Dynamic Authentication Broker with Non-Binary Decision Logic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication techniques lack flexibility to adapt to changing environments and do not effectively accommodate non-binary authentication methods, limiting their ability to provide secure access to resources.
Innovation Solution
A method that dynamically determines multiple authentication servers and their invocation order for user authentication, incorporating both binary and non-binary authentication decisions through an authentication broker that employs pre-flow, in-flow, and decision rules, including machine learning for adaptive decision-making.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional sequential multi-factor authentication is used, then authentication security is maintained, but system flexibility and adaptability to changing environments deteriorate
Solution Approach 1:
The authentication system dynamically determines the invocation order of multiple authentication servers based on pre-flow rules evaluating authentication request characteristics. The system can adjust the authentication flow in real-time by evaluating in-flow rules during the process and applying decision rules to authentication results, transforming a static sequential authentication process into a dynamic adaptive system that maintains security while improving flexibility.
Solution Approach 2:
The patent introduces an authentication broker as an intermediary component that coordinates between the application server and multiple authentication servers. The broker evaluates rules, determines invocation orders, and processes authentication results, allowing the system to maintain security policies while adapting to different authentication scenarios and environments without requiring changes to the core authentication servers.
2Adaptability or versatility
If traditional binary authentication decisions are used, then authentication process simplicity is maintained, but ability to accommodate non-binary authentication methods deteriorates
Solution Approach 1:
The system changes the parameter space of authentication decisions from binary (accept/reject) to multi-valued outcomes including accept, reject, proceed to additional authentication, and continue. The decision rules evaluate authentication results and determine next steps based on these expanded parameters, allowing the system to accommodate non-binary authentication methods like risk scoring and confidence levels while managing complexity through structured rule evaluation.
Solution Approach 2:
The authentication process is segmented into distinct phases: pre-flow rule evaluation to determine initial invocation order, in-flow rule evaluation during authentication to adjust the process dynamically, and decision rule evaluation to determine final outcomes. This segmentation allows the system to handle complex non-binary authentication methods by breaking down the decision-making process into manageable, rule-based stages.
3Adaptability or versatility
If dynamic determination of authentication servers and invocation order is implemented, then authentication flexibility is improved, but system complexity increases
Solution Approach 1:
The authentication broker serves as an intermediary that absorbs and manages the complexity of dynamic rule evaluation and server coordination. By centralizing the logic for evaluating pre-flow, in-flow, and decision rules in the broker rather than distributing complexity across multiple servers, the system achieves dynamic flexibility while containing system complexity in a single manageable component.
Solution Approach 2:
The system implements feedback mechanisms where authentication results from one server influence the invocation order and selection of subsequent authentication servers through in-flow rule evaluation. This feedback loop allows the system to adapt dynamically based on actual authentication outcomes while maintaining manageable complexity through rule-based decision logic that processes feedback systematically.
Data Source
AI summary
User authentication techniques are provided for multiple authentication sources and for non-binary authentication decisions. An authentication request is received from an application server to authenticate a user for access to a protected resource. Pre-flow rules and the authentication request are evaluated to dynamically determine a plurality of authentication servers to invoke for the authentication request and an order for the invocation. A first authentication server is contacted to obtain a first authentication result for the user. In-flow rules and the first authentication result are evaluated to determine if additional authentication of the user should be performed. A second authentication server is contacted based on the determined invocation order and/or a result of the in-flow rules to obtain a second authentication result for the user. Decision rules and the first and second authentication results are evaluated to determine an authentication decision. The first authentication result and/or the second authentication result comprise a non-binary result.


