Web-centric Authentication Protocol for Decentralized Certificate Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication protocols face challenges in mobile and cloud-based environments, where organizations lack control over user devices, leading to credential management issues, security risks, and increased complexity, especially when using web-form based login mechanisms that are insecure and prone to errors.

Innovation Solution

A Web-centric authentication protocol that enables decentralized, enterprise-grade authentication across various devices and networks, utilizing a trusted third party for multi-factor authentication, efficient distribution of X.509 certificates, and a certificate management system for secure, automated certificate generation and renewal, compatible with existing HTTP stacks and TLS/SSL protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If web-form based login mechanisms are used for authentication, then ease of operation is improved, but security is worsened due to being insecure and prone to errors

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authentication service as an intermediary between the client and protected resources. This service issues authentication certificates that enable secure, automated authentication without requiring users to manually manage credentials or use insecure web-form logins. The authentication service mediates the authentication process by verifying credentials and issuing certificates that clients can use to access protected resources securely.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual web-form based authentication mechanisms with an automated certificate-based authentication system. Instead of users filling out login forms and managing passwords manually, the system automatically issues and manages authentication certificates. This substitution eliminates the security vulnerabilities of web-form logins while maintaining ease of operation through automated authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If organizations implement control over user devices for authentication, then security is improved, but adaptability is worsened in mobile and cloud-based environments where devices are personally owned

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts the authentication control from the device itself and places it in a cloud-based authentication service. Instead of requiring organizations to control user devices directly, the authentication credentials and verification processes are extracted and hosted in the cloud. This allows secure authentication to be implemented without needing control over personally owned mobile devices, thereby maintaining both security and adaptability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication service is designed to be universal and work across multiple platforms and device types. It can authenticate users on personally owned mobile devices, cloud-based applications, and enterprise resources without requiring device-specific controls. The service provides multi-functionality by supporting various authentication scenarios (single sign-on, multi-factor authentication) across different environments, making it adaptable to both enterprise and personal devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If decentralized authentication is implemented across various devices and networks, then adaptability is improved, but device complexity increases due to credential management requirements

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication system implements self-service by automatically managing authentication certificates without requiring users to manually handle credentials. The client automatically obtains authentication certificates from the authentication service and uses them for accessing protected resources. This eliminates the complexity of manual credential management while maintaining decentralized authentication across multiple devices and networks, as each device can independently obtain and use its own certificates.

Inventive Principle:
Principle #25Self-service

4Reliability

If existing authentication protocols are used in enterprise desktop scenarios with full organizational control, then security is improved, but ease of operation is worsened due to static configuration requirements

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces dynamic authentication capabilities that adapt to different environments and devices. Instead of requiring static configurations for enterprise desktop scenarios, the authentication service dynamically issues certificates and adjusts authentication methods based on the client device and context. This maintains the security of enterprise protocols while improving ease of operation by eliminating the need for manual static configuration, allowing the system to adapt automatically to various devices and networks.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9369458B2Web-centric authentication protocol
Publication Date: 2016.06.14 RED HAT INC
  • US9369458B2 patent drawing
  • US9369458B2 patent drawing
  • US9369458B2 patent drawing

AI summary

Systems and methods are disclosed for providing a Web-centric authentication protocol. In one implementation, a processing device receives a user request to access a protected resource and determines that a digital certificate for accessing the protected resource is not stored locally. A processing device requests a first digital certificate from an authentication service. A processing device receives the first certificate from the authentication service. A processing device receives a certificate request from the authentication service. A processing device provides the first digital certificate to the authentication service in response to the certificate request. A processing device receives a second digital certificate from the authentication service. A processing device accesses the protected resource using the second digital certificate.