Conditional Login Promotion via Policy Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face the inconvenience of maintaining separate authentication credentials for multiple network-based services, leading to cumbersome and redundant login processes, which can compromise security and user experience.
Innovation Solution
A conditional login promotion system that utilizes a cloud-based Policy Engine to authenticate a user's local operating system login with relying party entities, incorporating multiple authentication factors such as biometrics and passive device identifiers, thereby eliminating the need for repetitive logins and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users provide separate authentication credentials for each service, then security is maintained through independent authentication, but user convenience deteriorates due to cumbersome redundant logins
Solution Approach 1:
The patent merges multiple authentication credentials into a single set of credentials that can be used across multiple services. The authentication system combines the user's local OS credentials with service-specific credentials to create a unified authentication mechanism that promotes the local login to multiple relying party entities simultaneously.
Solution Approach 2:
The patent implements universal credentials that can authenticate a user to multiple different services. The local OS login credentials are designed to be multi-functional, serving as the basis for authentication across various relying party entities without requiring service-specific credential sets.
2Reliability
If multiple authentication factors are required, then security is enhanced through multi-factor authentication, but device complexity increases due to multiple credential management requirements
Solution Approach 1:
The patent segments the authentication system into distinct layers: the local OS authentication layer and the service-specific authentication layer. This segmentation allows each layer to handle specific authentication factors independently, simplifying the overall system architecture while maintaining multi-factor authentication capabilities.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that bridges the local OS credentials and service-specific credentials. This intermediary layer manages the combination and promotion of authentication factors, reducing the complexity burden on the user while maintaining security requirements.
3Loss of time
If separate credentials are maintained for each service, then service-specific security requirements are met, but user time increases due to repetitive login processes
Solution Approach 1:
The patent performs preliminary authentication at the local OS level before the user needs to access any service. By authenticating the user's identity and credentials in advance, the system eliminates the need for repetitive logins when accessing multiple services, significantly reducing login time while maintaining service-specific security requirements.
Data Source
AI summary
The present disclosure relates to a system and method for providing conditional login promotion. An example system includes at least one processor and at least one memory element, wherein the system is configured for receiving an indication of a local operating system login by a user from a client device associated with the user; receiving one or more authentication factors associated with the user from the client device; and determining whether the local operating system login is to be promoted to a relying party entity based upon the one or more authentication factors associated with the user.


