Dynamic Trust Federation for Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing systems lack a dynamic and flexible method for managing user authentication across multiple applications, leading to inconsistent and application-centric authentication processes that do not adapt to varying trust levels based on location and transaction variables.

Innovation Solution

A computer-implemented method and system for dynamic trust federation, where a security token is used to enable sign-on into groups of applications based on applicable trust criteria, allowing for elevation and modification of authentication levels based on user interactions, location, and other variables, enabling seamless authentication across multiple applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single authentication level is used for all applications, then the authentication process is simple to implement, but it lacks adaptability to varying trust levels based on location and transaction variables

Engineering Contradiction:
Improveadaptability to varying trust levelsVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication by allowing the authentication level to change based on runtime conditions such as user location, transaction type, and trust criteria. The system dynamically adjusts authentication requirements rather than using static authentication levels, enabling adaptability to varying trust levels while managing complexity through automated decision-making algorithms.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters dynamically based on multiple variables including user location, transaction variables, and trust criteria. By modifying authentication parameters (such as required verification steps, authentication strength) based on contextual factors, the system achieves adaptability without requiring complete system redesign for each scenario.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If application-centric authentication is used, then each application can maintain its own security standards, but it leads to inconsistent authentication processes across the cloud ecosystem

Engineering Contradiction:
Improveauthentication consistencyVSAvoidflexibility in authentication management
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal authentication framework that works across multiple applications and cloud services. The trust federation mechanism provides a common authentication approach that can be applied universally across different applications while still allowing each application to participate in the federated trust system, thereby achieving consistency without sacrificing flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces a trust federation intermediary that mediates between individual applications and users. This intermediary layer coordinates authentication requests across applications, ensuring consistent authentication processes while allowing individual applications to maintain their specific security requirements through the standardized federation interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If authentication levels are fixed, then the system is easier to manage, but it cannot adapt to different user interactions and location variables

Engineering Contradiction:
Improveease of authentication managementVSAvoidresponsiveness to user context
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system implements self-service authentication management where the authentication level is automatically adjusted based on user context, location, and transaction variables without requiring manual intervention. The trust federation system autonomously evaluates trust criteria and adjusts authentication requirements, making the system adaptable to different contexts while maintaining ease of operation through automated decision-making.

Inventive Principle:
Principle #25Self-service

4Reliability

If multiple authentication levels are implemented dynamically, then the system becomes more secure and flexible, but it increases the complexity of authentication management

Engineering Contradiction:
Improvesecurity levelVSAvoidauthentication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously monitors user behavior, location, and transaction variables to dynamically adjust authentication levels. The trust federation system uses feedback from multiple sources to make real-time authentication decisions, enhancing security while managing complexity through automated feedback loops that eliminate the need for manual authentication management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9094391B2Dynamic trust federation
Publication Date: 2015.07.28 BANK OF AMERICA CORP
  • US9094391B2 patent drawing
  • US9094391B2 patent drawing
  • US9094391B2 patent drawing

AI summary

Aspects of the present disclosure are directed to methods and systems dynamic trust federation. In one aspect, a computer implemented method may include a security token that enables sign-on into a group applications based on applicable trust criteria. In one aspect, when a user interacts with one application in the group, the trust is elevated through the application internal authentication application program interface (API). The trust may be included in the security token to make available to other applications in the group. Applications can be in multiple groups with variable level of authentication based on location and other transactions variables.