Authentication Platform for Managed Security Service Providers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user authentication methods, such as user ID and password schemes, are inefficient and insecure in distributed computing environments, requiring repetitive sign-on processes and being vulnerable to unauthorized access due to the lack of secure transmission and varying encoding methods among different vendors.

Innovation Solution

A two-factor authentication platform that integrates authentication systems from various vendors, utilizing a secret PIN and a continually changing token code, where the token code is synchronized with a password server, ensuring secure user authentication and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional user ID and password schemes are used for authentication, then the authentication process is simple to implement, but the security is compromised due to vulnerable transmission and lack of secure path

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent components: authentication clients, authentication servers, security tokens, and credential vaults. Each component performs a specific function (e.g., tokens generate one-time passwords, servers validate credentials), collectively providing robust security without requiring any single component to be overly complex.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authentication server acts as an intermediary between users and protected resources. The server receives authentication requests, validates credentials through secure protocols, and manages credential vaults. This intermediary layer protects the authentication process from direct exposure to potential attackers while maintaining system security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional sign-on procedures are used across multiple computer systems, then each system can be accessed independently, but the user experience deteriorates due to repetitive sign-on requirements

Engineering Contradiction:
Improveaccess convenienceVSAvoidtime spent on repetitive sign-on
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The authentication system provides universal access across multiple computer systems and networks through a single set of credentials. Users authenticate once to the authentication server, which then manages their access to multiple resources, eliminating the need for separate sign-on procedures at each system while maintaining security through centralized credential management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If authentication credentials are transmitted over the network, then remote access is enabled, but security is compromised due to potential interception by network analyzers

Engineering Contradiction:
Improveremote access capabilityVSAvoidtransmission security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system uses one-time passwords that are generated periodically by security tokens and expire after a single use. This periodic regeneration of credentials ensures that even if credentials are intercepted during transmission, they become immediately invalid, preventing replay attacks and ensuring secure remote access.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The authentication system dynamically changes credential parameters by generating unique one-time passwords for each authentication attempt. These credentials have different values each time they are used and expire after validation, transforming static password transmission into dynamic, time-limited credential exchange that resists interception.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If multiple vendor authentication devices are integrated, then authentication options are expanded, but system complexity increases due to different encoding and validation methods

Engineering Contradiction:
Improveauthentication device varietyVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication server implements universal support for multiple authentication device types and vendor protocols. It provides a unified interface that handles different encoding and validation methods internally, allowing diverse authentication devices to be integrated without increasing the complexity of the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication server acts as an intermediary layer between various vendor-specific authentication devices and the protected systems. It translates and normalizes different authentication protocols and encoding methods into a unified validation process, eliminating the need for complex point-to-point integrations between each device vendor and each target system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7707626B2Authentication management platform for managed security service providers
Publication Date: 2010.04.27 RAKUTEN GROUP INC
  • US7707626B2 patent drawing
  • US7707626B2 patent drawing
  • US7707626B2 patent drawing

AI summary

An authentication management platform that enables authentication systems from various vendors to be integrated into a single service offering. The disclosed arrangement can support multiple, distinct customers and multiple primary authentication servers on a single platform. The management platform provides access only to users that enter a valid passcode comprising both: (1) a personal identification number (PIN) and (2) the current code generated by a security token card assigned to that user. The authentication management platform may be configured to be controlled and maintained by the subscriber to the system, or may be serviced/maintained by a third party service provider.