Dynamic Credential Bypass for Authentication Efficiency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems in data processing environments require multiple authentication steps, creating friction and inefficiencies, particularly for developers and administrators who need to propagate changes across networks, while automating authentication without compromising security remains challenging.

Innovation Solution

Implementing a system that uses dynamic credentials and multiple authentication standards to automate repeat authentications by storing credentials and utilizing a table of excepted devices based on network identifiers, allowing for 'touchless' access to remote resources without repeated logins.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication steps are implemented to ensure security, then security is improved, but operational efficiency deteriorates due to repeated authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication by storing credentials and creating bypass table entries before the actual resource access is needed. When a device reconnects or changes state, the pre-stored credentials and bypass entries enable immediate access without requiring full re-authentication, thus maintaining security while improving operational efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces bypass tables and credential storage mechanisms as intermediary components between the authentication challenge and the resource access. These intermediaries hold pre-validated authentication information, allowing devices to bypass repeated authentication challenges while maintaining the security framework, thus resolving the contradiction between security and efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automation of authentication tasks is implemented to improve efficiency, then productivity is improved, but security deteriorates due to potential credential compromise

Engineering Contradiction:
Improveautomation efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The authentication system is segmented into multiple components: credential storage, bypass table management, and authentication challenge handling. Credentials are stored dynamically and segmented from the actual authentication process, allowing automated access while maintaining security through distributed credential management and conditional access control

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses dynamic credential storage and time-limited bypass entries rather than static authentication mechanisms. Credentials are stored temporarily and bypass entries expire after certain conditions are met, making the automation dynamic and adaptable to security requirements, thus enabling productivity improvement without permanent security compromise

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10193888B1Dynamic authentication in alternate operating environment
Publication Date: 2019.01.29 WELLS FARGO BANK NA
  • US10193888B1 patent drawing
  • US10193888B1 patent drawing
  • US10193888B1 patent drawing

AI summary

Systems and methods that employ dynamic credentials across distinct authentication standards can be used to reduce the burden associated with repeated re-authentication. A utility can be employed during logon in an alternate operating environment that stores information from the logon dynamically and generates a credential file that is employed to grant access to a resource without repeating the earlier logon procedure, even if the device changes its user state. After processes requiring resource access are complete, or when an allowed time expires, the granted access is revoked and the device returns to a default or standard authentication technique.