Dynamic Authentication Broker with Non-Binary Decision Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication techniques lack flexibility to adapt to changing environments and do not effectively accommodate non-binary authentication methods, limiting their ability to provide secure access to resources.

Innovation Solution

A method that dynamically determines multiple authentication servers and their invocation order for user authentication, incorporating both binary and non-binary authentication decisions through an authentication broker that employs pre-flow, in-flow, and decision rules, including machine learning for adaptive decision-making.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional sequential multi-factor authentication is used, then authentication security is maintained, but system flexibility and adaptability to changing environments deteriorate

Engineering Contradiction:
ImproveflexibilityVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The authentication system dynamically determines the invocation order of multiple authentication servers based on pre-flow rules evaluating authentication request characteristics. The system can adjust the authentication flow in real-time by evaluating in-flow rules during the process and applying decision rules to authentication results, transforming a static sequential authentication process into a dynamic adaptive system that maintains security while improving flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an authentication broker as an intermediary component that coordinates between the application server and multiple authentication servers. The broker evaluates rules, determines invocation orders, and processes authentication results, allowing the system to maintain security policies while adapting to different authentication scenarios and environments without requiring changes to the core authentication servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional binary authentication decisions are used, then authentication process simplicity is maintained, but ability to accommodate non-binary authentication methods deteriorates

Engineering Contradiction:
Improveauthentication method diversityVSAvoidauthentication process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system changes the parameter space of authentication decisions from binary (accept/reject) to multi-valued outcomes including accept, reject, proceed to additional authentication, and continue. The decision rules evaluate authentication results and determine next steps based on these expanded parameters, allowing the system to accommodate non-binary authentication methods like risk scoring and confidence levels while managing complexity through structured rule evaluation.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The authentication process is segmented into distinct phases: pre-flow rule evaluation to determine initial invocation order, in-flow rule evaluation during authentication to adjust the process dynamically, and decision rule evaluation to determine final outcomes. This segmentation allows the system to handle complex non-binary authentication methods by breaking down the decision-making process into manageable, rule-based stages.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If dynamic determination of authentication servers and invocation order is implemented, then authentication flexibility is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication process flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication broker serves as an intermediary that absorbs and manages the complexity of dynamic rule evaluation and server coordination. By centralizing the logic for evaluating pre-flow, in-flow, and decision rules in the broker rather than distributing complexity across multiple servers, the system achieves dynamic flexibility while containing system complexity in a single manageable component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where authentication results from one server influence the invocation order and selection of subsequent authentication servers through in-flow rule evaluation. This feedback loop allows the system to adapt dynamically based on actual authentication outcomes while maintaining manageable complexity through rule-based decision logic that processes feedback systematically.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10616196B1User authentication with multiple authentication sources and non-binary authentication decisions
Publication Date: 2020.04.07 EMC IP HLDG CO LLC
  • US10616196B1 patent drawing
  • US10616196B1 patent drawing
  • US10616196B1 patent drawing

AI summary

User authentication techniques are provided for multiple authentication sources and for non-binary authentication decisions. An authentication request is received from an application server to authenticate a user for access to a protected resource. Pre-flow rules and the authentication request are evaluated to dynamically determine a plurality of authentication servers to invoke for the authentication request and an order for the invocation. A first authentication server is contacted to obtain a first authentication result for the user. In-flow rules and the first authentication result are evaluated to determine if additional authentication of the user should be performed. A second authentication server is contacted based on the determined invocation order and/or a result of the in-flow rules to obtain a second authentication result for the user. Decision rules and the first and second authentication results are evaluated to determine an authentication decision. The first authentication result and/or the second authentication result comprise a non-binary result.