Data Shield Server Proxy for Multi-Factor Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges with managing multiple online account passwords, leading to security risks due to the need for unique credentials for each service, and existing systems lack effective protection against unauthorized access and credential replay attacks.

Innovation Solution

Implementing a data shield server that requires multi-factor authentication (MFA) and conceals host address and port information, allowing users to connect indirectly through a unique port assigned to their identity, ensuring only authorized access to data resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users use unique passwords for each online service to maintain security, then security risk is reduced, but the complexity of managing multiple credentials increases and usability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a data shield server as an intermediary between users and online services. The server manages credentials centrally, allowing users to access multiple services without memorizing individual passwords. The shield server acts as a mediator that handles authentication to multiple services using a single user credential, thus maintaining security while simplifying password management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If companies require employees to regularly change passwords to maintain security, then security is improved, but the burden on employees increases and productivity decreases

Engineering Contradiction:
ImprovesecurityVSAvoidemployee efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The data shield server enables employees to access multiple corporate services without manually entering credentials for each service. The system automatically manages authentication to multiple services, eliminating the need for employees to repeatedly change or enter passwords. This self-service approach maintains security while removing the productivity burden of frequent password changes.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If direct access to host systems is allowed to simplify operations, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveaccess simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent positions the data shield server as a mandatory intermediary between users and host systems. All access requests must route through the shield server, which verifies credentials and manages authentication to multiple services. This intermediary architecture maintains operational simplicity for users while enforcing security controls, as the shield server mediates all access and can revoke or modify permissions centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If multiple services are accessed directly without centralization to maintain service independence, then system autonomy is preserved, but security monitoring and auditing become difficult

Engineering Contradiction:
Improveservice independenceVSAvoidaudit trail
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent merges authentication and access management functions into a centralized data shield server while preserving service independence. The shield server consolidates credential management and authentication logging for multiple services, creating a unified audit trail. Services remain independently operational, but the shield server combines security monitoring capabilities, enabling comprehensive auditing of access across all services without compromising their autonomous functionality.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11855993B2Data shield system with multi-factor authentication
Publication Date: 2023.12.26 DELINEA INC
  • US11855993B2 patent drawing
  • US11855993B2 patent drawing
  • US11855993B2 patent drawing

AI summary

Techniques to facilitate protection of data resources from unauthorized access are disclosed herein. In at least one implementation, a data shield server instructs a user to replace an address and a port associated with a data resource with an updated address associated with the data shield server and a unique port that is uniquely assigned to the user. A request from the user to access the data resource is received at the updated address associated with the data shield server and on the unique port that is uniquely assigned to the user. In response to the request, the user is authenticated using multi-factor authentication to verify that an identity of the user that submitted the request matches the user assigned to the unique port on which the request was received. Upon successful authentication, the data shield server operates as a proxy to connect the user through to the data resource.