Centralized Network Authentication Using MFA Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing centralized authentication and authorization protocols like TACACS+ and RADIUS rely on usernames and passwords, which are vulnerable to security threats and expose sensitive information to attacks, such as network eavesdropping and snooping.

Innovation Solution

Implement a custom authentication and authorization apparatus that uses multi-factor authentication (MFA) and generates tokens valid for a predetermined time, replacing the need for transmitting real credentials, ensuring secure access without exposing sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional authentication protocols (RADIUS/TACACS+) are used to enable centralized authentication and authorization, then device connectivity and management capability are improved, but security is worsened due to transmission of sensitive credentials over the network

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a copy of the authentication mechanism where instead of transmitting actual credentials (usernames/passwords), the system transmits a copy or representation of authentication state through digital certificates and cryptographic proofs. The requester apparatus presents a certificate that proves authentication without exposing the actual credential, thus maintaining connectivity while eliminating credential exposure risks

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces cryptographic intermediaries (digital certificates, cryptographic protocols) that mediate between the requester apparatus and the authenticated resource. Instead of direct credential transmission, an intermediary cryptographic proof system is used to verify authentication status, preventing direct exposure of sensitive credentials while maintaining the authentication function

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If credentials are transmitted over the network for authentication, then authentication functionality is achieved, but security is compromised due to eavesdropping and snooping attacks

Engineering Contradiction:
Improveauthentication functionalityVSAvoidcredential exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system transmits a cryptographic copy or proof of authentication rather than the actual credential. The digital certificate and cryptographic signatures serve as copies that verify authentication status without being the original credential itself, thus maintaining authentication reliability while preventing credential exposure to eavesdroppers

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent employs short-lived cryptographic tokens and time-limited certificates that are disposable after use. Instead of transmitting permanent credentials, the system uses ephemeral authentication proofs that become invalid after verification or expiration, reducing the window of opportunity for attacks while maintaining authentication functionality

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12476962B2Authentication and authorization of requester apparatuses in network systems
Publication Date: 2025.11.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12476962B2 patent drawing
  • US12476962B2 patent drawing
  • US12476962B2 patent drawing

AI summary

According to examples, an apparatus includes a processor that receives a request from a requester apparatus to access a target apparatus. The processor may provide a token valid to the requester apparatus upon determining that the requester apparatus is authenticated to access the target apparatus, in which the token complies with and is sent via a centralized authentication and authorization protocol. The processor may also receive an access check message from the target apparatus, in which the access check message includes the token and the identity of the requester apparatus. In addition, the processor may enable the target apparatus to control access to the requester apparatus. The apparatus disclosed herein enable for the retrofitting of secure multi-factor or one-time password authentication into systems that rely on a centralized authentication and authorization protocol, such as the TACACS+ or the RADIUS protocol.