Authentication Assurance Vector for Enterprise Policy Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in choosing appropriate authenticators for software applications, leading to ambiguity in enterprise policies and potential security weaknesses or poor user experience due to underfitting or overfitting of authenticators with session associations.

Innovation Solution

A computer-implemented system that uses a three-dimensional authentication vector to assess and prescribe authenticators based on Authenticator Strength Assurance Level (ASAL), Post Authentication Assurance Level (PAAL), and Origin Point Assurance Level (OPAL), integrating security, governance, and infrastructure mapping to ensure appropriate authentication policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If enterprise policies provide flexibility in authenticator selection, then ease of operation is improved, but security reliability deteriorates due to potential underfitting or overfitting of authenticators

Engineering Contradiction:
Improveease of authenticator selectionVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms authenticator selection from a qualitative policy decision into a quantitative parameter-based selection process. By defining specific parameters (assured party, authentication method, session association) and their corresponding values, the system enables automated matching of authenticators to application requirements through parameter comparison, thereby maintaining security reliability while improving operational ease.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary authentication policy framework that mediates between enterprise security requirements and application-specific needs. This framework acts as a translator between high-level security policies and concrete authenticator selections, using parameter-based rules to bridge the gap between policy intent and implementation, thus resolving the contradiction between flexibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprise policies are made specific and restrictive, then security reliability is improved, but ease of operation worsens due to complexity in policy configuration and authenticator selection

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of policy configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication policy into distinct parameter components (assured party, authentication method, session association) that can be independently configured and combined. This segmentation allows security requirements to be broken down into manageable, reusable parameter sets that can be applied consistently across multiple applications, reducing configuration complexity while maintaining security specificity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal parameter-based policy templates that can serve multiple applications and scenarios. By defining parameters with standardized values and relationships, the same policy framework can be reused across different contexts, reducing the need for custom policy configuration for each application while maintaining appropriate security controls.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Manufacturing precision

If multiple parameters are considered for authenticator selection, then manufacturing precision is improved, but device complexity increases due to the multi-dimensional assessment framework

Engineering Contradiction:
Improveprecision of authenticator selectionVSAvoidcomplexity of assessment system
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent adds dimensional structure to the parameter space by organizing parameters across three distinct dimensions (assured party, authentication method, session association) with multiple levels within each dimension. This dimensional organization enables precise authenticator selection through multi-dimensional matching while providing a structured framework that manages complexity through hierarchical classification rather than flat parameter enumeration.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12513129B1Multi-dimensional model for assessing authentication assurance levels
Publication Date: 2025.12.30 MORGAN STANLEY SERVICES GROUP INC
  • US12513129B1 patent drawing
  • US12513129B1 patent drawing
  • US12513129B1 patent drawing

AI summary

A method comprising receiving, by a computer system, a parameter value for each of multiple parameters for an application for an enterprise and determining, by the computer system based on a first database table lookup, a recommended authentication vector for the application based on the parameter values. The recommended authentication vector comprises assurance level values for authenticator strength assurance level (ASAL), Post Authentication Assurance Level (PAAL), and Origin Point Assurance Level (OPAL). The method further comprises determining, by the computer system based on a second database table lookup, one or more enterprise-certified authentication infrastructures for the application based on the recommended authentication vector and implementing the one or more enterprise-certified authentication infrastructures in the application for a production deployment of the application by the enterprise.