Client Authentication Configuration via Dynamic GUI Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SSL client authentication methods are inconvenient for users, as they lack efficient mechanisms for changing authentication configurations during sessions and provide inadequate visual feedback on authentication status, often prompting users for certificate selection even when no valid certificates are available, leading to potential unauthenticated sessions.

Innovation Solution

A method and system that automatically configures client authentication based on stored data and provides a graphical user interface for users to change authentication settings, offering visual feedback on authentication status and allowing selection of certificates or opting out of authentication, thereby streamlining the authentication process and enhancing user control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If client applications are configured to automatically select a certificate, then the authentication process is streamlined and user convenience is improved, but the user loses the ability to change authentication configuration during a session

Engineering Contradiction:
Improveauthentication process convenienceVSAvoidauthentication configuration flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic authentication configuration that allows users to change certificate selection during an SSL session. The system transitions from static automatic selection to dynamic reconfigurable selection, enabling users to switch between automatic selection, manual selection, and opt-out modes without closing the application window or disrupting the session.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If client applications prompt the user for certificate selection every time, then the user has full control over authentication, but the user experience deteriorates due to repeated prompts even when only one certificate is available

Engineering Contradiction:
Improveauthentication controlVSAvoiduser experience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements a hybrid approach where the system performs partial automatic selection (when only one certificate is available or based on user preference) while retaining the option for full manual control. The GUI allows users to choose between automatic selection, manual selection, and opt-out modes, providing appropriate level of automation without excessive prompting.

Inventive Principle:
Principle #16Partial or excessive action

3Device complexity

If the system provides no visual feedback on authentication status, then the system complexity is reduced, but the user cannot determine whether authentication is being used

Engineering Contradiction:
Improvesystem complexityVSAvoidauthentication status information
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent introduces visual feedback mechanisms in the GUI that display authentication status, current certificate selection, and authentication mode. The system provides real-time information about whether authentication is being used and which certificate is selected, enabling users to make informed decisions without increasing fundamental system complexity.

Inventive Principle:
Principle #23Feedback

4Reliability

If the system requires closing application windows or clearing SSL certificate cache to change authentication configuration, then authentication security is maintained, but productivity decreases due to session disruption

Engineering Contradiction:
Improveauthentication securityVSAvoidsession continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary configuration options where users can set their authentication preferences in advance. The system stores and retrieves these preferences automatically, allowing users to change authentication configuration during sessions without disrupting connectivity. The GUI enables users to pre-configure automatic selection, manual selection, or opt-out modes for different servers.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9985956B2Client authentication
Publication Date: 2018.05.29 RED HAT INC
  • US9985956B2 patent drawing
  • US9985956B2 patent drawing
  • US9985956B2 patent drawing

AI summary

A client authentication system receives authentication requests associated with a web page in response to a client computing system requesting access to the web page. The authentication system determines whether a storage device contains configurations for the authentication requests. The authentication system configures client authentication for the client authentication requests in view of whether the storage device includes the configurations for the authentication requests. The GUI allows control to change the client authentication configuration for at least one of the authentication requests.