Adaptive IP Authentication via Risk Counter

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication processes on computer networks are often either overly burdensome for users or risk inaccurately authenticating users, leading to strain on network bandwidth and potential data loss or compromise.

Innovation Solution

A system that uses an IP address counter to determine an authentication level for users by incrementing the counter for consistent access from the same IP address and decrementing it for access from different IP addresses, thereby tailoring the authentication process to the perceived risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a more burdensome authentication process is implemented, then authentication accuracy is improved, but user convenience deteriorates and network bandwidth is consumed

Engineering Contradiction:
Improveauthentication accuracyVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication process is made dynamic by adjusting the authentication level based on real-time risk assessment. The system transitions from static authentication to adaptive authentication where the burden shifts based on IP address behavior patterns, device consistency, and detected anomalies, resolving the contradiction between security and convenience

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters dynamically based on risk parameters. When risk is low, minimal authentication is required; when risk increases, authentication requirements escalate. This parameter adaptation allows the system to maintain high authentication accuracy when needed while providing ease of operation during normal usage

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a more burdensome authentication process is implemented, then authentication accuracy is improved, but network bandwidth is consumed and server resources are strained

Engineering Contradiction:
Improveauthentication accuracyVSAvoidnetwork bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system applies partial authentication action based on risk level. Instead of always performing full authentication, it performs minimal authentication for low-risk scenarios and reserves full authentication for high-risk scenarios. This selective application reduces unnecessary network bandwidth consumption and server resource strain while maintaining authentication accuracy when required

Inventive Principle:
Principle #16Partial or excessive action

3Device complexity

If authentication is performed without risk assessment, then authentication simplicity is maintained, but unnecessary authentication processes clog network bandwidth

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidnetwork bandwidth
Core Design Contradiction:
Device complexityVSLoss of energy

Solution Approach 1:

The system performs preliminary risk assessment before authentication to determine the appropriate authentication level. By evaluating IP address behavior patterns, device consistency, and contextual factors in advance, the system pre-determines authentication requirements and avoids unnecessary authentication processes that would clog network bandwidth

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250148120A1Determining the Relative Risk for Using an Originating IP Address as an Identifying Factor
Publication Date: 2025.05.08 TRUIST BANK
  • US20250148120A1 patent drawing
  • US20250148120A1 patent drawing
  • US20250148120A1 patent drawing

AI summary

A relative risk can be determined using an originating Internet Protocol (IP) address as an identifying factor for purposes of authenticating a user. The originating IP address can be used as an identifying factor for a particular user account to determine potentially fraudulent activity and reduce the risk of fraud. This additional identifying factor can be used as a part of an overall authentication platform to help screen fraud attempts and to authenticate valid and non-fraudulent users. Using certain aspects can distinguish whether originating IP addresses are public or private. Some examples can track and match originating IP addresses to user accounts and also can keep track of recently active sessions for each IP address.