Multifactor Authentication Enabler for Third-Party Apps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current service provider networks face challenges in authenticating end users for third-party applications, as they often lack identifiers and multifactor authentication mechanisms, making it difficult to establish trust relationships and manage billing for user services.

Innovation Solution

The implementation of a system that provides application-initiated user authentication using a user personal identification number (PIN) and multifactor authentication, where the authentication enabler determines user credentials based on the application identifier and performs policy-based authentication, including PIN and Generic Bootstrapping Architecture (GBA) methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service provider networks use traditional authentication methods for third-party applications, then existing infrastructure can be maintained, but authentication reliability and trust establishment deteriorate due to lack of identifiers and multifactor authentication mechanisms

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent components: application identifiers for app-level authentication, user identifiers for user-level authentication, and multiple credential types (passwords, PINs, biometrics) that can be independently selected and combined. This segmentation allows the system to build reliable multifactor authentication without requiring a complete overhaul of existing infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The service provider network acts as an intermediary between third-party applications and end users, implementing authentication enablers that mediate the authentication process. These enablers provide the missing identifier functions and coordinate multifactor authentication across different systems, establishing trust relationships without requiring direct integration between applications and users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If service provider networks implement multifactor authentication with identifiers for third-party applications, then trust relationship establishment improves, but API complexity and difficulty of implementation worsen

Engineering Contradiction:
Improvetrust relationship adaptabilityVSAvoidAPI complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication enablers provide universal identifier functions that work across different application types and service provider networks. The same enabler infrastructure supports application identifiers, user identifiers, and multiple credential types, allowing a single system to handle diverse authentication scenarios without requiring separate implementations for each case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system allows dynamic selection and combination of authentication parameters based on policy requirements. Different credential types (password, PIN, biometric) and authentication factors can be configured and combined in various ways to meet specific trust requirements, with the API adapting its behavior based on the selected parameters rather than requiring separate endpoints for each authentication type.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If service provider networks perform authentication on behalf of third-party applications, then authentication assurance and billing capability improve, but system operation complexity worsens

Engineering Contradiction:
Improveauthentication assurance levelVSAvoidsystem operation ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The service provider network performs authentication preliminarily, before the application needs to use the service. The authentication enablers verify user identities and establish trust relationships in advance, providing authentication tokens or credentials that the application can then use without performing its own complex authentication. This preliminary authentication ensures high assurance levels while simplifying application operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system is designed to be self-service oriented, where the service provider network automatically manages credential verification, trust relationship establishment, and authentication state tracking without requiring manual intervention. The API handles authentication coordination automatically based on policy rules, reducing operational complexity despite the enhanced authentication capabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8893244B2Application-based credential management for multifactor authentication
Publication Date: 2014.11.18 WORKDAY INC
  • US8893244B2 patent drawing
  • US8893244B2 patent drawing
  • US8893244B2 patent drawing

AI summary

A device receives a request to authenticate an end user of a user device to use an application, based on an application identifier and a user identifier included the request, and determines whether the application is authenticated based on the application identifier. The device also determines whether the user device is authenticated based on the user identifier and utilizing a generic bootstrapping architecture (GBA) authentication procedure, and determines whether the end user is authenticated based on a personal identification number (PIN) associated with the end user. The device further provides, to an application server device hosting the application, results of the authentications of the application, the user device, and the end user.