Authentication Control Server Mediating Multiple Methods
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems face difficulties in introducing new authentication methods without modifying the settings of existing communication server apparatus and client apparatus, particularly when transitioning from password-based authentication to more secure methods like public key cryptography or biometric authentication.
Innovation Solution
A system where a first client apparatus uses authentication information compliant with a first authentication method and a second client apparatus converts its authentication information into a format compliant with the first method for transmission to a communication server, which then routes the information to appropriate authentication servers for processing, allowing both authentication methods to be handled without changing the server or client settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a new authentication method is introduced to an existing authentication system, then authentication security is improved, but system compatibility and ease of operation deteriorate due to required changes in server and client settings
Solution Approach 1:
The patent introduces an authentication control server as an intermediary component that mediates between the communication server and authentication servers. This control server receives authentication requests, determines the appropriate authentication method, and routes them to the corresponding authentication server. By placing the authentication method selection and routing logic in this intermediary control server, the communication server and client apparatus do not need to be modified to support multiple authentication methods, thus maintaining compatibility while enabling enhanced security.
Solution Approach 2:
The authentication control server is designed to handle multiple authentication methods universally. It can process both traditional password authentication and newer methods like public key authentication, biometric authentication, and token-based authentication through a single unified interface. This multi-functional design allows the system to support various authentication methods without requiring separate processing paths in the communication server or client, thereby maintaining ease of operation while improving security.
2Adaptability or versatility
If authentication methods are extended to include multiple methods, then authentication versatility is improved, but device complexity increases due to need for handling different authentication formats
Solution Approach 1:
The authentication control server acts as an intermediary that handles the complexity of routing authentication requests to different authentication servers based on the authentication method type. It receives authentication requests from the communication server, determines which authentication server should process the request, and forwards it accordingly. This routing function is centralized in the control server, preventing the communication server and client from needing to implement complex logic to handle multiple authentication formats directly.
Solution Approach 2:
The authentication processing function is segmented into separate components: the authentication control server handles request routing and method determination, while individual authentication servers (password authentication server, public key authentication server, biometric authentication server, token authentication server) handle specific authentication methods independently. This segmentation allows each component to specialize in one or a few authentication methods, reducing the complexity burden on any single component while enabling the system to support multiple authentication methods overall.
Data Source
AI summary
A client apparatus converts second input authentication information having a data content compliant with a second authentication method different from a first authentication method into authentication target information in a data format compliant with the first authentication method and transmits information corresponding to the authentication target information to a communication server apparatus. A server apparatus is capable of carrying out both a first process of providing a first authentication server apparatus that carries out an authentication process compliant with the first authentication method with first information corresponding to the authentication target information and a second process of providing a second authentication server apparatus that carries out an authentication process compliant with the second authentication method with second information corresponding to the authentication target information. The server apparatus transmits authentication result information based on at least one of a result of the authentication performed by the first authentication server apparatus based on the first information and a result of the authentication performed by the second authentication server apparatus based on the second information to the communication server apparatus.


