Unified Authentication SDK for Multi-Protocol Assurance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems become cumbersome for consumers as security levels increase, and not all consumers or applications require high security, leading to inefficient data security for sensitive information across various devices.
Innovation Solution
A Centralized Authentication System with a unified interface and Object Data Structure that supports multiple authentication protocols and systems, allowing for customizable assurance levels and seamless device registration and authentication across various devices, including smartphones and personal computers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple authentication systems with high security levels are implemented, then data security is improved, but system complexity and user burden increase
Solution Approach 1:
The patent implements a universal authentication system that can handle multiple authentication protocols (password-based, certificate-based, biometric, etc.) through a single unified framework. The system provides multi-functionality by supporting various assurance levels (AL1-AL5) within the same architecture, allowing it to adapt to different security requirements without requiring separate authentication systems for each protocol or security level.
Solution Approach 2:
The system uses parameter changes by varying the assurance level (AL1-AL5) and authentication protocol parameters based on the specific service and user requirements. The Object Data Structure dynamically adjusts authentication parameters such as required factors, protocol types, and validation strictness according to the security sensitivity of the accessed resource, thereby achieving high security where needed while maintaining simplicity where sufficient.
2Reliability
If multiple authentication systems with high security levels are implemented, then data security is improved, but ease of operation deteriorates
Solution Approach 1:
The authentication system is dynamic in that it automatically adjusts the authentication requirements based on the service being accessed, user profile, and security policies. The system can switch between different assurance levels and protocols without user intervention, presenting only the necessary authentication steps to each user. This dynamic adaptation maintains ease of operation for low-security services while ensuring high security for sensitive operations.
Solution Approach 2:
The system applies local quality by tailoring the authentication complexity to the specific service or resource being accessed. Different parts of the system (different services) receive different authentication treatments based on their security requirements. For example, a public information service may require only AL1 authentication, while a medical records service requires AL4 or AL5, thereby optimizing user experience for each local context.
3Reliability
If authentication systems are implemented for all consumers, then security coverage is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal authentication client that can operate across all device types (smartphones, tablets, computers, wearables) using a single unified SDK. The Object Data Structure and authentication framework are designed to be device-agnostic, supporting multiple protocols and assurance levels within the same codebase, thereby providing comprehensive security coverage without requiring separate authentication systems for each device category.
Data Source
AI summary
Embodiments of the disclosure provide a method of incorporating multiple authentication systems and protocols. The types of authentication systems and protocols can vary based on desired assurance levels. A Centralized Authentication System together with an authentication policy dictates acceptable authentication systems. Authorization data for each authorization system are captured and packaged into a single Object Data Structure. The authorization data can be compared to data stored in an identity store for authentication. The authorization data can also be used for user and device registration and for transferring an authentication or registration token from a previously authenticated and registered device to a new device.


