Single Identifier with Multiple Authentication Secrets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face significant maintenance and security risks due to the need for multiple security systems and accounts for employees with multiple job titles, leading to increased costs and user complexity in managing various authentication methods.
Innovation Solution
A computer-implemented method for multiple security access mechanisms using a single identifier, where a first authentication secret is validated, and attributes are acquired to transmit an access credential, allowing flexible management of security systems and streamlined access across different roles and resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple separate security systems and accounts are maintained for employees with multiple job titles, then authentication security and access control are improved, but system complexity and maintenance costs increase
Solution Approach 1:
The patent combines multiple separate security systems into a single unified authentication system. Instead of maintaining separate accounts and authentication mechanisms for each job title, the system merges them into one system that handles multiple authentication secrets associated with a single identifier, thereby reducing system complexity while maintaining security
Solution Approach 2:
The authentication system is designed to be universal by supporting multiple authentication secrets (such as passwords, biometrics, tokens) for a single identifier. This multi-functional approach allows the same system to handle different authentication requirements for various job titles without requiring separate systems, thus improving reliability without increasing complexity
2Manufacturing precision
If multiple separate security systems are maintained for different job titles, then access control precision is improved, but maintenance burden and costs increase
Solution Approach 1:
The patent merges multiple maintenance-intensive security systems into a single unified system. By combining the authentication mechanisms for different job titles into one system that supports multiple authentication secrets per identifier, the maintenance burden is significantly reduced while access control precision is maintained through role-based attribute resolution
Solution Approach 2:
The system uses parameter changes by storing multiple authentication secrets with associated attributes (such as role, department, clearance level) for each identifier. The system dynamically selects and validates the appropriate authentication secret based on the required access parameters, maintaining precise access control while simplifying maintenance through a unified parameter management approach
3Reliability
If multiple identifiers and authentication methods are required for different roles, then security reliability is improved, but user ease of operation deteriorates
Solution Approach 1:
The patent implements a universal identifier that can be used across multiple roles and authentication methods. Instead of requiring users to remember multiple identifiers, the system allows a single identifier to be associated with multiple authentication secrets, each valid for different roles or contexts, thereby improving ease of operation while maintaining security reliability
Solution Approach 2:
The system introduces an intermediary authentication mechanism that mediates between the user's single identifier and the multiple authentication secrets. The authentication server acts as an intermediary that automatically manages which authentication secret to validate based on the access request context, relieving users of the burden of manually selecting or remembering multiple authentication methods
4Strength
If separate authentication systems are used for different job titles, then authentication strength is improved for sensitive roles, but device complexity increases
Solution Approach 1:
The patent creates a universal authentication framework that can accommodate multiple authentication strengths within a single system. The system supports various authentication methods (passwords, biometrics, hardware tokens, certificates) and can apply appropriate authentication strength requirements for different roles without requiring separate hardware configurations, thus maintaining authentication strength while reducing device complexity
Solution Approach 2:
The system uses parameter changes by storing authentication strength requirements and secret types as configurable parameters associated with each identifier and role. This allows the system to dynamically adjust authentication strength based on the accessed resource or user role without requiring different hardware configurations, maintaining security for sensitive roles while simplifying the overall system architecture
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Techniques for using multiple security access mechanisms for a single identifier are presented. A single identifier is permitted to be associated with multiple authentication secrets. The single identifier resolves to a particular identity in response to the particular authentication secret presented with the single identifier. Moreover, in an embodiment, any resolved identity may have a variety of attributes automatically set for a particular communication session, such as role, access rights, etc.