Multi-Device Authentication Enrollment via Server Policy Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems require clients to communicate exhaustive lists of authentication capabilities over networks, compromising privacy and efficiency, and fail to manage random challenges effectively, leading to user errors and denial of authentication requests.
Innovation Solution
Implementing a query policy where a secure transaction server transmits a server policy to the client, allowing the client to identify a subset of supported authentication capabilities, enabling multiple device provisioning and management, and automatically requesting new random challenges when previous ones expire, thereby enhancing privacy and user experience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If clients communicate exhaustive lists of authentication capabilities over networks, then authentication completeness is improved, but privacy is compromised and efficiency deteriorates
Solution Approach 1:
The patent extracts only the necessary authentication capabilities from the exhaustive list and transmits them to the server. Instead of sending all available authentication methods, the client selectively transmits only those capabilities that are required for the current authentication context, thereby maintaining privacy while ensuring authentication completeness.
Solution Approach 2:
The authentication capabilities are segmented into different categories or levels of detail. The client transmits segmented information based on what the server requires, rather than sending a complete exhaustive list. This segmentation allows the client to control information disclosure while still providing sufficient authentication data.
2Reliability
If clients communicate exhaustive lists of authentication capabilities, then authentication completeness is improved, but communication efficiency deteriorates
Solution Approach 1:
The client extracts and transmits only the essential authentication capabilities needed for the current transaction, removing unnecessary information from the communication stream. This extraction principle reduces message size and improves communication efficiency while maintaining authentication completeness.
Solution Approach 2:
Instead of transmitting the complete exhaustive list (excessive action), the client transmits a partial list containing only the necessary capabilities. This partial action approach optimizes communication efficiency by sending minimal required information while still achieving complete authentication verification.
3Reliability
If systems require manual handling of random challenges, then security control is improved, but user experience deteriorates due to errors and authentication denials
Solution Approach 1:
The system implements automatic monitoring and handling of random challenges without requiring manual user intervention. The authentication client automatically detects expired challenges, requests new ones from the server, and manages the challenge-response process, thereby maintaining security control while eliminating user errors and improving ease of operation.
Solution Approach 2:
The system implements continuous feedback monitoring of random challenge status. When a challenge expires or becomes invalid, the system automatically detects this through feedback mechanisms and initiates retrieval of a new challenge, ensuring continuous security validation without user involvement and preventing authentication denials due to expired challenges.
4Manufacturing precision
If systems process multiple authentication devices sequentially, then device management accuracy is improved, but authentication efficiency deteriorates
Solution Approach 1:
The patent merges the processing of multiple authentication devices into a single unified operation. Instead of sequentially processing each device one at a time, the system combines multiple device enrollments and registrations into parallel batch operations, thereby maintaining accurate device management while significantly improving authentication efficiency.
Solution Approach 2:
The system performs preliminary preparation for processing multiple devices by pre-configuring the authentication environment and pre-validating device capabilities before the actual enrollment process. This preliminary action allows subsequent batch processing to proceed efficiently without compromising device management accuracy, as all devices are pre-checked and ready for simultaneous processing.
Data Source
AI summary
A system, apparatus, method, and machine readable medium are described for multi-device operations within an authentication framework. For example, one embodiment of a method comprises: detecting N authentication devices on a client, wherein N>1; generating a N cryptographic entities, one for each of the N authentication devices; transmitting a command to the client to register each of the N cryptographic entities into each of the N authentication devices; executing the command on the client and responsively registering each of the N cryptographic entities into each of the respective N authentication devices; and subsequently using at least one of the authentication devices and its associated cryptographic entity for authenticating a user of the client over a network.


