Identity Agent Unified Authentication Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face friction and security risks due to the need for separate logins across different applications and browsers on the same device, which lack context and lead to frequent re-authentication and increased security vulnerabilities.

Innovation Solution

An identity agent is used to capture and store user credentials and device security posture information, allowing seamless authentication across applications by generating an association between the credential and security posture, which is then communicated to browsers for unified access and enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate logins are used for different applications and browsers, then each login can be independently configured, but user friction increases and security context is lost

Engineering Contradiction:
Improvelogin configuration flexibilityVSAvoiduser authentication friction
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent merges multiple separate login systems into a unified authentication framework. The identity agent consolidates credential management across different applications and browsers, allowing a single authentication event to grant access to multiple services without requiring separate login procedures for each application.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The identity agent serves multiple functions simultaneously: it manages credentials for different applications, captures security posture information, generates associations between credentials and security context, and communicates with various browsers. This multi-functional approach eliminates the need for separate dedicated login systems for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If separate logins are used for different applications, then each application can have its own authentication logic, but security risks increase due to lack of context

Engineering Contradiction:
Improveapplication-specific authenticationVSAvoidsecurity context continuity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The identity agent acts as an intermediary between applications and users. It captures security posture information from the device, associates it with user credentials, and communicates this contextual information to browsers and applications. This intermediary role ensures that security context is maintained and shared across different authentication events without requiring each application to independently manage security state.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If frequent re-authentication is required, then security can be maintained, but user experience deteriorates and time is lost

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The identity agent performs preliminary actions by capturing security posture information and establishing associations between credentials and security context before authentication events occur. By pre-configuring and pre-establishing these relationships, the system enables faster authentication processes while maintaining security, as the contextual information is already in place and does not need to be re-established during each authentication event.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If multiple separate credentials are managed, then access control can be精细化, but password management complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the credential management function from individual applications and consolidates it into a centralized identity agent. This extraction removes the complexity of managing multiple separate credentials from each application, as the identity agent handles credential storage, association with security posture, and communication with browsers in a unified manner, simplifying the overall system architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20230171238A1Systems and Methods for Using an Identity Agent to Authenticate a User
Publication Date: 2023.06.01 CISCO TECHNOLOGY INC
  • US20230171238A1 patent drawing
  • US20230171238A1 patent drawing
  • US20230171238A1 patent drawing

AI summary

In one embodiment, a method includes receiving, by an identity agent installed on a device, a credential associated with a user of the device and storing, by the identity agent, the credential on the device. The method also includes capturing, by the identity agent, information associated with a security posture of the device and generating, by the identity agent, an association of the security posture and the credential. The method further includes receiving, by the identity agent, a request for the association of the security posture and the credential from a browser and communicating, by the identity agent, the association of the security posture and the credential to the browser.