652282B2 patent drawing
  • US10652282B2 patent drawing

AI summary

Embodiments described herein are implemented in authentication brokering systems where an authentication broker issues security tokens that represent its authentications of users. Client devices operated by the users store the security tokens and send them to resource providers. The resource providers authenticate and grant access to the users based on validation of the security tokens. Authentication related messages exchanged between the resource providers and the authentication broker are used to exchange authentication risk data that is obtained or derived by the resource providers and the authentication broker. The resource providers obtain authentication risk data directly from the authentication broker and indirectly, via the authentication broker, from each other. As security tokens are used or managed, authentication risk data is shared among the participants in the authentication brokering system. The participants are able to modify their authentication procedures or make authentication decisions based on shared authentication risk data.