Unified Authentication SDK for Multi-Protocol Assurance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems become cumbersome for consumers as security levels increase, and not all consumers or applications require high security, leading to inefficient data security for sensitive information across various devices.

Innovation Solution

A Centralized Authentication System with a unified interface and Object Data Structure that supports multiple authentication protocols and systems, allowing for customizable assurance levels and seamless device registration and authentication across various devices, including smartphones and personal computers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication systems with high security levels are implemented, then data security is improved, but system complexity and user burden increase

Engineering Contradiction:
Improvedata securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication system that can handle multiple authentication protocols (password-based, certificate-based, biometric, etc.) through a single unified framework. The system provides multi-functionality by supporting various assurance levels (AL1-AL5) within the same architecture, allowing it to adapt to different security requirements without requiring separate authentication systems for each protocol or security level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses parameter changes by varying the assurance level (AL1-AL5) and authentication protocol parameters based on the specific service and user requirements. The Object Data Structure dynamically adjusts authentication parameters such as required factors, protocol types, and validation strictness according to the security sensitivity of the accessed resource, thereby achieving high security where needed while maintaining simplicity where sufficient.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple authentication systems with high security levels are implemented, then data security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system is dynamic in that it automatically adjusts the authentication requirements based on the service being accessed, user profile, and security policies. The system can switch between different assurance levels and protocols without user intervention, presenting only the necessary authentication steps to each user. This dynamic adaptation maintains ease of operation for low-security services while ensuring high security for sensitive operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies local quality by tailoring the authentication complexity to the specific service or resource being accessed. Different parts of the system (different services) receive different authentication treatments based on their security requirements. For example, a public information service may require only AL1 authentication, while a medical records service requires AL4 or AL5, thereby optimizing user experience for each local context.

Inventive Principle:
Principle #3Local quality

3Reliability

If authentication systems are implemented for all consumers, then security coverage is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication client that can operate across all device types (smartphones, tablets, computers, wearables) using a single unified SDK. The Object Data Structure and authentication framework are designed to be device-agnostic, supporting multiple protocols and assurance levels within the same codebase, thereby providing comprehensive security coverage without requiring separate authentication systems for each device category.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10938814B2Unified authentication software development kit
Publication Date: 2021.03.02 AETNA INC
  • US10938814B2 patent drawing
  • US10938814B2 patent drawing
  • US10938814B2 patent drawing

AI summary

Embodiments of the disclosure provide a method of incorporating multiple authentication systems and protocols. The types of authentication systems and protocols can vary based on desired assurance levels. A Centralized Authentication System together with an authentication policy dictates acceptable authentication systems. Authorization data for each authorization system are captured and packaged into a single Object Data Structure. The authorization data can be compared to data stored in an identity store for authentication. The authorization data can also be used for user and device registration and for transferring an authentication or registration token from a previously authenticated and registered device to a new device.