Algorithmic Decay Authentication Assurance Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems require users to consistently provide multiple authentication factors, which can diminish user experience and increase security challenges, as factors like voice recognition are easily performed but others, such as one-time codes, require significant user effort, and do not account for varying transaction levels or user and account authentication assurance levels.

Innovation Solution

Determining a composite measure of authentication assurance using a combination of user-level and account-level indicators, applying an algorithmic decay model to historical authentication activities, and considering both historical and runtime-provided inputs to dynamically adjust authentication requirements based on confidence levels and transaction types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication factors are required for each log-in, then security is improved, but user experience deteriorates due to increased effort and complexity

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts authentication requirements based on real-time risk assessment, user behavior patterns, and transaction sensitivity. Instead of requiring consistent multi-factor authentication for all log-ins, the system adapts the authentication challenge level to match the actual security risk, reducing unnecessary friction for low-risk transactions while maintaining strong security for high-risk operations

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters such as the number of factors required, the type of factors needed, and the frequency of re-authentication based on contextual parameters including transaction value, user location, device trust level, and time since last authentication. This allows the system to optimize between security and usability by adjusting parameters rather than applying a fixed authentication policy

Inventive Principle:
Principle #35Parameter changes

2Reliability

If authentication factors are required frequently, then security is improved, but user effort and time consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication actions by continuously monitoring user behavior, device characteristics, and transaction patterns in the background. This preliminary assessment establishes a baseline trust level that allows users to bypass authentication steps for routine, low-risk transactions, reducing authentication time while maintaining security through continuous background verification

Inventive Principle:
Principle #10Preliminary action

3Reliability

If consistent multi-factor authentication is applied, then account compromise is reduced, but system complexity and resource consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies different authentication qualities and requirements to different contexts, users, and transactions rather than using a uniform approach. High-value transactions or unusual patterns trigger enhanced multi-factor authentication, while routine transactions use simplified methods. This local differentiation reduces overall system complexity by applying complex security measures only where locally required

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11227036B1Determination of authentication assurance via algorithmic decay
Publication Date: 2022.01.18 AMAZON TECH INC
  • US11227036B1 patent drawing
  • US11227036B1 patent drawing
  • US11227036B1 patent drawing

AI summary

Disclosed are various embodiments for determining authentication assurance using algorithmic decay. In an embodiment, an authentication request associated with an account is received. At least one historical authentication event associated with the account is determined. A measure of authentication assurance is determined based at least in part on applying an exponential time decay to at least one authentication assurance value individually corresponding to the historical authentication event(s). A response to the authentication request is generated based at least in part on the measure of authentication assurance.