Authentication Hub Routing for Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for authenticating access requests across various client devices, resource management computers, and data processing servers are complex and prone to security breaches, leading to potential leaks of sensitive authentication information.

Innovation Solution

The implementation of an authentication hub that provides centralized routing and processing of access requests, restricting the distribution of authentication information based on sensitivity, trust levels, and resource security, while minimizing the amount of information sent to data processing servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication information is distributed to multiple data processing servers for validation, then resource security is improved, but the risk of information leakage increases

Engineering Contradiction:
Improveresource securityVSAvoidinformation leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments authentication information into different types (device information, account information, transaction information) and routes different segments to different specialized data processing servers. This segmentation reduces the risk that a single server breach exposes all authentication information, as each server only handles specific types of data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication hub serves as an intermediary between client devices and multiple data processing servers. It receives authentication requests, determines the appropriate server based on the type of validation needed, and routes requests accordingly. This intermediary role prevents direct exposure of all authentication information to any single server.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple data processing servers are used for authentication validation, then authentication capability is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication hub provides universal functionality by handling multiple types of authentication validations through a single interface. It can route device information validation, account validation, and transaction validation to appropriate servers, making the system adaptable to various authentication needs without requiring separate systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication hub simplifies system complexity by acting as a central intermediary that manages communication between client devices and multiple specialized servers. It abstracts the complexity of multiple servers from client devices, providing a unified interface while maintaining the benefits of specialized validation capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If sensitive authentication information is sent to third-party data processing servers, then validation accuracy is improved, but privacy protection deteriorates

Engineering Contradiction:
Improvevalidation accuracyVSAvoidprivacy protection
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments authentication information and sends only the necessary segments to third-party servers for validation. For example, device information is sent to device validation servers, while account information is handled by account validation servers. This segmentation maintains validation accuracy while minimizing the exposure of sensitive personal information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different types of authentication information are handled with different levels of privacy protection based on their sensitivity and purpose. The system applies appropriate routing and validation methods tailored to each information type, ensuring that only the minimum necessary information is exposed to external servers while maintaining validation accuracy.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12339992B2Data security hub
Publication Date: 2025.06.24 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12339992B2 patent drawing
  • US12339992B2 patent drawing
  • US12339992B2 patent drawing

AI summary

Client devices can send access request messages to resource management computers to request access to a resource. A data security hub can provide centralized routing between different client devices, resource management computers, and authentication data processing servers. The data security hub can reduce the risk of sensitive authentication information from leaking (e.g., due to a breach) by limiting the amount or types of authentication information distributed to the data processing servers. The data security hub can limited the authentication information being distributed based on its sensitivity, the trust level of the client device, and the security level of the requested resource. The data security hub can also evaluate the client devices and data processing servers to identify security breaches and can cancel or reroute access requests accordingly. Thus, the data security hub can maintain resource security while better preserving the privacy of the client device's authentication information.