Authentication Orchestration System Risk-Adaptive Challenge Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems lack a unified approach to decouple goal authentication levels from challenge methods, leading to inefficient and burdensome security measures that do not adequately consider global risk indicators.
Innovation Solution
An authentication orchestration system that includes a challenge orchestration component to determine a risk level, adjust the goal authentication level, and select appropriate challenge methods to raise the authentication level, while decoupling the authentication client from the challenge methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If challenge methods are applied to raise authentication level, then security is improved, but user convenience deteriorates due to burdensome challenges
Solution Approach 1:
The system dynamically adjusts the authentication level parameter based on risk assessments. When risk is low, the authentication level is reduced, minimizing user burden. When risk is high, the authentication level is increased to enhance security. This parameter adjustment resolves the contradiction by making security measures adaptive rather than static.
Solution Approach 2:
The authentication orchestration system acts as an intermediary between the authentication client and challenge methods. It decouples the client from specific challenge implementations, allowing the system to select appropriate challenges based on risk without requiring the client to handle all challenge types directly, thereby improving user experience while maintaining security.
2Device complexity
If unified authentication approach is implemented, then system complexity is reduced, but adaptability to different risk scenarios deteriorates
Solution Approach 1:
The system segments the authentication process into distinct components: authentication client, orchestration system, risk assessment module, and challenge method library. This segmentation allows each component to have a specific function, reducing overall system complexity while enabling flexible adaptation to different risk scenarios through the orchestration layer.
Solution Approach 2:
The system implements dynamic adaptability where the authentication level and challenge methods are adjusted in real-time based on risk assessments. The orchestration system can dynamically select from multiple challenge methods and adjust authentication requirements without requiring changes to the underlying system architecture, thus maintaining low complexity while achieving high adaptability.
3Reliability
If goal authentication level is set high, then security is improved, but user burden increases due to unnecessary challenges
Solution Approach 1:
The system dynamically changes the authentication level parameter based on real-time risk assessments. Instead of maintaining a consistently high authentication level, the system adjusts the parameter to match the actual risk, ensuring security when needed while minimizing user time burden when risk is low. This resolves the contradiction by making security measures proportional to actual threats.
Data Source
AI summary
Systems, methods, and computer readable media for an authentication orchestration system. Example methods include receiving, from an authentication client, an authentication request, the authentication request comprising an indication of an account and an indication of a goal authentication level. The method further includes accessing a current authentication level and adjusting, based on a risk level, the goal authentication level to an adjusted goal authentication level. The method further includes selecting a challenge method of a plurality of challenge methods based on a difference between the adjusted goal authentication level and the current authentication level. The method further includes performing the selected challenge method with a user associated with the account, and causing to be sent, to the authentication client, an indication of whether the adjusted authentication level was achieved.


