Identity Registry Mediator for Scalable Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face difficulties in managing and authenticating access to privileged and confidential data across multiple systems, servers, and services, leading to challenges in inventory management and secure access control.

Innovation Solution

A system comprising processors that receive requests for confidential data, generate challenge tokens, and encrypt them, using a security backend to validate and provide access, while also generating secure enrollment profiles and cryptographic fingerprints for identity and access management, enabling secure and scalable access control across various platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple technologies and systems are used to provide authentication access, then access capability and versatility are improved, but device complexity and difficulty of management increase

Engineering Contradiction:
Improveaccess capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a registry as an intermediary component that centralizes the management of authentication information for multiple systems and services. The registry stores authentication credentials and manages the relationships between clients and target systems, eliminating the need for complex direct authentication configurations between each pair of systems. This mediator approach maintains high adaptability while reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication information is provided to enable access to multiple systems, then ease of operation is improved, but security risks and loss of information increase

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent extracts authentication information from the clients and stores it securely in a centralized registry. This separation allows clients to access multiple systems without directly handling sensitive authentication credentials. The registry holds the authentication information in a protected manner, reducing security risks while maintaining ease of operation for clients needing to access multiple systems.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If temporary and dynamic systems are implemented, then adaptability and productivity are improved, but reliability and measurement precision decrease

Engineering Contradiction:
Improvesystem deployment speedVSAvoidauthentication reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary registration and enrollment actions where temporary and dynamic systems are pre-registered with the registry before actual authentication is needed. During enrollment, authentication credentials are pre-configured and stored securely. This preliminary action enables rapid deployment of dynamic systems while maintaining authentication reliability, as the authentication framework is established in advance rather than created on-demand.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11411733B1Systems and methods for identity and access control
Publication Date: 2022.08.09 CITIBANK N A
  • US11411733B1 patent drawing
  • US11411733B1 patent drawing
  • US11411733B1 patent drawing

AI summary

Identity and access control systems and methods employ a registry that receives a request for confidential data from a client, together with a secure enrollment profile identifier for the client, and generates and sends a challenge token to the client, which encrypts and returns the encrypted challenge token to the registry. Thereafter, the registry confirms that the encrypted challenge token is validly encrypted and calls up a security backend with authorization to provide the requested confidential data to client, and the security backend sends the requested confidential data to the client.