Centralized Identifier Management for Multi-Server Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing multiple user identifiers across different network servers face operational constraints and lack harmonization of authentication processes, requiring different levels of trust and confidentiality, leading to incompatibilities and restrictive solutions.

Innovation Solution

A centralized management system with a management center that acts as an intermediary between users and servers, utilizing a database with root identifiers and higher-level server identifiers to facilitate authentication and data access, while ensuring security and trust through contextual analysis and confidence index verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple different identifiers are used for different servers and services, then user authentication can be performed across various networks, but operational incompatibilities arise and system complexity increases

Engineering Contradiction:
Improveauthentication compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a management center as an intermediary between users and multiple servers. This management center maintains a database that maps different user identifiers (login names, email addresses, phone numbers) to a single internal user identifier. When a user attempts to access any server, the management center intercepts the authentication request, resolves the identifier mapping, and facilitates the connection, thereby unifying access across diverse systems without requiring users to manage multiple identifiers manually.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The management center serves multiple functions: it acts as an identifier resolution service, an authentication gateway, a trust relationship manager, and a communication broker between users and servers. By consolidating these functions into a single universal system, the patent eliminates the need for separate authentication mechanisms for each server, reducing overall system complexity while maintaining broad compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If different identification mechanisms are implemented for various servers, then specific security requirements can be met, but operational incompatibilities and trust management difficulties increase

Engineering Contradiction:
Improvesecurity levelVSAvoidtrust management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The management center acts as a trusted intermediary that establishes and manages confidence relationships between users and servers. It maintains confidence levels in its database that indicate the degree of trust between authentication entities. When a user authenticates through the management center, the system automatically manages the trust relationships, eliminating the need for users to manually configure or understand complex trust settings across different servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the management center continuously monitors and updates confidence levels based on authentication outcomes and server responses. This feedback loop allows the system to dynamically adjust trust relationships, ensuring that security requirements are met while automatically managing the complexity of trust configurations for users.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If a centralized management system is implemented to unify identifiers, then operational compatibility improves, but system complexity and trust verification requirements increase

Engineering Contradiction:
Improveoperational compatibilityVSAvoidmanagement system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct functional components: user terminals, a centralized management center, and multiple servers. The management center itself is segmented into modular functions including identifier resolution, authentication handling, confidence management, and communication protocols. This segmentation allows each component to be developed and maintained independently, reducing the overall complexity burden despite the centralized architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The management center implements self-service mechanisms for trust verification and identifier resolution. It automatically maintains its own database of identifier mappings and confidence levels, and autonomously handles the complex tasks of resolving identifiers and managing trust relationships without requiring external intervention or complex configuration, thereby reducing the operational complexity burden.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2271053B1Evolving system and method for managing and aggregating several identifiers around a polymorphous authenticator
Publication Date: 2019.07.31 SOC FR DU RADIOTELEPHONE SFR
  • EP2271053B1 patent drawingFigure 1
  • EP2271053B1 patent drawingFigure 2
  • EP2271053B1 patent drawingFigure 3

AI summary

The system has a managing center (1) comprising communication interfaces (2, 3) for communicating with a server and/or a network, of a server and a user, respectively. A data base is associated to the managing center. The managing center has an analysis and verification unit for analyzing and verifying a confidence index of the server for considering the confidence index from which the managing center carries out an authentification. A correlation unit correlates two common identifiers from identical contextual information. An independent claim is also included for a method for managing and aggregating identifiers.