Extensible Authentication Framework for Multi-Provider Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-factor authentication (MFA) techniques are limited by being restricted to authentication methods native to a single server, preventing the use of external authentication procedures and restricting the number and variety of authentication techniques that can be employed.

Innovation Solution

An extensible MFA system that includes a claims facilitator, which directs users through a customizable authentication flow that can incorporate internal and external claims providers, enabling the use of various authentication methods such as biometrics and compliance procedures, by establishing trust relationships with external providers and managing authentication flows dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If authentication methods are restricted to server-native methods, then system simplicity is maintained, but adaptability and versatility of authentication techniques are limited

Engineering Contradiction:
Improveauthentication technique varietyVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication service that acts as a mediator between the server and external authentication providers. This service receives authentication requests, coordinates with external providers, and manages the authentication flow, thereby enabling external authentication methods without increasing server complexity. The intermediary handles the complexity of integrating multiple authentication sources while maintaining server simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication service is designed with universal functionality to handle both internal and external authentication providers through a unified interface. It can coordinate with various authentication techniques (biometric, compliance procedures, etc.) from different sources, making the system adaptable and versatile while maintaining a consistent authentication architecture that does not require server-specific customization for each method.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple external authentication providers are integrated, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication provider flexibilityVSAvoidauthentication flow management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct components: an authentication service that manages the flow, external authentication providers that execute specific methods, and a coordination mechanism that integrates them. This segmentation allows the system to incorporate multiple external providers without overwhelming complexity, as each provider operates independently through standardized interfaces while the authentication service coordinates them.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication service implements feedback mechanisms to coordinate with external providers, receiving authentication results and adjusting the flow accordingly. This feedback loop simplifies management by automating the coordination process, allowing the system to handle multiple providers through a structured exchange of authentication information rather than manual complexity management.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If server-native authentication methods are used, then ease of operation is maintained, but adaptability to external authentication procedures is reduced

Engineering Contradiction:
Improveexternal authentication method supportVSAvoidauthentication process simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The authentication service serves as an intermediary layer that presents a simplified, consistent interface to users while handling the complexity of external authentication providers behind the scenes. Users interact with a unified authentication process that appears simple and straightforward, while the intermediary manages the complexity of coordinating with external providers, thus maintaining ease of operation while enabling external methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces direct server-based authentication mechanics with a service-mediated approach that substitutes the mechanical complexity of server-native methods with a coordinated service architecture. This substitution maintains operational simplicity by abstracting the complexity of external provider integration away from both the server and the user interface.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3685287B1Extensible framework for authentication
Publication Date: 2021.09.22 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3685287B1 patent drawingFigure 1
  • EP3685287B1 patent drawingFigure 2
  • EP3685287B1 patent drawingFigure 3

AI summary

Methods, systems, and apparatuses in a computing device enable user access to a resource. The method includes receiving, from a user, a request for access to a resource; accessing an authentication flow for granting access to the resource; obtaining first claims for a user from a first claims provider in the authentication flow; determining a second claims provider in the authentication flow, the second claims provider having a trust relationship with the claims facilitator; directing the user to the second claims provider; receiving second claims for the user from the second claims provider; and enabling the user to access the resource in response to at least the received first and second claims.