Client Device Authentication with Unified API Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital servicing platforms for business banking fail to support the evolving needs of businesses, requiring multiple credentials for interactions and lacking robust security, leading to vulnerabilities and inefficiencies.
Innovation Solution
Implementing a security architecture with API policies and a backend system that uses OAuth tokens and TLS encryption to make user identity and entitlements immutable, offloading authentication and authorization from front-end components to a secure back-end environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current digital servicing platforms are used, then businesses can access financial services, but the systems lack robust security and require multiple credentials, creating vulnerabilities
Solution Approach 1:
The patent merges authentication and authorization functions into a unified policy enforcement interceptor that intercepts API calls and validates credentials through a centralized policy information point, eliminating the need for multiple separate credential systems while enhancing security
Solution Approach 2:
The policy enforcement interceptor acts as an intermediary between client devices and the enterprise system, mediating authentication and authorization by intercepting API calls and validating credentials through the policy information point, thereby centralizing security control
2Reliability
If authentication and authorization are handled by front-end components, then systems can process requests, but security vulnerabilities arise
Solution Approach 1:
The patent extracts authentication and authorization logic from front-end components and relocates it to a back-end policy enforcement interceptor, removing security vulnerabilities from the front-end while maintaining seamless user experience through transparent credential validation
3Adaptability or versatility
If platforms are updated with current digital experience expectations, then servicing capabilities improve, but significant updates are required impacting the workforce
Solution Approach 1:
The policy enforcement interceptor provides universal authentication and authorization capabilities that work across multiple systems and applications, enabling the enterprise system to meet current digital experience expectations without requiring separate credential systems for each application
Data Source
AI summary
A system and method are provided for authenticating client devices communicating with an enterprise system. The method includes providing a policy enforcement interceptor to intercept API calls and enabling the policy enforcement interceptor to communicate with a policy information point to query the at least one endpoint for entitlements associated with an account. The method also includes intercepting an API call to the application API, communicating with the policy information point to determine entitlements associated with the account by having the policy information point query an entitlements database and, when the entitlements returned to the policy enforcement interceptor are valid, invoking a policy decision point to validate the client device. The method also includes, when the client device is validated, permitting invocation of the API. The method also includes providing an API response to the client device to permit access to the application via the API.


