Authentication Enrollment Security via Preliminary Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems often fail to ensure secure enrollment of new authentication methods, as they may not require prior authentication or provide weak security points, potentially compromising the strength of the new authentication procedures.
Innovation Solution
Enrolling users in new authentication procedures only after they have successfully authenticated using an earlier-established procedure that is at least as strong, ensuring a secure process by requiring combinations of authentication factors such as user identifiers, one-time passcodes, biometrics, and location verification, and defining security strengths through policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional authentication systems allow users to set different security levels for different apps without requiring prior authentication for enrollment, then ease of operation is improved, but security reliability deteriorates
Solution Approach 1:
The system performs preliminary authentication using an existing authentication procedure before allowing enrollment in a new authentication procedure. This ensures that the user's identity is verified in advance, preventing unauthorized enrollment while maintaining a streamlined process for legitimate users.
Solution Approach 2:
The system introduces an intermediary authentication check that mediates between the user's request to enroll and the actual enrollment process. This intermediary step verifies the user's identity through an existing authentication method before permitting enrollment, thus securing the process without adding significant complexity.
2Reliability
If the system requires strong authentication prior to enrollment, then security reliability is improved, but device complexity increases
Solution Approach 1:
The system leverages existing authentication procedures that serve multiple purposes - they are used for both regular authentication and for verifying enrollment requests. This multi-functionality allows the system to maintain strong security without adding separate dedicated enrollment verification mechanisms, thus avoiding increased complexity.
Solution Approach 2:
The system uses its own existing authentication infrastructure to verify enrollment requests, rather than introducing external or separate verification systems. The existing authentication procedures serve themselves by also validating enrollment operations, eliminating the need for additional complexity.
3Ease of operation
If low risk score authentication is accepted for enrollment in high security procedures, then ease of operation is improved, but security reliability worsens
Solution Approach 1:
The system performs a preliminary authentication check using the existing authentication procedure with a determined security strength before allowing enrollment. This advance verification ensures that only users who can successfully authenticate with sufficient security strength proceed to enrollment, preventing weak authentication from compromising high-security procedures.
Data Source
AI summary
A technique is directed to operating an authentication system. The technique involves receiving an enrollment request to enroll a user in a new authentication procedure in place of an earlier-established authentication procedure. The earlier-established authentication procedure is operative to authenticate the user at a first security level within a range of security levels. The new authentication procedure is operative to authenticate the user at a second security level within the range of security levels, the first security level being at least as high as the second security level within the range of security levels. The technique further involves, in response to the enrollment request, initiating the earlier-established authentication procedure to authenticate the user. The technique further involves, in response to completion of the earlier-established authentication procedure, performing an authentication enrollment operation associated with the new authentication procedure.


