Hardware Appliance Dispatching Identity Information via Variable Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network-centric security models are complex and opaque, leading to difficulties in understanding and managing security, with users often circumventing security measures due to complexity, and existing solutions are expensive to administer, making a complete redesign impractical.

Innovation Solution

A user-centric approach using a hardware appliance, referred to as a 'vault,' that serves as a local security hub for storing and dispatching user identity information, employing a variable verification procedure that tests multiple verification factors and selectively releases information based on a combined verification strength exceeding a threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network-centric security models with multiple point solutions are implemented, then security coverage is improved, but system complexity increases and becomes opaque to users

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent consolidates multiple disparate security point solutions into a single unified hardware appliance that provides comprehensive security functions. This appliance combines identity management, access control, and verification capabilities into one integrated device, reducing the number of separate security components while maintaining or improving security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The hardware appliance acts as an intermediary security hub between users and network resources. It mediates authentication and authorization requests by verifying user identities and managing access credentials centrally, simplifying the security architecture while providing robust security enforcement across multiple applications and services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex security verification procedures are implemented, then security strength is improved, but ease of operation deteriorates and users circumvent security

Engineering Contradiction:
Improvesecurity strengthVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The verification procedure dynamically adjusts the number and type of verification factors required based on the security sensitivity of the requested operation. For low-risk operations, fewer verification factors are required, while high-risk operations trigger more stringent multi-factor verification. This dynamic approach maintains strong security for critical functions while providing convenient access for routine operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes verification parameters such as the number of required factors, the types of verification methods (knowledge-based, possession-based, inherence-based), and the threshold for approval based on the context of the access request. This allows the security system to adapt its strength to match the risk level, improving user experience for low-risk operations while maintaining robust security for high-risk operations.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If comprehensive identity management systems are implemented, then access control capability is improved, but administrative cost increases

Engineering Contradiction:
Improveaccess control capabilityVSAvoidadministrative cost
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The hardware appliance provides universal security services that can be shared across multiple applications, services, and users. A single appliance manages identity verification and access control for diverse workloads, eliminating the need for separate security systems for each application. This multi-functional approach reduces administrative overhead and costs while providing comprehensive access control capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service capabilities where users can independently manage their own identity credentials, update their information, and request access without requiring manual administrative intervention for routine operations. This automation reduces the administrative burden and operational costs associated with comprehensive identity management while maintaining versatile access control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10789386B2Dispatching identity information from secure hardware appliance
Publication Date: 2020.09.29 REAVIRE INC
  • US10789386B2 patent drawing
  • US10789386B2 patent drawing
  • US10789386B2 patent drawing

AI summary

A technique for promoting network security employs a user-centric approach in which a hardware appliance serves as a local security hub for storing and dispatching user identity information (UII). The hardware appliance is configured to release UII in response to access requests by applying a variable verification procedure. The variable verification procedure tests multiple verification factors associated with an access request, assigns a verification strength to each factor, and selectively releases the requested UII in response to a combined verification strength exceeding a threshold.