Authentication Orchestration System Risk-Adaptive Challenge Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems lack a unified approach to decouple goal authentication levels from challenge methods, leading to inefficient and burdensome security measures that do not adequately consider global risk indicators.

Innovation Solution

An authentication orchestration system that includes a challenge orchestration component to determine a risk level, adjust the goal authentication level, and select appropriate challenge methods to raise the authentication level, while decoupling the authentication client from the challenge methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If challenge methods are applied to raise authentication level, then security is improved, but user convenience deteriorates due to burdensome challenges

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts the authentication level parameter based on risk assessments. When risk is low, the authentication level is reduced, minimizing user burden. When risk is high, the authentication level is increased to enhance security. This parameter adjustment resolves the contradiction by making security measures adaptive rather than static.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The authentication orchestration system acts as an intermediary between the authentication client and challenge methods. It decouples the client from specific challenge implementations, allowing the system to select appropriate challenges based on risk without requiring the client to handle all challenge types directly, thereby improving user experience while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If unified authentication approach is implemented, then system complexity is reduced, but adaptability to different risk scenarios deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidrisk scenario adaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system segments the authentication process into distinct components: authentication client, orchestration system, risk assessment module, and challenge method library. This segmentation allows each component to have a specific function, reducing overall system complexity while enabling flexible adaptation to different risk scenarios through the orchestration layer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic adaptability where the authentication level and challenge methods are adjusted in real-time based on risk assessments. The orchestration system can dynamically select from multiple challenge methods and adjust authentication requirements without requiring changes to the underlying system architecture, thus maintaining low complexity while achieving high adaptability.

Inventive Principle:
Principle #15Dynamics

3Reliability

If goal authentication level is set high, then security is improved, but user burden increases due to unnecessary challenges

Engineering Contradiction:
Improveauthentication securityVSAvoiduser time burden
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically changes the authentication level parameter based on real-time risk assessments. Instead of maintaining a consistently high authentication level, the system adjusts the parameter to match the actual risk, ensuring security when needed while minimizing user time burden when risk is low. This resolves the contradiction by making security measures proportional to actual threats.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250030681A1Authentication orchestration system
Publication Date: 2025.01.23 SNAP INC
  • US20250030681A1 patent drawing
  • US20250030681A1 patent drawing
  • US20250030681A1 patent drawing

AI summary

Systems, methods, and computer readable media for an authentication orchestration system. Example methods include receiving, from an authentication client, an authentication request, the authentication request comprising an indication of an account and an indication of a goal authentication level. The method further includes accessing a current authentication level and adjusting, based on a risk level, the goal authentication level to an adjusted goal authentication level. The method further includes selecting a challenge method of a plurality of challenge methods based on a difference between the adjusted goal authentication level and the current authentication level. The method further includes performing the selected challenge method with a user associated with the account, and causing to be sent, to the authentication client, an indication of whether the adjusted authentication level was achieved.