Authentication Assurance Vector for Enterprise Policy Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in choosing appropriate authenticators for software applications, leading to ambiguity in enterprise policies and potential security weaknesses or poor user experience due to underfitting or overfitting of authenticators with session associations.
Innovation Solution
A computer-implemented system that uses a three-dimensional authentication vector to assess and prescribe authenticators based on Authenticator Strength Assurance Level (ASAL), Post Authentication Assurance Level (PAAL), and Origin Point Assurance Level (OPAL), integrating security, governance, and infrastructure mapping to ensure appropriate authentication policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If enterprise policies provide flexibility in authenticator selection, then ease of operation is improved, but security reliability deteriorates due to potential underfitting or overfitting of authenticators
Solution Approach 1:
The patent transforms authenticator selection from a qualitative policy decision into a quantitative parameter-based selection process. By defining specific parameters (assured party, authentication method, session association) and their corresponding values, the system enables automated matching of authenticators to application requirements through parameter comparison, thereby maintaining security reliability while improving operational ease.
Solution Approach 2:
The patent introduces an intermediary authentication policy framework that mediates between enterprise security requirements and application-specific needs. This framework acts as a translator between high-level security policies and concrete authenticator selections, using parameter-based rules to bridge the gap between policy intent and implementation, thus resolving the contradiction between flexibility and security.
2Reliability
If enterprise policies are made specific and restrictive, then security reliability is improved, but ease of operation worsens due to complexity in policy configuration and authenticator selection
Solution Approach 1:
The patent segments the authentication policy into distinct parameter components (assured party, authentication method, session association) that can be independently configured and combined. This segmentation allows security requirements to be broken down into manageable, reusable parameter sets that can be applied consistently across multiple applications, reducing configuration complexity while maintaining security specificity.
Solution Approach 2:
The patent creates universal parameter-based policy templates that can serve multiple applications and scenarios. By defining parameters with standardized values and relationships, the same policy framework can be reused across different contexts, reducing the need for custom policy configuration for each application while maintaining appropriate security controls.
3Manufacturing precision
If multiple parameters are considered for authenticator selection, then manufacturing precision is improved, but device complexity increases due to the multi-dimensional assessment framework
Solution Approach 1:
The patent adds dimensional structure to the parameter space by organizing parameters across three distinct dimensions (assured party, authentication method, session association) with multiple levels within each dimension. This dimensional organization enables precise authenticator selection through multi-dimensional matching while providing a structured framework that manages complexity through hierarchical classification rather than flat parameter enumeration.
Data Source
AI summary
A method comprising receiving, by a computer system, a parameter value for each of multiple parameters for an application for an enterprise and determining, by the computer system based on a first database table lookup, a recommended authentication vector for the application based on the parameter values. The recommended authentication vector comprises assurance level values for authenticator strength assurance level (ASAL), Post Authentication Assurance Level (PAAL), and Origin Point Assurance Level (OPAL). The method further comprises determining, by the computer system based on a second database table lookup, one or more enterprise-certified authentication infrastructures for the application based on the recommended authentication vector and implementing the one or more enterprise-certified authentication infrastructures in the application for a production deployment of the application by the enterprise.


