Service User Identifier for Authentication Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication services require users to manage multiple devices, suffer from direct links to personal data, and have limitations in device distribution and management, leading to security risks and user inconvenience.
Innovation Solution
The proposed authentication service uses a 'Service User Identifier' (SUID) to abstract user identity from the authentication service, allowing a single authenticator to be associated with multiple sites, enabling on-demand device distribution and replacement, and temporary access codes without pre-assigning devices to users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a direct link between personal data and subscribing site is established, then authentication verification is simplified, but user identity security is weakened
Solution Approach 1:
The patent introduces an authentication service as an intermediary between users and subscribing sites. The service holds personal data and verifies authentication credentials without exposing direct links between users and sites. The service acts as a mediator that validates credentials and returns verification results, thereby simplifying authentication while maintaining security through the intermediary layer.
2Adaptability or versatility
If multiple authentication devices are provided for different organizations, then authentication coverage is improved, but user burden increases
Solution Approach 1:
The patent creates a universal authentication service that can be used across multiple subscribing organizations. Instead of requiring separate authentication devices for each organization, the service provides a single credential verification mechanism that works with all participating sites. Users authenticate through the service once, and the verification is accepted by multiple organizations, thereby providing broad authentication coverage while reducing the number of devices users must manage.
3Reliability
If authentication devices are pre-assigned to users, then device-user relationship is established, but distribution delays and security risks increase
Solution Approach 1:
The patent inverts the conventional distribution model by not pre-assigning devices to users before distribution. Instead, devices are distributed first without binding them to specific users, and the authentication service establishes the device-user relationship dynamically during the authentication process. This reversal eliminates distribution delays and security risks associated with pre-assignment, while still ensuring reliable device-user relationships are established when needed.
4Productivity
If authentication devices are bulk-shipped to organizations, then distribution efficiency is improved, but administrative burden increases
Solution Approach 1:
The patent implements a self-service distribution model where authentication devices are bulk-shipped to organizations but are not pre-configured or pre-assigned. The authentication service automatically handles device registration, user association, and credential management without requiring administrative intervention. Organizations simply distribute the devices to users, and the service manages the rest, thereby maintaining high distribution efficiency while eliminating administrative burdens.
Data Source
AI summary
A method of allowing a user to authenticate to an authentication service while isolating information associated with the user from the authentication service includes generating a service user identifier (SUID) associated with an authentication code source, a subscribing site and an authentication service. The method includes creating an association of the SUID with the information associated with the user, and isolating the association within the subscribing site. The method includes providing an authentication code generated by the authentication code-generating device from the user to the subscribing site, and providing the authentication code along with the SUID and information identifying the subscribing site to the authentication service. The method includes identifying the code-generating device, using the SUID and the information identifying the subscribing site, and generating an authentication decision for the authentication code with respect to the code-generating device, and providing the decision to the subscribing site.


