Authentication Service Managing Identity Provider Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers face challenges in designing a flexible authentication system that allows them to control the selection of identity providers (IDPs) and multi-factor authentication (MFA) methods, as some third-party IDPs discontinue cookie usage and limit access to analytics data, reducing their ability to track user interactions effectively.

Innovation Solution

An authentication system that manages IDP implementation and updates on a service provider's website, enabling them to choose and configure IDPs, offer MFA options, and integrate with various authentication methods, ensuring user identity verification without storing sensitive information, thus enhancing user experience and analytics tracking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If third-party IDPs are used for authentication, then user authentication and registration are simplified, but control over IDP selection and analytics data access is reduced

Engineering Contradiction:
Improveauthentication processVSAvoidIDP selection control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces an authentication service as an intermediary layer between the service provider and third-party IDPs. This authentication service manages the integration with multiple IDPs, allows the service provider to control which IDPs are presented to users, and maintains analytics capabilities without requiring direct integration with each IDP. The intermediary handles the complexity of IDP management while preserving service provider control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple IDPs are supported, then user freedom in choosing authentication method increases, but system complexity increases

Engineering Contradiction:
Improveauthentication method optionsVSAvoidauthentication system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication service provides a universal interface that works with multiple different IDPs through standardized protocols. Rather than implementing separate integration logic for each IDP, the system uses a single authentication service that can authenticate users through various IDPs, reducing overall system complexity while maintaining support for multiple authentication methods.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If IDPs discontinue cookie usage and limit data access, then user privacy and security are improved, but analytics tracking capability is reduced

Engineering Contradiction:
Improveuser privacy and securityVSAvoidanalytics data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The authentication service acts as an intermediary that maintains analytics capabilities independent of IDP data access limitations. It collects and processes authentication events and user interaction data through its own tracking mechanisms, rather than relying on data access from third-party IDPs, thus preserving analytics functionality while respecting IDP privacy policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12169576B2Authentication service for use with indentity providers
Publication Date: 2024.12.17 BREAD & BUTTER IO INC
  • US12169576B2 patent drawing
  • US12169576B2 patent drawing
  • US12169576B2 patent drawing

AI summary

An authentication system for authenticating a user to access gated digital content includes a user computing device, a service provider server, an authentication service, and at least one identity provider. The service provider server is configured to require registration and authentication prior to providing the user with access to the gated digital content, and the at least one identity provider is configured to authenticate a user identity of the user. Upon receiving a request via the user computing device to access the gated digital content hosted by the service provider server, the authentication service displays an authentication platform interface to the user. The authentication platform interface displays at least one identity provider selector linked to the at least one identity provider, and the at least one identity provider is based on a policy of the authentication service set by the service provider.