Authentication Broker Risk Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication brokering systems do not effectively share authentication-related risk information among participants, leading to incomplete authentication decisions, as resource providers and authentication brokers operate independently without exchanging contextual or risk-related data.
Innovation Solution
Implementing a system where authentication brokers issue security tokens that include authentication risk data, allowing resource providers to share and utilize this data for enhanced authentication procedures, thereby modifying their decisions based on collective risk assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication brokers and resource providers operate independently with separate security domains, then each entity maintains its own security control and authentication decisions are made locally, but authentication risk information is not shared and authentication decisions are incomplete
Solution Approach 1:
The patent implements feedback loops where authentication risk information flows bidirectionally between resource providers and authentication brokers. Resource providers send authentication context information to brokers, and brokers return risk assessments that influence subsequent authentication decisions. This continuous feedback mechanism ensures that authentication decisions are based on complete information while maintaining separate security domains.
Solution Approach 2:
The patent segments authentication risk information into distinct components that can be independently managed and shared. Different types of risk information (device risk, behavioral risk, contextual risk) are separated and exchanged selectively between security domains, allowing each entity to maintain control over their own security policies while benefiting from shared risk data.
2Reliability
If authentication procedures use basic token validation only, then the authentication process is simple and fast, but security is insufficient against sophisticated attacks
Solution Approach 1:
The patent performs preliminary authentication risk assessments before final authentication decisions are made. Resource providers and authentication brokers evaluate multiple risk factors (device characteristics, authentication patterns, contextual information) in advance to establish a baseline risk level. This preliminary action allows the system to maintain simple token validation for low-risk scenarios while applying more sophisticated checks only when necessary.
Solution Approach 2:
The patent implements dynamic authentication procedures that adapt their complexity based on real-time risk assessments. When risk levels are low, the system uses simple token validation for fast authentication. When risk levels increase or anomalies are detected, the system dynamically introduces additional verification steps and risk factor evaluations, making the authentication procedure more complex only when security demands it.
3Reliability
If contextual factors and risk data are evaluated during authentication, then authentication decisions are more informed and secure, but the authentication process takes more time and computational resources
Solution Approach 1:
The patent applies partial evaluation of contextual factors and risk data based on the specific authentication scenario. Not all risk factors are evaluated for every authentication request - only those relevant to the current context are assessed. This selective approach allows the system to make informed authentication decisions without always incurring the full computational overhead of evaluating every possible risk factor.
Solution Approach 2:
The patent pre-computes and caches risk assessments for commonly encountered scenarios, device types, and authentication patterns. When the same or similar authentication contexts occur again, the system retrieves pre-evaluated risk data instead of performing complete real-time analysis, significantly reducing authentication processing time while maintaining decision quality for standard scenarios.
Data Source
AI summary
Embodiments described herein are implemented in authentication brokering systems where an authentication broker issues security tokens that represent its authentications of users. Client devices operated by the users store the security tokens and send them to resource providers. The resource providers authenticate and grant access to the users based on validation of the security tokens. Authentication related messages exchanged between the resource providers and the authentication broker are used to exchange authentication risk data that is obtained or derived by the resource providers and the authentication broker. The resource providers obtain authentication risk data directly from the authentication broker and indirectly, via the authentication broker, from each other. As security tokens are used or managed, authentication risk data is shared among the participants in the authentication brokering system. The participants are able to modify their authentication procedures or make authentication decisions based on shared authentication risk data.


