Remote Authentication Server for Dynamic Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for user devices are inflexible and insecure, particularly when accessed outside a private network, as they rely on local management and do not allow dynamic access control or secure authentication regardless of location.
Innovation Solution
A method that authenticates users through a remote server connected via the internet, using a proof of authentication to grant access to user devices, allowing for flexible and secure access management, including multi-factor authentication and contextual data verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If local authentication management is used on the user device, then authentication can be performed independently of network location, but access control becomes static and insecure
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the user device and the network resources. The server receives authentication requests from the device, verifies credentials, and returns authentication tokens. This mediator enables dynamic access control policies to be enforced remotely while maintaining authentication availability offline through cached credentials.
Solution Approach 2:
The system performs preliminary authentication actions by caching authentication credentials and tokens on the user device before network disconnection occurs. This preliminary action allows the device to maintain authentication state and access control flexibility even when offline, resolving the contradiction between availability and adaptability.
2Productivity
If local authentication cache is used when outside the network, then authentication can proceed without network connection, but security is compromised and access management is rigid
Solution Approach 1:
The authentication system implements feedback mechanisms where the authentication server continuously updates access control policies and reissues authentication tokens based on current security conditions. The user device receives these feedback signals and adjusts its authentication state accordingly, maintaining both fast authentication and high security even when offline.
Solution Approach 2:
The patent transforms static local authentication caches into dynamic authentication states that can be remotely updated. The authentication token includes time-limited validity and can be revoked or modified by the authentication server, making the cached credentials dynamic rather than static, thus improving security without sacrificing authentication speed.
3Adaptability or versatility
If remote server authentication is implemented, then dynamic and flexible access control is achieved, but additional network infrastructure and complexity are required
Solution Approach 1:
The authentication server is designed as a universal platform that can serve multiple user devices, applications, and network resources simultaneously. By consolidating authentication functionality into a single multi-functional server, the system achieves dynamic access control without proportionally increasing overall system complexity.
Solution Approach 2:
The system uses authentication tokens as digital copies of user credentials that can be distributed to multiple devices and applications. Instead of replicating complex authentication logic across multiple systems, a single authentication decision is copied into portable tokens that enable flexible access control throughout the network.
Data Source
AI summary
A method for authenticating a user on a user device with an authentication phase that includes: displaying a page of an authentication server in an internet browser, initiating an authentication process via this page to authenticate the user to a server remote from the user device, supplying to the user device a proof of authentication from the remote server, and opening an access session to the user device using this proof of authentication. Embodiments of the invention may include a computer program and an authentication system implementing such a method.


