Dynamic Authentication Threshold Adjustment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication attempt thresholds are arbitrary and do not adapt to individual user behavior, potentially compromising usability and security, as they do not account for the probability of successful authentication based on recentness and frequency of successful attempts.

Innovation Solution

A system and method that determine an authentication attempt threshold by analyzing the recentness and frequency of successful authentication attempts, allowing for a dynamic adjustment of the number of attempts based on the user's authentication history, thereby providing a personalized threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a fixed authentication attempt threshold is used for all users, then security is simplified and easier to implement, but security effectiveness deteriorates because it does not adapt to individual user behavior patterns

Engineering Contradiction:
Improveauthentication system complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements dynamic authentication thresholds that automatically adjust based on user behavior patterns. The system monitors authentication history, success rates, and temporal patterns to continuously adapt the threshold for each user, transforming the static security parameter into a dynamic one that responds to actual user characteristics and risk profiles.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication attempt threshold parameter based on analyzed user behavior data. By calculating probability scores from authentication patterns and using these to adjust the threshold parameter dynamically, the system optimizes security effectiveness without requiring complex manual configuration or intervention.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a low authentication attempt threshold is set, then security against brute force attacks is improved, but usability deteriorates because frequent users may be locked out due to temporary glitches or forgotten credentials

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different authentication thresholds to different users based on their individual behavior patterns. Instead of a uniform threshold, each user receives a personalized threshold tailored to their authentication history, success rates, and temporal patterns, allowing frequent users to benefit from higher thresholds while maintaining strict security for users with suspicious patterns.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system continuously monitors authentication attempts and outcomes, using this feedback to adjust individual user thresholds dynamically. By analyzing authentication success rates, temporal patterns, and behavior changes, the system adapts thresholds in real-time, providing higher limits to trusted users while maintaining low limits for potentially compromised accounts.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If a high authentication attempt threshold is set, then usability is improved for infrequent users who may forget credentials, but security deteriorates because it allows more opportunities for brute force attacks

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements location-specific (user-specific) authentication thresholds based on individual behavior patterns. Each user's threshold is customized according to their authentication history, frequency, success rates, and temporal patterns, allowing infrequent users to receive higher thresholds while frequent users receive appropriately lower thresholds for enhanced security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The authentication threshold parameter is dynamically changed based on analyzed user behavior data. The system calculates probability scores from authentication patterns and uses these to adjust the threshold parameter for each user, optimizing the balance between security and usability for every individual user rather than applying a static universal threshold.

Inventive Principle:
Principle #35Parameter changes

4Ease of manufacture

If arbitrary fixed thresholds are used, then implementation is simpler, but security optimization deteriorates because thresholds do not account for user investment or visit frequency

Engineering Contradiction:
Improvesystem implementation simplicityVSAvoidsecurity optimization
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system automatically analyzes user authentication patterns and self-adjusts thresholds without requiring manual configuration or administrator intervention. The authentication system serves itself by monitoring its own data, calculating probability scores, and dynamically adjusting thresholds based on observed user behavior, eliminating the need for complex manual setup while achieving optimized security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10367799B2Systems and methods for determining an authentication attempt threshold
Publication Date: 2019.07.30 PAYPAL INC
  • US10367799B2 patent drawing
  • US10367799B2 patent drawing
  • US10367799B2 patent drawing

AI summary

Systems and methods are provided for determining an authentication attempt threshold. Authentication systems often have predetermined authentication attempt thresholds that may not be sufficient for some users and do not necessarily provide any increased security. Systems and methods provided for determining an authentication thresholds described herein may determine the authentication threshold based on certain factors in a user's authentication attempt history that may provide information about a user's probability of a successful authentication to provide additional security for users more likely to successfully authenticate while providing additional assistance to users who may be less likely to successfully authenticate.