Directory Server Authentication with Trusted Markers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing strong authentication methods can be overly burdensome, leading to unnecessary computational resource consumption and potentially causing users and resource providers to opt for less secure alternatives, thereby compromising sensitive data security.
Innovation Solution
A directory server computer system that allows users to indicate trusted resource providers, reducing the authentication level for subsequent interactions. This system involves receiving an indication of trust, storing this data, and providing a lower level of authentication when the user interacts with a trusted resource provider.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If strong authentication methods are implemented, then data security is improved, but user convenience and computational resource efficiency deteriorate
Solution Approach 1:
The patent applies different authentication levels based on the specific interaction context. Trusted resource providers receive reduced authentication requirements (second level) compared to untrusted providers (first level). This local differentiation of authentication quality resolves the contradiction by providing strong authentication only where necessary while offering convenience where trust is established.
Solution Approach 2:
The authentication level dynamically adjusts based on the user's trust indication for the resource provider. The system transitions between first level (strong) and second level (reduced) authentication depending on whether the user has marked the provider as trusted. This dynamic adaptation resolves the contradiction by making authentication strength flexible rather than static.
2Reliability
If strong authentication methods are implemented, then data security is improved, but computational resource consumption increases
Solution Approach 1:
The system applies strong authentication processing only to interactions with untrusted resource providers, while using reduced authentication for trusted providers. This local application of authentication intensity optimizes computational resource usage by concentrating security efforts where they are most needed rather than uniformly applying strong authentication to all interactions.
Solution Approach 2:
The patent uses partial authentication action by implementing reduced authentication (second level) for trusted resource providers instead of always applying full strong authentication. This partial action approach maintains adequate security for trusted interactions while significantly reducing computational resource consumption compared to universal strong authentication.
3Ease of operation
If reduced authentication level is provided for trusted resource providers, then user convenience and resource efficiency are improved, but authentication security may be compromised
Solution Approach 1:
The system performs preliminary authentication at the first (strong) level when the user indicates trust in a resource provider. This preliminary strong authentication establishes a trusted relationship that enables subsequent reduced authentication. The preliminary action ensures security is maintained before the convenience of reduced authentication takes effect.
Solution Approach 2:
The system uses feedback from the user's trust indication to determine the appropriate authentication level. The user's explicit indication of trust serves as feedback that triggers the transition from first level to second level authentication. This feedback mechanism ensures that reduced authentication is only applied when the user actively chooses to trust the provider, maintaining security while enabling convenience.
Data Source
AI summary
An authentication request message from a user conducting an interaction at a resource provider computer is received. It is determined that data representing an indication that the resource provider is trusted by the user and including a trusted marker is present in a database. Authentication to the user is provided, and information indicating that the user has been authenticated and the trusted marker are sent so that authorization request message for the interaction that includes the trusted marker is generated. The trusted marker is validated, and the authorization request message including information related to the interaction and the validated trusted marker is sent to an authorizing entity computer.


