Transparent Adaptive Authentication via Network Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for integrating enhanced security features like adaptive authentication and transaction monitoring into online service providers require significant modifications to existing server software, are not transparent, and are resource-intensive, especially when dealing with legacy systems and third-party applications.

Innovation Solution

The technique intercepts and reroutes communications between a server and a client, redirecting them to a 'challenger' device for enhanced security processing, which includes adaptive authentication and transaction monitoring, without modifying the server software, thus integrating security operations transparently into the server workflow.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional methods are used to integrate enhanced security features into online service providers, then security functionality is improved, but system complexity and implementation effort increase significantly

Engineering Contradiction:
Improvesecurity functionalityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security functionality is segmented into a separate network device (challenger) that operates independently from the server. The challenger handles step-up authentication and transaction monitoring, while the server maintains its original simple login processing workflow. This segmentation allows security enhancements without increasing server complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The challenger acts as an intermediary device between the client and server. It intercepts communications, performs security operations, and relays responses back to the server. This intermediary approach enables enhanced security functionality while keeping the server architecture unchanged and simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If server software is modified to incorporate new security functions, then security capabilities are enhanced, but implementation time and resource allocation increase

Engineering Contradiction:
Improvesecurity capabilitiesVSAvoidimplementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The complex security functions (adaptive authentication, transaction monitoring) are extracted from the server software and implemented in a separate challenger device. This extraction eliminates the need to modify server code, thereby reducing implementation time and avoiding engineering resource reallocation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of modifying the original server software, a copying approach is used where the challenger device replicates and extends security functionality externally. The server continues to operate with its original code while the challenger provides additional security capabilities through intercepted communications.

Inventive Principle:
Principle #26Copying

3Reliability

If step-up authentication processes are integrated into existing systems, then security identification is improved, but operational simplicity deteriorates

Engineering Contradiction:
Improvesecurity identificationVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The challenger serves as an intermediary that automatically handles step-up authentication processes. When the server requests user information, the challenger intercepts this request, adds step-up authentication challenges, and manages the additional verification steps without requiring the server to handle complex authentication logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The challenger performs preliminary security assessments and prepares step-up authentication challenges before the server processes requests. By pre-configuring security rules and authentication methods in the challenger, the system maintains operational simplicity at the server level while still implementing comprehensive security identification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9282094B1Transparent adaptive authentication and transaction monitoring
Publication Date: 2016.03.08 EMC IP HLDG CO LLC
  • US9282094B1 patent drawing
  • US9282094B1 patent drawing
  • US9282094B1 patent drawing

AI summary

Enhanced security processes are integrated into online service provider workflow activities in a transparent fashion with little or no impact on the servers. Enhanced security processes may include adaptive authentication and transaction monitoring. The enhanced security processes are partially implemented in a network device, such as a network communication device, a firewall, or a load balancing system, or a separate security device, rather than being implemented in the server systems hosting on-line websites. With such an arrangement, server software is minimally modified or rewritten, and third party software, such as security applications, remains in operation.