On-Demand Service Access Risk Management via Intermediary Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional database systems are vulnerable to attacks such as phishing and keystroke logging, leading to unauthorized access to user accounts and associated organizations.
Innovation Solution
Implementing mechanisms to manage the risk of access to on-demand services by determining the source of access requests based on stored information, using techniques like authentication via email, token validation, and referencing white or black lists to permit or deny access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional database systems use traditional login authentication, then ease of operation is maintained, but security reliability deteriorates due to vulnerability to phishing and keystroke logging attacks
Solution Approach 1:
The patent introduces an intermediary authentication mechanism that acts as a mediator between the user and the database system. This intermediary validates access requests by checking multiple factors including login credentials, device identifiers, location information, and behavioral patterns before granting access to the database system, thereby enhancing security without significantly impacting user convenience
Solution Approach 2:
The system performs preliminary authentication actions before allowing database access. It pre-establishes security policies, device trust levels, and access rules that are evaluated in advance of each access attempt. This preliminary validation ensures that only authenticated and authorized requests proceed to the database system
2Reliability
If the system implements comprehensive access risk management with multiple authentication factors, then security reliability improves, but device complexity increases
Solution Approach 1:
The authentication system is segmented into independent modular components: credential validation module, device identification module, location verification module, and behavioral analysis module. Each module handles a specific aspect of authentication independently, allowing the system to maintain high security through comprehensive checks while managing complexity through modular design and clear separation of concerns
Solution Approach 2:
The system dynamically adjusts authentication parameters such as the number of required factors, trust thresholds, and validation strictness based on risk assessment. For low-risk requests, fewer authentication factors are required, while high-risk requests trigger more stringent multi-factor authentication, thereby maintaining security reliability while adapting complexity to the actual risk level
Data Source
AI summary
In accordance with embodiments, there are provided mechanisms and methods for managing a risk of access to an on-demand service as a condition of permitting access to the on-demand service. These mechanisms and methods for providing such management can enable embodiments to help prohibit an unauthorized user from accessing an account of an authorized user when the authorized user inadvertently loses login information. The ability of embodiments to provide such management may lead to an improved security feature for accessing on-demand services.


