Dynamic Authentication Reliability Thresholding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for accessing restricted data in computer networks lack assurance of user identity authenticity, as they rely on password security, which can be compromised, and may not account for varying levels of data sensitivity or device compatibility, leading to potential unauthorized access.

Innovation Solution

The system enhances security by having the user's device send authentication method information, including apparatus details, to the host, which calculates a reliability value based on predefined thresholds, ensuring only authorized and reliable access to sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional password-based authentication is used, then ease of operation is improved, but reliability of authentication is worsened

Engineering Contradiction:
Improveease of authenticationVSAvoidauthentication reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system changes the parameter of authentication reliability by introducing a reliability value associated with each authentication method. The host computer selects authentication methods based on data sensitivity levels, transforming the static password-based system into a dynamic multi-parameter authentication system where reliability can be adjusted according to the security requirements of different data.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple authentication methods are implemented, then reliability is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The host computer is designed with multi-functionality to handle multiple authentication methods (biometric, token-based, knowledge-based). The system universally supports various authentication approaches through a unified reliability value framework, allowing the same host infrastructure to adapt to different authentication requirements without requiring separate specialized systems for each method.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system is made dynamic by allowing the host computer to selectively activate different authentication methods based on the sensitivity level of the data being accessed. The reliability values and authentication method selections can be updated in real-time, transforming a static authentication configuration into a flexible, adaptive system that responds to changing security requirements.

Inventive Principle:
Principle #15Dynamics

3Reliability

If authentication reliability is increased for sensitive data, then security is improved, but ease of operation is worsened

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies local quality by differentiating authentication requirements based on the specific data being accessed. Different sensitivity levels (e.g., personal information vs. financial data) receive different authentication methods and reliability thresholds. This allows high reliability authentication to be applied locally only where needed, rather than uniformly across all data access operations, thereby maintaining convenience for less sensitive operations while ensuring security for critical data.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If the system adapts to different data sensitivity levels, then adaptability is improved, but device complexity is worsened

Engineering Contradiction:
Improvedata sensitivity adaptationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-defining sensitivity levels and associated authentication requirements for different data types. The host computer is pre-configured with reliability values and authentication method mappings for various sensitivity categories. This preliminary structuring allows the system to quickly adapt to different data access scenarios without requiring complex real-time analysis, reducing operational complexity while maintaining high adaptability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8935758B2System and method for checking the authenticity of the identity of a person accessing data over a computer network
Publication Date: 2015.01.13 AUTHASAS
  • US8935758B2 patent drawing
  • US8935758B2 patent drawing
  • US8935758B2 patent drawing

AI summary

A data processing system (100) comprises: a database (4); a host computer (3) and a user computer (1) capable of communicating with each other over a network (2); wherein the user computer sends a data request message (RQ) to the host computer (3), the request message containing Data information (RD), Identity information (RI), and Authenticity information (A; VI), wherein the host computer (3) checks the authentication information and only sends the required data if the Identity information (RI) defines an authorized user and the authentication information (A; VI) authenticates the user identification information. The request message further contains secondary information (RT) and the host computer (3) calculates, from the secondary-information, a reliability value (R), compares the calculated reliability value with a predefined reliability threshold, and sends the required data only if the reliability value is at least as high as the reliability threshold.