Single Identifier with Multiple Authentication Secrets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face significant maintenance and security risks due to the need for multiple security systems and accounts for employees with multiple job titles, leading to increased costs and user complexity in managing various authentication methods.

Innovation Solution

A computer-implemented method for multiple security access mechanisms using a single identifier, where a first authentication secret is validated, and attributes are acquired to transmit an access credential, allowing flexible management of security systems and streamlined access across different roles and resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple separate security systems and accounts are maintained for employees with multiple job titles, then authentication security and access control are improved, but system complexity and maintenance costs increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate security systems into a single unified authentication system. Instead of maintaining separate accounts and authentication mechanisms for each job title, the system merges them into one system that handles multiple authentication secrets associated with a single identifier, thereby reducing system complexity while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system is designed to be universal by supporting multiple authentication secrets (such as passwords, biometrics, tokens) for a single identifier. This multi-functional approach allows the same system to handle different authentication requirements for various job titles without requiring separate systems, thus improving reliability without increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If multiple separate security systems are maintained for different job titles, then access control precision is improved, but maintenance burden and costs increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidmaintenance burden
Core Design Contradiction:
Manufacturing precisionVSEase of manufacture

Solution Approach 1:

The patent merges multiple maintenance-intensive security systems into a single unified system. By combining the authentication mechanisms for different job titles into one system that supports multiple authentication secrets per identifier, the maintenance burden is significantly reduced while access control precision is maintained through role-based attribute resolution

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system uses parameter changes by storing multiple authentication secrets with associated attributes (such as role, department, clearance level) for each identifier. The system dynamically selects and validates the appropriate authentication secret based on the required access parameters, maintaining precise access control while simplifying maintenance through a unified parameter management approach

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple identifiers and authentication methods are required for different roles, then security reliability is improved, but user ease of operation deteriorates

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiduser ease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal identifier that can be used across multiple roles and authentication methods. Instead of requiring users to remember multiple identifiers, the system allows a single identifier to be associated with multiple authentication secrets, each valid for different roles or contexts, thereby improving ease of operation while maintaining security reliability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary authentication mechanism that mediates between the user's single identifier and the multiple authentication secrets. The authentication server acts as an intermediary that automatically manages which authentication secret to validate based on the access request context, relieving users of the burden of manually selecting or remembering multiple authentication methods

Inventive Principle:
Principle #24Intermediary (Mediator)

4Strength

If separate authentication systems are used for different job titles, then authentication strength is improved for sensitive roles, but device complexity increases

Engineering Contradiction:
Improveauthentication strengthVSAvoidhardware configurations
Core Design Contradiction:
StrengthVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication framework that can accommodate multiple authentication strengths within a single system. The system supports various authentication methods (passwords, biometrics, hardware tokens, certificates) and can apply appropriate authentication strength requirements for different roles without requiring separate hardware configurations, thus maintaining authentication strength while reducing device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses parameter changes by storing authentication strength requirements and secret types as configurable parameters associated with each identifier and role. This allows the system to dynamically adjust authentication strength based on the accessed resource or user role without requiring different hardware configurations, maintaining security for sensitive roles while simplifying the overall system architecture

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP1918845B1Multiple security access mechanisms for a single identifier
Publication Date: 2013.01.16 DELL EMC
  • EP1918845B1 patent drawingFigure 1
  • EP1918845B1 patent drawingFigure 2
  • EP1918845B1 patent drawingFigure 3~4

AI summary

Techniques for using multiple security access mechanisms for a single identifier are presented. A single identifier is permitted to be associated with multiple authentication secrets. The single identifier resolves to a particular identity in response to the particular authentication secret presented with the single identifier. Moreover, in an embodiment, any resolved identity may have a variety of attributes automatically set for a particular communication session, such as role, access rights, etc.