Smart Card Persona Mapping for Multi-Account Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional identity and access management systems face challenges in managing smart cards that are associated with multiple user personas, leading to complex directory maintenance, security vulnerabilities, and user inconvenience due to the need to remember multiple usernames.

Innovation Solution

An identity management platform maps a single smart card to multiple user personas by comparing certificate attributes with user directory values, allowing users to select the appropriate persona for access, thereby simplifying directory management and reducing security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single smart card is mapped to multiple user personas, then user convenience is improved by eliminating the need to remember multiple usernames, but directory maintenance complexity increases

Engineering Contradiction:
Improveuser convenienceVSAvoiddirectory maintenance complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the user identity representation by introducing distinct user personas that are linked to a single smart card through certificate attributes. Each persona represents a specific role or access context, allowing the system to maintain clear, organized mappings between certificates and multiple identities without creating directory clutter.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mapping mechanism that connects the smart card certificate to multiple user personas through shared certificate attributes. This intermediary layer simplifies directory maintenance by providing a structured way to associate a single certificate with multiple personas without requiring complex directory entries or manual tracking.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple user personas are associated with a single smart card, then access flexibility is improved, but security vulnerabilities increase due to complex directory structures

Engineering Contradiction:
Improveaccess flexibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by associating specific certificate attributes with specific user personas based on their security requirements. Each persona can have tailored access permissions and attributes relevant to its function, allowing flexible access control while maintaining security through attribute-based differentiation rather than complex directory structures.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses parameter changes by leveraging certificate attributes as the basis for persona identification and access control. By changing the parameter mapping approach from traditional username-based authentication to certificate attribute-based persona mapping, the system achieves both flexibility and improved security through a simpler, more traceable structure.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If traditional username-based authentication is used for multiple personas, then directory structure remains simple, but user burden increases due to needing to remember multiple usernames

Engineering Contradiction:
Improvedirectory structure simplicityVSAvoiduser burden
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent implements universality by making the single smart card certificate serve multiple functions - it can authenticate the user for multiple different personas and access contexts. The certificate acts as a universal credential that the system automatically resolves to the appropriate persona based on the requested resource or context, eliminating the need for users to remember multiple usernames while maintaining a simple directory structure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables self-service by allowing the system to automatically resolve which user persona should be activated based on the smart card certificate and access context. The user simply presents the certificate, and the system autonomously determines the appropriate persona mapping without requiring the user to manually select or remember specific usernames, thereby reducing user burden while keeping the directory simple.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250358280A1Techniques for mapping a smart card to multiple user personas
Publication Date: 2025.11.20 OKTA INC
  • US20250358280A1 patent drawing
  • US20250358280A1 patent drawing
  • US20250358280A1 patent drawing

AI summary

Methods, systems, and devices for mapping a smart card to multiple user personas are described. A smart card may be used for authenticating a user requesting access to a resource associated with an organization. The smart card may have embedded therein a digital certificate identifying a digital identity of the user. The user may be associated with multiple user accounts or personas in a repository, such as a user directory. Techniques may allow for the multiple user personas to be mapped to digital certificate of a single smart card and for authentication of the multiple user personas using the single smart card.