Bulk MFA Enrollment in Identity Cloud Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multifactor authentication (MFA) solutions face challenges in efficiently enrolling large numbers of users, particularly in cloud-based systems, as they often require user intervention, re-validation of already verified credentials, and lack seamless integration with existing identity stores, leading to time-consuming and costly processes.

Innovation Solution

The implementation of bulk MFA enrollment in an identity cloud management system, where user identities and MFA information are imported in bulk, with auto-enrollment of MFA factors like time-based one-time passwords (TOTP), phone numbers, and emails, leveraging trusted data sources to automate the enrollment process without re-validation, and integrating with existing identity stores for seamless migration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional MFA enrollment methods are used, then user security is improved, but enrollment time and complexity increase significantly

Engineering Contradiction:
Improveuser securityVSAvoidenrollment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-validating user credentials and pre-configuring MFA factors before the actual enrollment process. User identities, contact information, and MFA security factors are retrieved and validated in advance from trusted data sources, allowing the enrollment to proceed automatically without time-consuming real-time verification steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The MFA enrollment process is designed to be self-service oriented, where the system automatically enrolls users based on existing trusted data without requiring manual user intervention. The system self-validates credentials, self-configures MFA factors, and self-completes the enrollment workflow, eliminating the need for administrative overhead and user participation in the enrollment process.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual MFA enrollment processes are used, then authentication security is maintained, but operational complexity and cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary layer that automatically bridges existing identity stores and MFA systems. This intermediary component handles the complex tasks of credential validation, MFA factor configuration, and enrollment coordination, shielding both the identity store and MFA system from direct complex interactions while maintaining security through automated mediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The enrollment system is designed with universal functionality to handle multiple data sources, user types, and MFA factors through a single unified process. The system can ingest user identities from various trusted sources, apply different validation rules, and configure multiple MFA factors (contact-based and non-contact-based) using the same automated workflow, reducing operational complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If bulk MFA enrollment is implemented, then enrollment efficiency is improved, but system integration complexity increases

Engineering Contradiction:
Improveenrollment efficiencyVSAvoidsystem integration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The bulk enrollment system is segmented into distinct modular components: identity validation module, MFA factor generation module, enrollment execution module, and verification module. Each segment handles a specific aspect of the bulk enrollment process independently, allowing for simplified integration with existing systems while maintaining high throughput. The segmentation enables parallel processing of user identities and MFA factors, improving efficiency without creating monolithic complexity.

Inventive Principle:
Principle #1Segmentation

4Extent of automation

If automated MFA enrollment is used, then user adoption is improved, but validation accuracy requirements increase

Engineering Contradiction:
Improveuser adoptionVSAvoidvalidation accuracy
Core Design Contradiction:
Extent of automationVSMeasurement precision

Solution Approach 1:

The automated enrollment system incorporates multiple feedback loops that continuously validate data accuracy and correctness. The system receives feedback from trusted data sources about user identity verification, contact information validity, and MFA factor configuration accuracy. This feedback mechanism allows the system to adjust validation parameters and re-verify critical data points, maintaining high validation accuracy while proceeding with automated enrollment at scale.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11611548B2Bulk multifactor authentication enrollment
Publication Date: 2023.03.21 ORACLE INT CORP
  • US11611548B2 patent drawing
  • US11611548B2 patent drawing
  • US11611548B2 patent drawing

AI summary

Embodiments perform bulk multifactor authentication (MFA) enrollment in an identity cloud management system. An entity can be created in the identity cloud management system, where the entity is issued a credential that includes a permissions scope for communicating with the identity cloud management system. A bulk set of user identities and MFA enrollment information including MFA security factors for the user identities and a status for the user identities can be received in association with the credential, where the MFA security factors include a mix of communication addresses and shared secrets. A subset of the user identities that include a status that indicates MFA enrollment can be enrolled, where the enrolling includes creating an MFA footprint for the subset of user identities within an MFA database, and each created MFA footprint includes a received MFA security factor. Access to cloud-based services or applications can be secured using the created MFA footprints, where the secured access includes secure API calls to the identity cloud management system.