Identity Infrastructure Service Centralizing Authentication Across Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of security contexts and authentication credentials across various software services and hardware platforms complicates user experience and security management, leading to increased developer time spent on security rather than feature development, and users face challenges with managing multiple credentials for different contexts.

Innovation Solution

Identity infrastructure services provide a centralized platform for creating arbitrary security contexts across multiple hardware and software platforms, using arbitrary identity providers, with programmatically controlled security contexts and unified APIs for authentication, authorization, and auditing, enabling single sign-on and multifactor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security contexts and authentication credentials are added to protect sensitive data across different software services and hardware platforms, then security coverage and protection capability are improved, but system complexity and user management burden increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security contexts and authentication credentials into a unified identity management system. The identity service aggregates authentication from multiple identity providers and consolidates security contexts into a single manageable framework, allowing users to access multiple services through unified authentication while maintaining comprehensive security coverage across different platforms and applications.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The identity service provides universal authentication capabilities that work across diverse software services and hardware platforms. It supports multiple identity providers (social networks, corporate directories, mobile device lock screens) and can authenticate users to various types of resources (applications, devices, data) through a single unified system, eliminating the need for separate authentication mechanisms for each context.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple security contexts and authentication credentials are added to protect sensitive data across different software services and hardware platforms, then security coverage and protection capability are improved, but user experience and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity coverageVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The identity service acts as an intermediary between users and multiple identity providers/services. It handles the complexity of authentication across different platforms by mediating between the user's single set of credentials and the multiple services that require authentication, transparently managing credential verification and token issuance without requiring users to directly interact with each service's authentication mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The unified identity management system provides universal access to multiple services through a single authentication interface. Users can authenticate to various software services and hardware platforms using one consistent method, while the system handles the diversity of authentication requirements across different identity providers and resource types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If application developers spend increasing amounts of time on computer security implementation, then security implementation quality is improved, but productivity and feature development speed decrease

Engineering Contradiction:
Improvesecurity implementation qualityVSAvoidfeature development speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts security implementation complexity from application developers by providing a separate, dedicated identity service. Developers no longer need to implement authentication and authorization logic within their applications; instead, they can integrate with the external identity service through standardized APIs, allowing them to focus on feature development while security expertise is concentrated in the specialized identity management system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The identity service serves as an intermediary that handles all security implementation details between applications and identity providers. Developers interact with the identity service through simplified APIs rather than directly implementing complex authentication mechanisms, allowing high-quality security implementation to be maintained while significantly reducing the time developers spend on security tasks.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If traditional token-based authentication is used across multiple contexts, then authentication capability is provided, but credential management complexity and security context proliferation increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The identity service provides a universal authentication framework that works across multiple security contexts and identity providers. Instead of requiring separate token-based authentication systems for each context, the identity service implements a unified approach that can issue and manage tokens across diverse services and platforms, maintaining authentication capability while reducing credential management complexity through centralized control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3207661B1Identity infrastructure as a service
Publication Date: 2021.12.29 AUTH0 INC
  • EP3207661B1 patent drawingFigure 1
  • EP3207661B1 patent drawingFigure 2
  • EP3207661B1 patent drawingFigure 3

AI summary

A method and system of an identity service to provide a single point of access for a plurality of applications for an authentication of a user identity. An authentication request is received from an application via an application program interface (API), wherein the authentication request includes logon information. The authentication request is translated to one or more identity providers. Upon authentication, serially executing one or more programmatic extension scripts associated with the user. Privileges are granted to the user based on at least one of the programmatic extension scripts associated with the user.