Authentication Routing via Directory Groups for MFA Token Diversity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face inefficiencies and high costs in supporting multiple authentication token types in multi-factor authentication, making it difficult to add new methods and phase out obsolete ones while maintaining network security.
Innovation Solution
A layer-one network policy server utilizes directory service groups to route authentication requests to appropriate layer-two network policy servers based on user authentication types, allowing for efficient management and prioritization of authentication methods, with automatic decommissioning of unused infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple different types of authentication tokens are supported in a multi-factor authentication system, then user authentication flexibility is improved, but system complexity and cost increase
Solution Approach 1:
The system segments authentication methods into distinct layers: layer-one network policy servers handle high-level routing decisions based on user groups and authentication types, while layer-two network policy servers handle specific authentication token processing. This segmentation allows the system to support multiple authentication types without requiring every server to handle every authentication method, thereby reducing overall system complexity while maintaining versatility.
Solution Approach 2:
Layer-one network policy servers act as intermediaries between clients and layer-two network policy servers. They receive authentication requests, determine the appropriate authentication type based on user identifying information, and route requests to the corresponding layer-two server. This intermediary layer abstracts the complexity of multiple authentication types from individual servers, allowing the system to support diverse authentication methods without proportionally increasing complexity at each component.
2Adaptability or versatility
If multiple authentication token types are supported simultaneously, then authentication versatility is improved, but infrastructure cost increases
Solution Approach 1:
The system dynamically routes authentication requests based on the user's identifying information and group membership. Layer-one network policy servers determine which layer-two server to contact based on the authentication type required, ensuring that infrastructure resources are activated only when needed. This dynamic approach allows the system to support multiple authentication types without maintaining all infrastructure components in constant active state, thereby reducing overall resource consumption while maintaining versatility.
3Adaptability or versatility
If new authentication methods are added to the system, then authentication capability is improved, but system complexity and deployment difficulty increase
Solution Approach 1:
The layered architecture allows new authentication methods to be added by deploying new layer-two network policy servers that handle specific authentication types, without requiring modifications to layer-one servers or existing authentication implementations. Each layer-two server can be independently developed, tested, and deployed, making it easier to add new authentication methods while maintaining system stability.
Solution Approach 2:
Layer-one network policy servers are designed with universal routing logic that can handle any authentication type through a standardized interface. When a new authentication method is introduced, the layer-one server can route requests to the new layer-two server using the same routing mechanisms already in place, eliminating the need to redesign the core routing infrastructure for each new authentication type.
4Reliability
If obsolete authentication infrastructure is maintained for backward compatibility, then system reliability is improved, but resource efficiency decreases
Solution Approach 1:
The system dynamically determines which layer-two network policy servers are needed based on current user authentication requirements. Obsolete authentication infrastructure can be maintained in the system but will simply not be activated unless users actually require those authentication types. This dynamic activation approach maintains backward compatibility for users who need legacy authentication methods while avoiding the constant resource consumption that would result from keeping all infrastructure components actively running.
Data Source
AI summary
Systems and methods are provided to utilize information from a directory service to determine, at a layer-one network policy server, the appropriate layer-two network policy server to which an authentication request should be routed. For example, a first directory service group may be created that includes all users using a first authentication type, a second directory service group may be created that includes all users using a second authentication type, etc. The layer-one network policy server may periodically synchronize with the directory service to download information about users in the different directory service groups, update a markup language document with that information, and use the markup language document to help route incoming authentication requests to the correct layer-two network policy server for a particular authentication type. In addition, a priority may be set (and changed) by an administrator favoring one or more authentication types in a network.


