Policy-Based Authentication Enabler for Third-Party Apps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing service provider networks face difficulties in authenticating end users due to the lack of an identifier in authentication requests, which complicates trust relationships between third-party applications, end users, and service providers, as current APIs do not provide sufficient mechanisms for user identification.

Innovation Solution

Implementing an authentication enabler and gateway within the service provider network, along with an authentication client on user devices, to perform authentication processes. This system evaluates authentication policies, requests identity information when needed, and returns authentication results, ensuring secure and policy-compliant user authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third party applications use existing APIs to access service provider network capabilities, then application development is enabled, but authentication of end users becomes difficult due to lack of user identifier

Engineering Contradiction:
Improveapplication development capabilityVSAvoiduser authentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an authentication enabler as an intermediary component between third party applications and the service provider network. This authentication enabler receives authentication requests from applications, obtains user identifiers through policy evaluation, and coordinates with the network to perform actual authentication. This mediator resolves the contradiction by enabling applications to access network capabilities while ensuring reliable user authentication through a dedicated authentication layer that handles identifier acquisition and verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If service provider network performs authentication on behalf of third party applications, then user identification accuracy improves, but system complexity increases due to additional authentication components

Engineering Contradiction:
Improveuser identification accuracyVSAvoidauthentication system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The authentication enabler is designed as a multi-functional component that handles multiple tasks: receiving authentication requests from various applications, evaluating authentication policies, obtaining user identifiers, coordinating with the service provider network, and returning authentication results. By consolidating these multiple functions into a single universal authentication enabler, the system achieves accurate user identification without proportionally increasing overall system complexity, as the enabler serves all third party applications through a unified interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If authentication policies are evaluated and enforced, then security and compliance improve, but processing time increases due to additional policy evaluation steps

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by evaluating and storing authentication policies in advance before actual authentication occurs. The authentication enabler maintains a repository of authentication policies that define security requirements, and when an authentication request arrives, the enabler quickly retrieves and applies the relevant pre-established policies rather than evaluating complex security rules in real-time. This preliminary preparation of authentication frameworks allows rapid policy-based authentication while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8978100B2Policy-based authentication
Publication Date: 2015.03.10 WORKDAY INC
  • US8978100B2 patent drawing
  • US8978100B2 patent drawing
  • US8978100B2 patent drawing

AI summary

A device receives a request to authenticate an end user of a user device based on a requested use of an application by the user device, and communicates with an authentication client, provided in the user device, to perform an authentication requested by the request. The device also generates a response to the request based on the communication with the authentication client, where the response indicates that the end user is or is not authenticated to use the application. The device further provides the response to an application server device hosting the application.