Dynamic Authentication Levels for Single Sign-On Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in managing multiple applications with different authentication types and levels, requiring them to remember various credentials and undergo repetitive authentication processes, which can be burdensome and inconvenient.
Innovation Solution
A single sign-on (SSO) system that allows users to access multiple applications with dynamic authentication levels, enabling 'step-up' and 'step-down' authentication based on the application's requirements, and includes features for single log-off and dynamic session timeouts, allowing users to manage their authentication levels manually and automatically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users access multiple applications with different authentication requirements, then security requirements are met, but user convenience deteriorates due to repetitive authentication
Solution Approach 1:
The patent implements a universal authentication system where a single set of credentials can access multiple applications with different authentication requirements. The system dynamically adjusts the authentication level based on the specific application being accessed, allowing one authentication mechanism to serve multiple functions across different security contexts.
Solution Approach 2:
The authentication system dynamically adapts its requirements based on the target application's security needs. When a user logs in, the system automatically determines the appropriate authentication level for each application, stepping up or down the authentication requirements as needed, rather than requiring fixed high-level authentication for all applications.
2Reliability
If applications require different authentication levels, then security requirements are satisfied, but system complexity increases for users
Solution Approach 1:
The patent introduces an intermediary authentication management system that sits between the user and multiple applications. This intermediary automatically handles the complexity of determining and enforcing appropriate authentication levels for different applications, shielding users from the underlying complexity while maintaining security requirements.
Solution Approach 2:
The system dynamically changes authentication parameters based on the target application's requirements. Instead of presenting a complex static authentication system, the parameters such as authentication level, credential types, and verification methods are adjusted automatically according to the specific application being accessed.
3Adaptability or versatility
If users remember multiple credentials for different applications, then access to all applications is enabled, but cognitive burden increases
Solution Approach 1:
The patent merges multiple credential management functions into a single unified authentication system. Instead of requiring separate credential sets for different applications, the system combines authentication management into one interface where a single credential set can access multiple applications, eliminating the need for users to remember and manage multiple separate credentials.
4Ease of operation
If single sign-on is implemented, then user convenience is improved, but security control over authentication levels is reduced
Solution Approach 1:
The single sign-on system maintains security control through dynamic authentication level adjustment. While providing simplified single sign-on access, the system automatically determines and enforces the appropriate authentication level for each application based on its security requirements, stepping up authentication when necessary and maintaining simplified access when appropriate.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Method and systems for single sign on with dynamic authentication levels is described. The method include receiving a data request for access to a second application, where the user is already authenticated to the first application at a first authentication level. Application information about the authentication level necessary to access the second application is retrieved. In response to a request, the user provides the further authentication data for accessing the second application. The type of the further authentication data required is based on the first authentication level and the minimum authentication level necessary to access the second application. The user is then authenticated to the second application at the minimum authentication level necessary to access the second application.