Dynamic Authentication Levels for Single Sign-On Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing multiple applications with different authentication types and levels, requiring them to remember various credentials and undergo repetitive authentication processes, which can be burdensome and inconvenient.

Innovation Solution

A single sign-on (SSO) system that allows users to access multiple applications with dynamic authentication levels, enabling 'step-up' and 'step-down' authentication based on the application's requirements, and includes features for single log-off and dynamic session timeouts, allowing users to manage their authentication levels manually and automatically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users access multiple applications with different authentication requirements, then security requirements are met, but user convenience deteriorates due to repetitive authentication

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal authentication system where a single set of credentials can access multiple applications with different authentication requirements. The system dynamically adjusts the authentication level based on the specific application being accessed, allowing one authentication mechanism to serve multiple functions across different security contexts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system dynamically adapts its requirements based on the target application's security needs. When a user logs in, the system automatically determines the appropriate authentication level for each application, stepping up or down the authentication requirements as needed, rather than requiring fixed high-level authentication for all applications.

Inventive Principle:
Principle #15Dynamics

2Reliability

If applications require different authentication levels, then security requirements are satisfied, but system complexity increases for users

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication management system that sits between the user and multiple applications. This intermediary automatically handles the complexity of determining and enforcing appropriate authentication levels for different applications, shielding users from the underlying complexity while maintaining security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes authentication parameters based on the target application's requirements. Instead of presenting a complex static authentication system, the parameters such as authentication level, credential types, and verification methods are adjusted automatically according to the specific application being accessed.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If users remember multiple credentials for different applications, then access to all applications is enabled, but cognitive burden increases

Engineering Contradiction:
Improveapplication access capabilityVSAvoidcredential management burden
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent merges multiple credential management functions into a single unified authentication system. Instead of requiring separate credential sets for different applications, the system combines authentication management into one interface where a single credential set can access multiple applications, eliminating the need for users to remember and manage multiple separate credentials.

Inventive Principle:
Principle #5Merging (Combining)

4Ease of operation

If single sign-on is implemented, then user convenience is improved, but security control over authentication levels is reduced

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication level control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The single sign-on system maintains security control through dynamic authentication level adjustment. While providing simplified single sign-on access, the system automatically determines and enforces the appropriate authentication level for each application based on its security requirements, stepping up authentication when necessary and maintaining simplified access when appropriate.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2304616B1Method and system for single sign on with dynamic authentication levels
Publication Date: 2018.03.21 HSBC TECHNOLOGY & SERVICES USA INC
  • EP2304616B1 patent drawingFigure 1
  • EP2304616B1 patent drawingFigure 2
  • EP2304616B1 patent drawingFigure 3

AI summary

Method and systems for single sign on with dynamic authentication levels is described. The method include receiving a data request for access to a second application, where the user is already authenticated to the first application at a first authentication level. Application information about the authentication level necessary to access the second application is retrieved. In response to a request, the user provides the further authentication data for accessing the second application. The type of the further authentication data required is based on the first authentication level and the minimum authentication level necessary to access the second application. The user is then authenticated to the second application at the minimum authentication level necessary to access the second application.