Transparent Adaptive Authentication via Network Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for integrating enhanced security features like adaptive authentication and transaction monitoring into online service providers require significant modifications to existing server software, are not transparent, and are resource-intensive, especially when dealing with legacy systems and third-party applications.
Innovation Solution
The technique intercepts and reroutes communications between a server and a client, redirecting them to a 'challenger' device for enhanced security processing, which includes adaptive authentication and transaction monitoring, without modifying the server software, thus integrating security operations transparently into the server workflow.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional methods are used to integrate enhanced security features into online service providers, then security functionality is improved, but system complexity and implementation effort increase significantly
Solution Approach 1:
The security functionality is segmented into a separate network device (challenger) that operates independently from the server. The challenger handles step-up authentication and transaction monitoring, while the server maintains its original simple login processing workflow. This segmentation allows security enhancements without increasing server complexity.
Solution Approach 2:
The challenger acts as an intermediary device between the client and server. It intercepts communications, performs security operations, and relays responses back to the server. This intermediary approach enables enhanced security functionality while keeping the server architecture unchanged and simple.
2Reliability
If server software is modified to incorporate new security functions, then security capabilities are enhanced, but implementation time and resource allocation increase
Solution Approach 1:
The complex security functions (adaptive authentication, transaction monitoring) are extracted from the server software and implemented in a separate challenger device. This extraction eliminates the need to modify server code, thereby reducing implementation time and avoiding engineering resource reallocation.
Solution Approach 2:
Instead of modifying the original server software, a copying approach is used where the challenger device replicates and extends security functionality externally. The server continues to operate with its original code while the challenger provides additional security capabilities through intercepted communications.
3Reliability
If step-up authentication processes are integrated into existing systems, then security identification is improved, but operational simplicity deteriorates
Solution Approach 1:
The challenger serves as an intermediary that automatically handles step-up authentication processes. When the server requests user information, the challenger intercepts this request, adds step-up authentication challenges, and manages the additional verification steps without requiring the server to handle complex authentication logic.
Solution Approach 2:
The challenger performs preliminary security assessments and prepares step-up authentication challenges before the server processes requests. By pre-configuring security rules and authentication methods in the challenger, the system maintains operational simplicity at the server level while still implementing comprehensive security identification.
Data Source
AI summary
Enhanced security processes are integrated into online service provider workflow activities in a transparent fashion with little or no impact on the servers. Enhanced security processes may include adaptive authentication and transaction monitoring. The enhanced security processes are partially implemented in a network device, such as a network communication device, a firewall, or a load balancing system, or a separate security device, rather than being implemented in the server systems hosting on-line websites. With such an arrangement, server software is minimally modified or rewritten, and third party software, such as security applications, remains in operation.


