Authentication Domain Key Pair Binding Across Multiple Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face burdensome authentication processes when accessing multiple services hosted on different domains, requiring separate account registrations and key pairs, which increases complexity and user burden.

Innovation Solution

Implementing a method and system for device binding across multiple domains using an authentication domain, where a user device generates a key pair associated with an authentication domain, allowing access to multiple domains using a single key pair for authentication, thereby streamlining the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users register for separate accounts and generate key pairs for each domain, then each domain can be securely authenticated, but the user burden and authentication complexity increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication domain that serves multiple functions across different service domains. A single key pair generated with the authentication domain can be used to authenticate users across multiple different domains (e.g., pharmacy service, grocery service), eliminating the need for separate key pairs for each domain while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication domain acts as an intermediary between users and multiple service domains. Instead of users directly managing separate key pairs for each domain, the authentication domain mediates by providing a centralized key pair that can be used across all domains, simplifying the authentication process while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users create separate key pairs for each domain, then domain-specific security is maintained, but the time required for registration and authentication increases

Engineering Contradiction:
Improvedomain-specific securityVSAvoidregistration and authentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having users register and generate a single key pair with the authentication domain before accessing any service domains. This pre-authentication step establishes a reusable credential that can be applied to multiple domains, eliminating the need for repeated registration and key pair generation for each domain.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple key pairs are used for different domains, then each domain can be securely accessed, but the number of authentication steps and registrations increases

Engineering Contradiction:
Improveaccess securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple domain-specific authentication processes into a single unified authentication mechanism. By combining the authentication functions across different domains and using a single key pair managed by the authentication domain, the system reduces the number of separate authentication steps while maintaining security for each domain.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11831754B2Systems and methods for device binding across multiple domains using an authentication domain
Publication Date: 2023.11.28 AETNA INC
  • US11831754B2 patent drawing
  • US11831754B2 patent drawing
  • US11831754B2 patent drawing

AI summary

In some instances, a method for authenticating a user using key pair authentication is provided. The method comprises enrolling the user into key pair authentication by generating a private and public key pair for an authentication domain, accessing the content on the first domain based on enrolling the user into the key pair authentication with a key pair authentication server using the private and public key pair for the authentication domain, requesting access for different content on a second domain, based on enrolling the user into the key pair authentication for the first domain, redirecting a browser from the second domain to the authentication domain, and accessing the different content on the second domain based on performing the key pair authentication with the key pair authentication server using the private and public key pair for the authentication domain.