IdP Framework for Multi-Factor Authentication Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in managing authentication methods across multiple accounts and systems due to varying security requirements that change over time, making it difficult to tailor authentication to meet custom security needs while ensuring ease of use and security.

Innovation Solution

An identity provider (IdP) system that facilitates authentication across multiple accounts, models authentication methods and security targets, and generates customizable policies to ensure compliance with security requirements, allowing administrators to query relationships between methods and targets, and track policy usage for reporting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations implement multiple authentication methods to meet varying security requirements, then security compliance is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidauthentication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication policy management system that handles multiple authentication methods (biometric, knowledge-based, possession-based) through a single integrated framework. This system provides multi-functionality by supporting various authentication types while presenting a unified interface to administrators, thereby improving security compliance without proportionally increasing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The invention introduces an intermediary authentication policy management system that mediates between security requirements and authentication implementations. This mediator layer abstracts the complexity of multiple authentication methods, allowing administrators to manage diverse authentication approaches through standardized policies without directly dealing with the underlying complexity of each authentication type.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If authentication policies are customized for different security requirements, then adaptability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication policy adaptabilityVSAvoidpolicy management ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamic authentication policies that can be adjusted based on risk levels, user roles, and contextual factors. The system automatically adapts authentication requirements without requiring manual reconfiguration, maintaining high adaptability while reducing the operational burden on administrators through automated policy adjustment based on changing conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention employs pre-configured authentication policy templates that address common security scenarios. These templates provide adaptability for different security requirements while simplifying operations by eliminating the need to create custom policies from scratch. Administrators can select and modify pre-built templates rather than designing authentication frameworks anew for each scenario.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication methods are diversified to meet different security targets, then security coverage is improved, but difficulty of detecting and measuring increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy compliance measurement
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements automated feedback mechanisms that continuously monitor authentication events and generate compliance reports. The system detects and measures policy compliance by analyzing authentication logs against defined policies, providing real-time feedback on security target achievement. This automated detection and measurement capability handles diversified authentication methods without proportionally increasing administrative burden.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11477249B2Security guidance for creation of multi factor authentication policy
Publication Date: 2022.10.18 OKTA INC
  • US11477249B2 patent drawing
  • US11477249B2 patent drawing
  • US11477249B2 patent drawing

AI summary

An identity provider (“IdP”) system maintains a framework of authentication methods and security targets that enables flexible authentication policy authoring and analysis of authentication performed by users of an organization. The IdP system generates authentication method profiles that include authentication factors and attributes, which may be further classified as required or optional. The IdP system also generates security target profiles that indicate security requirements needed to satisfy the corresponding security targets. The IdP system uses the generated profiles to determine relationships between authentication methods and security targets (e.g., a list of authentication methods that satisfy a given security target). Using these relationships, the IdP system may enable users to author policies and analyze how users' authentication behaviors comply with security targets.