Authentication Tier Registry for Low-Friction Secure Content Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems require additional authentication steps (AAS) that create friction for users, decreasing click-through and conversion rates, and retrofitting systems to delay AAS can be costly and affect user experience.
Innovation Solution
Implementing an Authentication Tier Designation (AASD) registry to associate restricted actions/webpages with authentication tiers, allowing for deferred AAS based on pre-approved data access control, using eager and lazy fetch methods to retrieve sensitive information efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If additional authentication steps (AAS) are required before allowing user access to restricted actions, then security is improved, but user experience deteriorates due to increased friction and decreased conversion rates
Solution Approach 1:
The patent implements preliminary authentication by requiring users to complete additional authentication steps (AAS) before accessing restricted actions. The system pre-approves data access control by associating restricted actions with authentication tiers, and performs eager fetch of authentication status before the user requests the restricted action. This ensures security is established in advance while allowing smooth access for pre-approved users.
Solution Approach 2:
The patent introduces dynamic authentication tier designation where the authentication requirements are not static but change based on the specific restricted action being accessed. The system dynamically determines whether AAS is required by checking the authentication tier associated with the requested action, allowing flexible adjustment of security levels based on the sensitivity and importance of each specific action.
2Reliability
If additional authentication steps (AAS) are delayed rather than waived, then security vulnerability is avoided, but system modification costs increase due to retrofitting requirements
Solution Approach 1:
The patent segments the authentication process into distinct tiers and associates each restricted action with a specific authentication tier. This segmentation allows the system to selectively apply AAS only when necessary, rather than requiring all users to complete all authentication steps. The authentication status is stored in a structured format that can be efficiently queried without requiring system-wide retrofitting.
Solution Approach 2:
The patent creates a universal authentication tier designation system that can be applied across multiple restricted actions and pages. The AASD registry serves as a central repository that maps restricted actions to authentication tiers, providing a multi-functional solution that handles various types of restricted actions (viewing PII, editing account information, etc.) through a unified approach, reducing the need for action-specific modifications.
3Reliability
If per-task authentication is implemented, then security is maintained for each specific action, but user frustration increases due to piece-meal security requirements
Solution Approach 1:
The patent performs preliminary authentication by eager-fetching the authentication status and tier information before the user requests a restricted action. This allows the system to determine in advance whether AAS is required and prepare the appropriate authentication challenge, reducing the perception of piece-meal security by presenting all necessary authentication requirements upfront rather than incrementally during the task.
Solution Approach 2:
The patent introduces an intermediary authentication tier designation system that mediates between the user's request for restricted actions and the security requirements. The AASD registry acts as an intermediary layer that translates user requests into appropriate authentication tier requirements, providing a smooth transition between different security levels without exposing the underlying complexity of per-task authentication to the user.
Data Source
AI summary
Techniques are described herein for performing authentication, and also “eager” or “lazy” fetch of data, for restricted webpages based on the restricted webpages being associated with an authentication tier in an AASD registry. Inclusion of a restricted webpage in the AASD registry enables AASD-based authentication for the webpage. According to embodiments, information for a restricted webpage included in the AASD registry includes one or more of the following for the webpage: an identifier, an authentication level, allowed fields, eager fetch fields, one or more sources for one or more fields, etc. When information for a webpage is included in the AASD registry, that information is used to perform eager fetch for one or more fields of the webpage that are not associated with authentication requirements indicated in the AASD registry information, or whose authentication requirements are already fulfilled by the requesting client.


