Authentication Routing via Directory Groups for MFA Token Diversity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face inefficiencies and high costs in supporting multiple authentication token types in multi-factor authentication, making it difficult to add new methods and phase out obsolete ones while maintaining network security.

Innovation Solution

A layer-one network policy server utilizes directory service groups to route authentication requests to appropriate layer-two network policy servers based on user authentication types, allowing for efficient management and prioritization of authentication methods, with automatic decommissioning of unused infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple different types of authentication tokens are supported in a multi-factor authentication system, then user authentication flexibility is improved, but system complexity and cost increase

Engineering Contradiction:
Improveauthentication method diversityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments authentication methods into distinct layers: layer-one network policy servers handle high-level routing decisions based on user groups and authentication types, while layer-two network policy servers handle specific authentication token processing. This segmentation allows the system to support multiple authentication types without requiring every server to handle every authentication method, thereby reducing overall system complexity while maintaining versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Layer-one network policy servers act as intermediaries between clients and layer-two network policy servers. They receive authentication requests, determine the appropriate authentication type based on user identifying information, and route requests to the corresponding layer-two server. This intermediary layer abstracts the complexity of multiple authentication types from individual servers, allowing the system to support diverse authentication methods without proportionally increasing complexity at each component.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple authentication token types are supported simultaneously, then authentication versatility is improved, but infrastructure cost increases

Engineering Contradiction:
Improveauthentication type supportVSAvoidinfrastructure resources
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The system dynamically routes authentication requests based on the user's identifying information and group membership. Layer-one network policy servers determine which layer-two server to contact based on the authentication type required, ensuring that infrastructure resources are activated only when needed. This dynamic approach allows the system to support multiple authentication types without maintaining all infrastructure components in constant active state, thereby reducing overall resource consumption while maintaining versatility.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If new authentication methods are added to the system, then authentication capability is improved, but system complexity and deployment difficulty increase

Engineering Contradiction:
Improveauthentication method additionVSAvoidsystem deployment ease
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The layered architecture allows new authentication methods to be added by deploying new layer-two network policy servers that handle specific authentication types, without requiring modifications to layer-one servers or existing authentication implementations. Each layer-two server can be independently developed, tested, and deployed, making it easier to add new authentication methods while maintaining system stability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Layer-one network policy servers are designed with universal routing logic that can handle any authentication type through a standardized interface. When a new authentication method is introduced, the layer-one server can route requests to the new layer-two server using the same routing mechanisms already in place, eliminating the need to redesign the core routing infrastructure for each new authentication type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If obsolete authentication infrastructure is maintained for backward compatibility, then system reliability is improved, but resource efficiency decreases

Engineering Contradiction:
Improvebackward compatibilityVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system dynamically determines which layer-two network policy servers are needed based on current user authentication requirements. Obsolete authentication infrastructure can be maintained in the system but will simply not be activated unless users actually require those authentication types. This dynamic activation approach maintains backward compatibility for users who need legacy authentication methods while avoiding the constant resource consumption that would result from keeping all infrastructure components actively running.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12519839B2Enhanced user authentication system and method
Publication Date: 2026.01.06 CENTURYLINK INTELLECTUAL PROPERTY LLC
  • US12519839B2 patent drawing
  • US12519839B2 patent drawing
  • US12519839B2 patent drawing

AI summary

Systems and methods are provided to utilize information from a directory service to determine, at a layer-one network policy server, the appropriate layer-two network policy server to which an authentication request should be routed. For example, a first directory service group may be created that includes all users using a first authentication type, a second directory service group may be created that includes all users using a second authentication type, etc. The layer-one network policy server may periodically synchronize with the directory service to download information about users in the different directory service groups, update a markup language document with that information, and use the markup language document to help route incoming authentication requests to the correct layer-two network policy server for a particular authentication type. In addition, a priority may be set (and changed) by an administrator favoring one or more authentication types in a network.