Identity-Verified Authenticator Registration for Enterprise Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication systems are vulnerable to malicious actors gaining access to secure enterprise applications by registering authenticators using stolen user credentials, allowing unauthorized access to sensitive information.
Innovation Solution
Implement identity verification during the registration of verified authenticators and enforce authentication policies based on assurance levels for enterprise applications, requiring users to authenticate with verified authenticators to access secure resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-factor authentication is implemented using registered authenticators, then access security to enterprise applications is improved, but the system becomes vulnerable to malicious actors who can register authenticators using stolen user credentials
Solution Approach 1:
The patent introduces an identity verification service as an intermediary between the authenticator registration process and the multi-factor authentication system. This service verifies the user's identity through alternative methods (biometrics, knowledge questions, etc.) before allowing authenticator registration, thereby blocking malicious actors who have only stolen credentials from registering fake authenticators
Solution Approach 2:
The system performs identity verification as a preliminary action before allowing authenticator registration. By verifying the user's identity through multiple methods before the authenticator is registered, the system prevents malicious actors from compromising the system later with stolen credentials
2Reliability
If identity verification is required to register verified authenticators, then security against credential theft is improved, but the registration process complexity increases
Solution Approach 1:
The system dynamically adjusts the identity verification requirements based on the assurance level of the application being accessed. Different applications can have different verification thresholds, allowing the system to be more stringent for high-security applications and more lenient for lower-security ones, thereby managing complexity through adaptability
Solution Approach 2:
The patent introduces assurance levels as a parameter that can be changed to control the strictness of identity verification requirements. By modifying this parameter, the system can adjust the number and type of verification methods required, balancing security needs with user convenience
3Measurement precision
If assurance levels are enforced for enterprise applications, then access control precision is improved, but the system complexity and implementation difficulty increase
Solution Approach 1:
The patent segments the enterprise application ecosystem into different assurance levels (e.g., low, medium, high). Each application can be assigned to an appropriate assurance level based on its security requirements, allowing for precise access control without requiring a completely new system architecture. This segmentation makes implementation more manageable
Data Source
AI summary
Systems and methods for managing access to secure enterprise resources using identity verification services and verified authenticators are provided. In example aspects, users are required to perform identity verification before the user can register verified authenticators. In an example, an issued user card is used to verify the identity of the user. In further example aspects, enterprise resources may be associated with assurance levels defining the level of authentication required to access the enterprise resources. In an example, an enterprise resource may have an assurance level that requires multi-factor authentication with a verified authenticator to access the enterprise resource.


