Mainframe Authentication System Using Unique User IDs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mainframe authentication systems lack effective security mechanisms, leading to inefficiencies, data misuse, and sub-optimal performance. They fail to provide granular and individual access privileges, making it difficult to track user activities and respond to security risks effectively.

Innovation Solution

An enhanced authentication system that implements a single sign-on process using unique mainframe IDs to track and monitor user activities. This system generates individual sessions based on mainframe IDs, allowing for granular access privilege enforcement and secure access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a single service ID is used for multiple users to access the mainframe, then access efficiency is improved, but security and user activity tracking deteriorate

Engineering Contradiction:
Improveaccess efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the authentication mechanism by introducing unique mainframe IDs for each user while maintaining a single service ID for system access. This segmentation allows the system to distinguish between individual users (via mainframe IDs) while preserving the efficiency of single-service authentication (via service ID), thereby resolving the contradiction between access efficiency and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces mainframe IDs as intermediary identifiers that bridge the gap between service-level access and user-level security. These mainframe IDs act as mediators that enable the system to track individual user activities while allowing efficient service-level authentication, thus resolving the security-efficiency contradiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If screen scraping is used for authentication, then implementation simplicity is improved, but stability and security deteriorate

Engineering Contradiction:
Improveimplementation simplicityVSAvoidauthentication stability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces the mechanical/screen-based scraping approach with a more robust identifier-based system using mainframe IDs. This substitution eliminates the instability of screen scraping while maintaining implementation simplicity, as the new system relies on straightforward identifier generation and association rather than complex screen parsing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If individual user sessions are created for each user, then security and activity tracking are improved, but system complexity increases

Engineering Contradiction:
Improveaccess privilege enforcementVSAvoidsession management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the mainframe ID serve multiple functions: it identifies the user, manages the session, enforces access privileges, and enables activity tracking. By giving the mainframe ID this universal role, the system achieves granular security control without proportionally increasing complexity, as a single identifier handles multiple security-related tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250106215A1Mainframe authentication and monitoring system with enhanced security
Publication Date: 2025.03.27 CIGNA INTPROP
  • US20250106215A1 patent drawing
  • US20250106215A1 patent drawing
  • US20250106215A1 patent drawing

AI summary

Apparatuses, systems, and methods relate to technology to identify a first user identification, where the first user identification is associated with an application. The technology determines that the first user identification is associated with a second user identification, where the second user identification is associated with a mainframe. The technology stores the first user identification in association with the second user identification into a storage, identifies a request to access the mainframe, wherein the request is associated with the first user identification, accesses the storage to identify the second user identification based on the first user identification, and generates a first session to access the mainframe based on the second user identification, where the first session is dedicated to tasks associated with the second user identification.