Unified Authentication System for Cross-Platform Identity Proofing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face frustration with managing multiple passwords and second-factor authentication objects across various online services, leading to decreased security and increased risk of identity theft due to password reuse and complexity.

Innovation Solution

A method and system for authenticating login requests that involve identifying a client device associated with an identity identifier, sending validation requests, and storing records after successful identity proofing, allowing for streamlined two-factor authentication without the need for multiple physical objects per service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users maintain multiple passwords and second-factor authentication objects for different online services, then security is improved, but user frustration and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication factors (passwords and second-factor authentication objects) into a single integrated authentication system. The identity provider consolidates credentials from multiple sources and presents them as unified authentication options to the user, reducing the number of separate authentication objects users must manage while maintaining security through multiple credential types.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system is designed to work across multiple provider servers and online services universally. A single set of authentication credentials can be used to access different services through the identity provider, eliminating the need for users to maintain separate authentication objects for each service while preserving service-specific security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If users re-use passwords or create easy-to-guess passwords to reduce management burden, then authentication simplicity is improved, but security decreases and identity theft risk increases

Engineering Contradiction:
Improvepassword management easeVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The identity provider acts as an intermediary between users and provider servers, managing multiple credentials on behalf of users. The system stores and manages diverse authentication factors (passwords, second-factor objects) centrally, allowing users to access multiple services without directly managing each credential. This mediator approach enables users to maintain strong, diverse passwords without the burden of remembering or managing multiple authentication objects across different services.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If two-factor authentication schemes are implemented with different physical objects for each service, then security is improved, but user frustration increases due to managing multiple second-factor objects

Engineering Contradiction:
Improveauthentication securityVSAvoidsecond-factor object management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system merges multiple second-factor authentication objects into a single managed collection at the identity provider. Instead of requiring separate second-factor objects for each service, the identity provider consolidates these credentials and manages them centrally, allowing users to authenticate with a unified set of credentials across multiple services while maintaining the security benefits of second-factor authentication.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2873192B1Methods and systems for using derived credentials to authenticate a device across multiple platforms
Publication Date: 2018.01.31 SECUREKEY TECH
  • EP2873192B1 patent drawingFigure 1A
  • EP2873192B1 patent drawingFigure 1B
  • EP2873192B1 patent drawingFigure 1C

AI summary

Methods and systems for adapting existing service provider servers to support two-factor authentication by leveraging an authentication server, which may be operated by a third party. Where a user desires to access content or services offered by a service provider server, the user may employ a client agent (for example, a web browser) in order to authenticate with the service provider server. Service provider server can redirect client agent to an authentication server to process at least a second factor or derived credential.