Multifactor Authentication Enabler for Third-Party Apps
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current service provider networks face challenges in authenticating end users for third-party applications, as they often lack identifiers and multifactor authentication mechanisms, making it difficult to establish trust relationships and manage billing for user services.
Innovation Solution
The implementation of a system that provides application-initiated user authentication using a user personal identification number (PIN) and multifactor authentication, where the authentication enabler determines user credentials based on the application identifier and performs policy-based authentication, including PIN and Generic Bootstrapping Architecture (GBA) methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If service provider networks use traditional authentication methods for third-party applications, then existing infrastructure can be maintained, but authentication reliability and trust establishment deteriorate due to lack of identifiers and multifactor authentication mechanisms
Solution Approach 1:
The authentication system is segmented into multiple independent components: application identifiers for app-level authentication, user identifiers for user-level authentication, and multiple credential types (passwords, PINs, biometrics) that can be independently selected and combined. This segmentation allows the system to build reliable multifactor authentication without requiring a complete overhaul of existing infrastructure.
Solution Approach 2:
The service provider network acts as an intermediary between third-party applications and end users, implementing authentication enablers that mediate the authentication process. These enablers provide the missing identifier functions and coordinate multifactor authentication across different systems, establishing trust relationships without requiring direct integration between applications and users.
2Adaptability or versatility
If service provider networks implement multifactor authentication with identifiers for third-party applications, then trust relationship establishment improves, but API complexity and difficulty of implementation worsen
Solution Approach 1:
The authentication enablers provide universal identifier functions that work across different application types and service provider networks. The same enabler infrastructure supports application identifiers, user identifiers, and multiple credential types, allowing a single system to handle diverse authentication scenarios without requiring separate implementations for each case.
Solution Approach 2:
The system allows dynamic selection and combination of authentication parameters based on policy requirements. Different credential types (password, PIN, biometric) and authentication factors can be configured and combined in various ways to meet specific trust requirements, with the API adapting its behavior based on the selected parameters rather than requiring separate endpoints for each authentication type.
3Measurement precision
If service provider networks perform authentication on behalf of third-party applications, then authentication assurance and billing capability improve, but system operation complexity worsens
Solution Approach 1:
The service provider network performs authentication preliminarily, before the application needs to use the service. The authentication enablers verify user identities and establish trust relationships in advance, providing authentication tokens or credentials that the application can then use without performing its own complex authentication. This preliminary authentication ensures high assurance levels while simplifying application operations.
Solution Approach 2:
The authentication system is designed to be self-service oriented, where the service provider network automatically manages credential verification, trust relationship establishment, and authentication state tracking without requiring manual intervention. The API handles authentication coordination automatically based on policy rules, reducing operational complexity despite the enhanced authentication capabilities.
Data Source
AI summary
A device receives a request to authenticate an end user of a user device to use an application, based on an application identifier and a user identifier included the request, and determines whether the application is authenticated based on the application identifier. The device also determines whether the user device is authenticated based on the user identifier and utilizing a generic bootstrapping architecture (GBA) authentication procedure, and determines whether the end user is authenticated based on a personal identification number (PIN) associated with the end user. The device further provides, to an application server device hosting the application, results of the authentications of the application, the user device, and the end user.


