Radius Server Authentication System for Dynamic Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods, including two-factor authentication using security tokens, are not completely secure and lack flexibility in granting access levels, posing challenges in transitioning away from compromised systems and providing appropriate permissions based on user location and device location.

Innovation Solution

A system and method for role-based authentication using a security token that determines the type of authentication request, converts between different authentication types, and dynamically assigns permission levels based on user and device location, utilizing a Radius server to authenticate users and attach appropriate permissions to authentication responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-factor authentication using security tokens is implemented, then security is improved, but the system becomes vulnerable to seed compromise and requires expensive replacement of millions of tokens

Engineering Contradiction:
Improveauthentication securityVSAvoidseed compromise vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the authentication parameter from seed-based one-time passwords to certificate-based cryptographic authentication. This fundamental parameter change eliminates the seed compromise vulnerability while maintaining strong security, allowing transition from vulnerable SecurID tokens to secure certificate-based authentication without hardware replacement.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical/hardware security token system with a software-based certificate authentication system. This substitution eliminates the physical token infrastructure that is vulnerable to seed extraction, moving to a cryptographic model where security relies on private key protection rather than hardware seed storage.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If traditional authentication systems are used, then implementation is simple, but flexibility in granting access levels based on location and device is lacking

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control where permission levels are not fixed but change based on real-time conditions such as user location, device location, and device characteristics. The Radius server dynamically evaluates these parameters and assigns appropriate permission levels, transforming static authentication into adaptive, context-aware access control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the authentication system into distinct functional components: certificate validation, location determination, device characterization, and permission level assignment. This segmentation allows each component to be independently configured and managed, providing flexibility without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If automatic conversion between authentication types is implemented, then transitioning from compromised systems is facilitated, but system complexity increases

Engineering Contradiction:
Improveauthentication transition easeVSAvoidauthentication server complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces the Radius server as an intermediary that mediates between legacy authentication systems and modern certificate-based authentication. The Radius server handles the complexity of automatic conversion, type determination, and protocol translation, shielding users from complexity while enabling seamless transition between authentication types.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements self-service automatic conversion where the authentication system automatically detects the user's current authentication type and converts them to the appropriate certificate-based authentication without manual intervention. The system self-manages the transition process, including generating new certificates and updating authentication credentials.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10708276B2Authentication system and method
Publication Date: 2020.07.07 LEVEL 3 COMMUNICATIONS LLC
  • US10708276B2 patent drawing
  • US10708276B2 patent drawing
  • US10708276B2 patent drawing

AI summary

A system includes least one processor in communication with a memory storing instructions, the at least one processor to receive an authentication request comprising authentication information from a user requesting access to a computing device connected to a communications network, determine a type of authentication request sent by the user, transmit the authentication request to an appropriate authentication server responsive to the type of authentication request, receive an authentication response from the appropriate authentication server, determine a permission level for the user requesting access to the computing device and attach the permission level to the authentication response, and transmit the authentication response to the user requesting access to the computing device.