Authentication Platform for Managed Security Service Providers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user authentication methods, such as user ID and password schemes, are inefficient and insecure in distributed computing environments, requiring repetitive sign-on processes and being vulnerable to unauthorized access due to the lack of secure transmission and varying encoding methods among different vendors.
Innovation Solution
A two-factor authentication platform that integrates authentication systems from various vendors, utilizing a secret PIN and a continually changing token code, where the token code is synchronized with a password server, ensuring secure user authentication and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional user ID and password schemes are used for authentication, then the authentication process is simple to implement, but the security is compromised due to vulnerable transmission and lack of secure path
Solution Approach 1:
The authentication system is segmented into multiple independent components: authentication clients, authentication servers, security tokens, and credential vaults. Each component performs a specific function (e.g., tokens generate one-time passwords, servers validate credentials), collectively providing robust security without requiring any single component to be overly complex.
Solution Approach 2:
An authentication server acts as an intermediary between users and protected resources. The server receives authentication requests, validates credentials through secure protocols, and manages credential vaults. This intermediary layer protects the authentication process from direct exposure to potential attackers while maintaining system security.
2Ease of operation
If traditional sign-on procedures are used across multiple computer systems, then each system can be accessed independently, but the user experience deteriorates due to repetitive sign-on requirements
Solution Approach 1:
The authentication system provides universal access across multiple computer systems and networks through a single set of credentials. Users authenticate once to the authentication server, which then manages their access to multiple resources, eliminating the need for separate sign-on procedures at each system while maintaining security through centralized credential management.
3Adaptability or versatility
If authentication credentials are transmitted over the network, then remote access is enabled, but security is compromised due to potential interception by network analyzers
Solution Approach 1:
The system uses one-time passwords that are generated periodically by security tokens and expire after a single use. This periodic regeneration of credentials ensures that even if credentials are intercepted during transmission, they become immediately invalid, preventing replay attacks and ensuring secure remote access.
Solution Approach 2:
The authentication system dynamically changes credential parameters by generating unique one-time passwords for each authentication attempt. These credentials have different values each time they are used and expire after validation, transforming static password transmission into dynamic, time-limited credential exchange that resists interception.
4Adaptability or versatility
If multiple vendor authentication devices are integrated, then authentication options are expanded, but system complexity increases due to different encoding and validation methods
Solution Approach 1:
The authentication server implements universal support for multiple authentication device types and vendor protocols. It provides a unified interface that handles different encoding and validation methods internally, allowing diverse authentication devices to be integrated without increasing the complexity of the overall system architecture.
Solution Approach 2:
The authentication server acts as an intermediary layer between various vendor-specific authentication devices and the protected systems. It translates and normalizes different authentication protocols and encoding methods into a unified validation process, eliminating the need for complex point-to-point integrations between each device vendor and each target system.
Data Source
AI summary
An authentication management platform that enables authentication systems from various vendors to be integrated into a single service offering. The disclosed arrangement can support multiple, distinct customers and multiple primary authentication servers on a single platform. The management platform provides access only to users that enter a valid passcode comprising both: (1) a personal identification number (PIN) and (2) the current code generated by a security token card assigned to that user. The authentication management platform may be configured to be controlled and maintained by the subscriber to the system, or may be serviced/maintained by a third party service provider.


