Authentication Service Security Level Combination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In ubiquitous computing environments, consistent and reliable authentication becomes challenging due to varying capabilities of mobile devices, which often lack specific authentication mechanisms required by services, limiting access to protected resources.
Innovation Solution
A method where an authorization service defines a demanded level of security, allowing users to provide one or a combination of authentication mechanisms, with each mechanism assigned a security level, enabling flexible authentication independent of specific mechanisms, using subjective logic to combine security levels and trust opinions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a specific authentication mechanism is required by a service, then the security level can be ensured, but mobile devices lacking this mechanism cannot access protected resources
Solution Approach 1:
The patent changes the authentication parameter from a specific mechanism type to a security level threshold. Instead of requiring a particular authentication mechanism, the system evaluates multiple authentication mechanisms based on their security levels and combines them to meet the demanded security threshold, enabling devices with varying capabilities to access services.
Solution Approach 2:
The patent creates a universal authentication framework that works across diverse devices by accepting multiple types of authentication mechanisms (biometric, knowledge-based, possession-based) and evaluating them through a common security level metric, making the system adaptable to various device capabilities while maintaining security requirements.
2Adaptability or versatility
If multiple authentication mechanisms are combined to achieve demanded security level, then flexibility and device compatibility improve, but the complexity of authentication evaluation increases
Solution Approach 1:
The patent introduces an intermediary authentication service that mediates between the client's authentication mechanisms and the service's security requirements. This intermediary evaluates security levels, combines authentication results, and makes authorization decisions, simplifying the overall system architecture while handling the complexity of multi-mechanism evaluation.
Solution Approach 2:
The patent transforms the complex problem of evaluating multiple authentication mechanisms into a simpler parameter-based evaluation system. Each mechanism is assigned a security level parameter, and the system combines these parameters mathematically to determine if the demanded security threshold is met, reducing evaluation complexity.
3Adaptability or versatility
If authentication is independent from specific mechanisms, then device compatibility improves, but ensuring consistent security levels across different mechanisms becomes more difficult
Solution Approach 1:
The patent establishes a standardized security level parameter scale (e.g., 0-100) that can be applied uniformly across different authentication mechanism types. This parameter transformation enables consistent measurement and comparison of security levels regardless of the specific mechanism used, facilitating mechanism-independent authentication while maintaining security consistency.
Data Source
AI summary
A computer-implemented method for authentication involves defining a level of trust required for access to a resource independently of any particular authentication mechanism or instance, determining levels of trust associated with a plurality of authentication instances, and selecting and combining two or more of the authentication instances to meet or exceed the required level of trust.


