Conditional Login Promotion via Policy Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face the inconvenience of maintaining separate authentication credentials for multiple network-based services, leading to cumbersome and redundant login processes, which can compromise security and user experience.

Innovation Solution

A conditional login promotion system that utilizes a cloud-based Policy Engine to authenticate a user's local operating system login with relying party entities, incorporating multiple authentication factors such as biometrics and passive device identifiers, thereby eliminating the need for repetitive logins and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users provide separate authentication credentials for each service, then security is maintained through independent authentication, but user convenience deteriorates due to cumbersome redundant logins

Engineering Contradiction:
Improvelogin convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges multiple authentication credentials into a single set of credentials that can be used across multiple services. The authentication system combines the user's local OS credentials with service-specific credentials to create a unified authentication mechanism that promotes the local login to multiple relying party entities simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements universal credentials that can authenticate a user to multiple different services. The local OS login credentials are designed to be multi-functional, serving as the basis for authentication across various relying party entities without requiring service-specific credential sets.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication factors are required, then security is enhanced through multi-factor authentication, but device complexity increases due to multiple credential management requirements

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct layers: the local OS authentication layer and the service-specific authentication layer. This segmentation allows each layer to handle specific authentication factors independently, simplifying the overall system architecture while maintaining multi-factor authentication capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that bridges the local OS credentials and service-specific credentials. This intermediary layer manages the combination and promotion of authentication factors, reducing the complexity burden on the user while maintaining security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If separate credentials are maintained for each service, then service-specific security requirements are met, but user time increases due to repetitive login processes

Engineering Contradiction:
Improvelogin timeVSAvoidservice-specific authentication flexibility
Core Design Contradiction:
Loss of timeVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary authentication at the local OS level before the user needs to access any service. By authenticating the user's identity and credentials in advance, the system eliminates the need for repetitive logins when accessing multiple services, significantly reducing login time while maintaining service-specific security requirements.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10237254B2Conditional login promotion
Publication Date: 2019.03.19 MCAFEE LLC
  • US10237254B2 patent drawing
  • US10237254B2 patent drawing
  • US10237254B2 patent drawing

AI summary

The present disclosure relates to a system and method for providing conditional login promotion. An example system includes at least one processor and at least one memory element, wherein the system is configured for receiving an indication of a local operating system login by a user from a client device associated with the user; receiving one or more authentication factors associated with the user from the client device; and determining whether the local operating system login is to be promoted to a relying party entity based upon the one or more authentication factors associated with the user.