Common Authentication Service Dynamic Challenge Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for networked systems are costly, intrusive, limited in portability, and ineffective against common attacks like phishing and man-in-the-middle attacks, especially at self-service channels where human interaction is absent, and they struggle to provide strong authentication across multiple devices and applications.
Innovation Solution
A common authentication service (CAS) that uses a dynamic authentication library model, allowing for the creation and management of unique authentication challenges and responses, which can be tailored based on user-defined criteria, device type, and risk profiles, eliminating the need for tokens or biometric readers, and providing a strong, cost-effective, and portable authentication solution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If token-based two factor authentication is used, then authentication strength is improved, but cost and user intrusiveness increase
Solution Approach 1:
The patent extracts the authentication challenge mechanism from physical tokens and relocates it to a centralized server system. The server dynamically generates and manages authentication challenges, eliminating the need for users to carry or manage physical tokens while maintaining strong authentication through multiple challenges that test different knowledge domains.
Solution Approach 2:
The patent creates virtual copies of authentication challenges that can be presented multiple times without consuming physical tokens. Each challenge is a digital representation of an authentication test that can be regenerated and reused, replacing the single-use nature of physical tokens with reusable digital challenge instances.
2Reliability
If device-specific authentication is used, then security is improved, but portability across devices and applications deteriorates
Solution Approach 1:
The patent creates a universal authentication service that can operate across multiple devices, applications, and platforms. The authentication challenges are device-agnostic and can be presented through various interfaces (web browsers, mobile apps, desktop applications), allowing the same authentication mechanism to serve multiple functions and platforms without requiring device-specific implementations.
Solution Approach 2:
The patent introduces a centralized authentication server as an intermediary between users and various applications/devices. This mediator manages all authentication challenges centrally, allowing users to authenticate to multiple services without needing separate authentication mechanisms for each device or application, thereby enabling portability while maintaining security.
3Ease of manufacture
If traditional authentication libraries are used, then implementation is simplified, but vulnerability to common attacks like phishing and man-in-the-middle increases
Solution Approach 1:
The patent implements dynamic authentication challenges that change with each authentication attempt and are tailored to the specific user and context. Rather than using static authentication libraries, the system generates challenges in real-time based on user profiles, risk assessments, and contextual information, making it difficult for attackers to use pre-captured credentials or phishing techniques.
Solution Approach 2:
The patent incorporates feedback mechanisms where the authentication system continuously monitors authentication attempts, user behavior, and system responses. This feedback is used to dynamically adjust challenge difficulty, select appropriate challenge types, and update user profiles, creating a responsive authentication system that adapts to detected threats and reduces vulnerability to attacks.
Data Source
AI summary
System architecture for network connected applications, devices, users, and web services providing security effected by means for managing interaction with an authentication library that effects a correlation between the use and creation of library entries having predetermined correlation indicia for effecting strong authentication of users and participants within the network. A common authentication service (CAS) based upon an XML or web services protocol is described.


