Adaptive Multi-Factor Authentication for Unpredictable Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-factor authentication systems are inadequate in providing secure access to classified files and documents due to static factor selection policies that do not adapt to dynamic operating environments, making them predictable and vulnerable to hackers, especially in cases of insider threats and data breaches.

Innovation Solution

An adaptive multi-factor authentication system that dynamically selects a subset of authentication factors based on environmental settings, using a trust-based framework that incorporates stochastic optimal selection procedures and biometric and non-biometric modalities, ensuring continuous and triggered authentication with no exploitable patterns, and a multi-user permission strategy that involves dynamic approver selection based on organizational structure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static factor selection policies are used in MFA systems, then implementation is simple and predictable, but security effectiveness decreases and vulnerability to hackers increases

Engineering Contradiction:
Improveadaptability of authentication factorsVSAvoidcomplexity of authentication system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication factor selection where the system adaptively chooses which authentication factors to require based on real-time environmental conditions, user behavior analysis, and risk assessment. This transforms the static MFA configuration into a dynamic system that adjusts its security posture continuously, resolving the contradiction between adaptability and complexity by making the system intelligent rather than merely complex

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters (which factors are required, in what sequence, and with what weights) based on environmental conditions and risk levels. This allows the same authentication system to present different difficulty and security profiles under different conditions, achieving high adaptability without requiring multiple separate authentication systems

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If the same set of authentication factors is used in all situations, then system implementation is straightforward, but security effectiveness decreases and vulnerabilities are exposed

Engineering Contradiction:
Improveflexibility of authentication strategyVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent makes the authentication factor selection dynamic by continuously monitoring environmental conditions, user behavior patterns, and system state. The system adapts its factor selection in real-time, choosing different combinations of authentication factors for different situations, thereby achieving both flexibility and reliability simultaneously

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system dynamically changes which authentication parameters are active and how they are weighted based on current conditions. This allows the authentication strategy to be flexible across different scenarios while maintaining high security reliability through context-aware factor selection

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If traditional access control policies based on trust are used, then ease of operation is maintained, but security against insider threats deteriorates

Engineering Contradiction:
Improveease of access controlVSAvoidprotection against insider threats
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements continuous feedback mechanisms that monitor user behavior, access patterns, and environmental conditions throughout the authentication process and session. This feedback is used to dynamically adjust authentication requirements and detect anomalous behavior, maintaining ease of operation for legitimate users while providing strong protection against insider threats through anomaly detection

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system transitions from static trust-based access control to dynamic risk-based access control. Authentication requirements and monitoring intensity adjust dynamically based on user behavior analysis and environmental context, making the system both easy to operate for legitimate users and highly effective against insider threats

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11038896B2Adaptive multi-factor authentication system with multi-user permission strategy to access sensitive information
Publication Date: 2021.06.15 DASGUPTA DIPANKAR
  • US11038896B2 patent drawing
  • US11038896B2 patent drawing
  • US11038896B2 patent drawing

AI summary

Systems and related methods for providing greater security and control over access to protected or classified resources, files and documents and other forms of sensitive information based upon an initial adaptive selection of multiple modalities for authentication in different operating environments, with subsequent multi-user permission strategy centering on organizational structure. The system calculates trustworthiness values of different authentication factors under various environmental settings, and combines a trust-based adaptive, robust and scalable software-hardware framework for the selection of authentication factors for continuous and triggered authentication with optimal algorithms to determine the security parameters of each of the authentication factors. A subset of authentication factors thus are determined for application at triggering events on-the-fly, thereby leaving no exploitable a priori pattern or clue for hackers to exploit. Upon authentication of an access request, based on the sensitivity or classification of the information being requested by a user, approvers are selected dynamically based on the work environment (e.g., mobility, use of the computing device seeking access, access policy, and the like). The selected sets of approvers are non-repetitive in nature.