Delayed Authentication for On-Demand Identity Products

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems for on-demand products are inefficient and resource-intensive, often causing performance bottlenecks and consumer dissatisfaction due to time-consuming authentication processes, which can fail due to technical issues or incomplete information, leading to wasted resources and diminished user experience.

Innovation Solution

Implementing a configuration option for delayed authentication, allowing the provision of on-demand identity products to commence without immediate authentication, with restricted access until sensitive data is accessed, and enabling delayed billing based on specific criteria to ensure secure and efficient delivery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If immediate authentication is required before providing on-demand products, then data security is improved, but system performance and user experience deteriorate due to time-consuming authentication processes

Engineering Contradiction:
Improvedata securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary partial registration using PII without requiring complete authentication upfront. Authentication is delayed and completed later when the consumer actually accesses the on-demand product, allowing the system to prepare and stage the product delivery in advance while maintaining security through conditional suspension of authentication requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication requirement is made dynamic through conditional suspension - it is temporarily suspended during the partial registration and product provisioning phase, then reactivated when the consumer accesses the actual product. This dynamic approach allows the system to balance security needs with performance requirements at different stages of the transaction.

Inventive Principle:
Principle #15Dynamics

2Reliability

If complete authentication is performed upfront, then authentication reliability is improved, but resource utilization deteriorates due to failed authentications from technical issues or incomplete information

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs partial authentication using only PII initially, rather than requiring complete authentication upfront. This partial action reduces the computational resources consumed during the registration phase and minimizes the impact of potential authentication failures, while still enabling product provisioning to proceed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The authentication step is extracted and separated from the initial product provisioning process. Instead of being a prerequisite, authentication is delayed until the consumer actually accesses the product, thereby removing the bottleneck and resource consumption associated with upfront authentication while maintaining security when needed.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If authentication is delayed until product access, then system performance is improved, but security risk increases during the provisioning phase

Engineering Contradiction:
Improveresponse timeVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Different security measures are applied at different stages of the process. During the partial registration and product provisioning phase, minimal security (PII-based) is applied to enable fast processing. When the consumer accesses the actual product, full authentication is required, applying stronger security measures locally at the point of data access rather than uniformly throughout the entire process.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses PII as an intermediary credential that enables partial authentication and product provisioning before full authentication. This intermediary mechanism allows the system to balance security and performance by providing a middle-ground authentication approach that is more permissive than full authentication but more secure than no authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If traditional immediate billing is implemented, then revenue recognition is improved, but consumer protection compliance deteriorates due to billing before successful product delivery

Engineering Contradiction:
Improverevenue recognitionVSAvoidconsumer protection compliance
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary product provisioning and staging before final billing occurs. The product is prepared and made available to the consumer in advance, and billing is delayed until the consumer actually accesses the product. This preliminary action allows the system to recognize revenue more accurately based on actual product delivery rather than premature billing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback-based billing where the actual product access event triggers the billing process. Rather than billing immediately upon request, the system waits for feedback confirming that the consumer has accessed the product, ensuring that billing occurs only when the service has been successfully delivered and enhancing consumer protection compliance.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3916605A1Authentication systems and methods for on-demand products
Publication Date: 2021.12.01 CSIDENTITY CORP
  • EP3916605A1 patent drawingFigure 1
  • EP3916605A1 patent drawingFigure 2
  • EP3916605A1 patent drawingFigure 3

AI summary

In one embodiment, a method includes receiving, from a requestor, a request for an on-demand identity product in relation to an identity of a consumer, the request comprising personally identifying information (PII) of the consumer. The method also includes executing, using the PII, a partial registration of the consumer for the on-demand identity product, the partial registration omitting satisfaction of at least one security requirement. The method additionally includes determining whether delayed authentication is enabled for the on-demand identity product. Moreover, the method includes, responsive to a determination that delayed authentication is enabled for the on-demand identity product: conditionally suspending the at least one security requirement; initiating provision of the on-demand identity product to the requestor; and restricting the requestor's access to determined sensitive data resulting from the initiated provision at least until the at least one security requirement is satisfied.