Identity-Verified Authenticator Registration for Enterprise Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication systems are vulnerable to malicious actors gaining access to secure enterprise applications by registering authenticators using stolen user credentials, allowing unauthorized access to sensitive information.

Innovation Solution

Implement identity verification during the registration of verified authenticators and enforce authentication policies based on assurance levels for enterprise applications, requiring users to authenticate with verified authenticators to access secure resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is implemented using registered authenticators, then access security to enterprise applications is improved, but the system becomes vulnerable to malicious actors who can register authenticators using stolen user credentials

Engineering Contradiction:
Improveaccess securityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an identity verification service as an intermediary between the authenticator registration process and the multi-factor authentication system. This service verifies the user's identity through alternative methods (biometrics, knowledge questions, etc.) before allowing authenticator registration, thereby blocking malicious actors who have only stolen credentials from registering fake authenticators

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs identity verification as a preliminary action before allowing authenticator registration. By verifying the user's identity through multiple methods before the authenticator is registered, the system prevents malicious actors from compromising the system later with stolen credentials

Inventive Principle:
Principle #10Preliminary action

2Reliability

If identity verification is required to register verified authenticators, then security against credential theft is improved, but the registration process complexity increases

Engineering Contradiction:
Improvesecurity against credential theftVSAvoidregistration process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically adjusts the identity verification requirements based on the assurance level of the application being accessed. Different applications can have different verification thresholds, allowing the system to be more stringent for high-security applications and more lenient for lower-security ones, thereby managing complexity through adaptability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces assurance levels as a parameter that can be changed to control the strictness of identity verification requirements. By modifying this parameter, the system can adjust the number and type of verification methods required, balancing security needs with user convenience

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If assurance levels are enforced for enterprise applications, then access control precision is improved, but the system complexity and implementation difficulty increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem implementation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the enterprise application ecosystem into different assurance levels (e.g., low, medium, high). Each application can be assigned to an appropriate assurance level based on its security requirements, allowing for precise access control without requiring a completely new system architecture. This segmentation makes implementation more manageable

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250254164A1Managing access to secure enterprise resources using identity verification services and verified authenticators
Publication Date: 2025.08.07 ENTRUST CORP
  • US20250254164A1 patent drawing
  • US20250254164A1 patent drawing
  • US20250254164A1 patent drawing

AI summary

Systems and methods for managing access to secure enterprise resources using identity verification services and verified authenticators are provided. In example aspects, users are required to perform identity verification before the user can register verified authenticators. In an example, an issued user card is used to verify the identity of the user. In further example aspects, enterprise resources may be associated with assurance levels defining the level of authentication required to access the enterprise resources. In an example, an enterprise resource may have an assurance level that requires multi-factor authentication with a verified authenticator to access the enterprise resource.