Adaptive Authentication Suspension for Token Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems face challenges in ensuring privacy and authentication between users in computer networks, particularly in scenarios where authentication tokens may fall out of synchronization or require multiple valid codes for Next Code Mode, leading to inconvenience and potential security risks.

Innovation Solution

A method and apparatus that detect occurrences associated with an authentication device, receive a one-time password, and an unrelated authentication factor, determining whether to suspend authentication based on both, allowing for adaptive authentication and synchronization adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the token requires entering a second valid authentication code within a specified validity window to move from Next Code Mode, then authentication security is maintained, but user convenience deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic authentication suspension based on real-time analysis of authentication factors. The system adaptively adjusts authentication requirements by evaluating multiple factors including device characteristics, location data, behavior patterns, and temporal information. When the system determines low risk through this dynamic assessment, it suspends the requirement for second code entry, thereby maintaining security while improving user convenience. This dynamic approach replaces the static validity window constraint with an intelligent, context-aware decision-making process.

Inventive Principle:
Principle #15Dynamics

2Reliability

If the authentication system requires multiple valid codes from the same token in Next Code Mode, then security against lost tokens is improved, but authentication time increases

Engineering Contradiction:
Improvesecurity against lost tokensVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary risk assessment before requiring multiple code entries. The system proactively evaluates authentication factors such as device fingerprint, geographic location, time of day, and user behavior patterns to pre-determine whether the authentication attempt poses a security risk. When the preliminary assessment indicates low risk, the system suspends the Next Code Mode requirement, allowing single-code authentication. This preliminary action prevents unnecessary time delays while maintaining security by only requiring multiple codes when risk is detected.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors authentication attempts and adjusts its behavior based on feedback from multiple authentication factors. It analyzes patterns in authentication requests, device characteristics, and user behavior to dynamically adjust the stringency of authentication requirements. This feedback mechanism allows the system to learn from authentication outcomes and optimize the balance between security and authentication time, reducing unnecessary delays for legitimate users while maintaining protection against token loss scenarios.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9300661B1Method, apparatus, and computer program product for determining whether to suspend authentication by an authentication device
Publication Date: 2016.03.29 EMC IP HLDG CO LLC
  • US9300661B1 patent drawing
  • US9300661B1 patent drawing
  • US9300661B1 patent drawing

AI summary

There is disclosed a technique for use in authentication. In one embodiment, the technique comprises a method with the following steps. The method comprises detecting an occurrence associated with an authentication device. The method also comprises receiving a one-time password as issued by the authentication device. The method further comprises receiving an authentication factor, wherein the authentication factor is unrelated to one-time passwords issued by the authentication device. The method still further comprises determining whether to suspend authentication by the authentication device based on the one-time password and the authentication factor.