Network Access Certificate Issuance via Attribute Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for user authentication in computer networks lack a precise method to verify identity, leading to issues such as redundant account creation, password management problems, and increased costs due to inefficient single sign-on solutions that often require middle tiers or proxy systems, which are impractical in certain scenarios.
Innovation Solution
A method and system that provide digital certificates for network access by querying a first system for user attributes matching predefined criteria, allowing direct interaction without a middle tier, and issuing certificates with specific characteristics tailored to each network or application, enabling granular control over access levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional single sign-on systems are used, then user authentication is simplified, but middle tiers or proxy systems are required which increase system complexity and are impractical in certain scenarios
Solution Approach 1:
The patent extracts the authentication function from the traditional middle-tier architecture by implementing direct certificate-based authentication between the user's device and the network. Digital certificates containing user attributes are validated directly by the network access point, eliminating the need for complex proxy systems while maintaining simplified user authentication.
2Reliability
If user accounts are created for each network access, then access control is precise, but account redundancy increases leading to increased storage requirements and costs
Solution Approach 1:
The patent implements universal digital certificates that can be used across multiple networks and applications. A single certificate containing user attributes can be presented to multiple networks, eliminating the need to create separate accounts for each network. This maintains precise access control through attribute validation while reducing account redundancy and storage requirements.
3Reliability
If digital certificates with granular access control are implemented, then security is enhanced, but certificate management and attribute validation become more complex
Solution Approach 1:
The patent performs preliminary actions by pre-defining user attributes and access criteria in the digital certificate before network access is required. User attributes such as authorization levels, permitted networks, and time restrictions are embedded in the certificate during issuance. This eliminates the need for complex real-time attribute validation and certificate management during network access, simplifying the overall system while maintaining enhanced security.
Data Source
AI summary
Provided is a system and method for providing a certificate, and more specifically a certificate for network access upon a second system. The method includes, identifying a first system having at least one processor and a plurality of users, each user having at least one attribute; receiving from a third party at least one required attribute for certificate based network access; receiving from a user known to the first system a request for certificate based network layer network access to a second system having at least one processor, the request having at least one identifier; querying the first system with the at least one identifier for attributes associated with the user requesting the certificate based network layer network access to a second system; evaluating the attributes associated with the user requesting the certificate to the at least one predefined attribute; and in response to at least one attribute associated with the user requesting the certificate correlating to the at least one predefined attribute, providing from a system other than the first system, as requested by the user a certificate with at least one characteristic for certificate based network layer network access on the second system, the second system distinct from the first system. An associated system for providing a Certificate is also provided.


