Cloud Authentication Service Dynamic Challenge Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional knowledge-based authentication techniques using static, site-centric challenges are vulnerable to social engineering attacks and limited by stale user intelligence, as they rely on information specific to a single website, which is not rich or diverse and can become ineffective due to inactivity.
Innovation Solution
A cloud-based authentication service tracks credential usage across multiple websites to generate dynamic knowledge-based challenges based on the end-user's credential usage history, providing more secure and robust authentication by leveraging rich and diverse user intelligence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static, site-centric knowledge-based challenges are used for authentication, then the authentication process is simple to implement, but the security is weak due to vulnerability to social engineering attacks
Solution Approach 1:
The patent transforms static KB challenges into dynamic ones by continuously updating challenge questions based on tracked credential usage patterns. The system monitors user authentication behavior across multiple websites and generates challenges reflecting current usage, making the authentication system adaptive and resistant to social engineering attacks while maintaining manageable complexity through automated tracking and generation processes
Solution Approach 2:
The system implements feedback loops by tracking credential usage across websites and using this information to generate subsequent KB challenges. The authentication service continuously monitors user authentication patterns and feeds this information back into challenge generation, creating a responsive security system that adapts to user behavior while maintaining security against social engineering attacks
2Reliability
If static knowledge-based challenges based on user information gathered by the RP website are used, then the challenge generation is straightforward, but the intelligence becomes stale due to user inactivity
Solution Approach 1:
The system performs preliminary tracking of credential usage across multiple websites before authentication is needed. By continuously monitoring and storing user authentication patterns in advance, the system ensures that current and relevant intelligence is available when KB challenges are generated, eliminating the delay and staleness associated with gathering information at the time of authentication
Solution Approach 2:
The patent implements continuous tracking of credential usage across websites, ensuring that the intelligence used for KB challenges is always current. The system maintains ongoing monitoring of user authentication patterns rather than relying on periodic or static data collection, eliminating gaps where intelligence could become stale and ensuring continuous availability of relevant user behavior information
3Reliability
If site-centric knowledge-based challenges are used, then the implementation is simple and focused on a single website, but the user intelligence is not rich or diverse
Solution Approach 1:
The patent implements a multi-tenanted cloud-based authentication service that tracks credential usage across multiple websites simultaneously. This universal tracking system serves multiple functions: monitoring user behavior, generating diverse KB challenges, and providing security across different websites, thereby enriching user intelligence without proportionally increasing complexity through shared infrastructure and centralized processing
Data Source
AI summary
A method and apparatus for knowledge-based authentication by a cloud-based authentication service are described. A cloud-based authentication service is to track credential usage of an end-user at the cloud-based authentication service. The authentication service receives a credential request for credentials associated with the end-user from a relying party website. The end-user no longer has authentication credentials for access to the relying party website. The authentication service issues a dynamic knowledge-based (KB) challenge to the end-user, the dynamic KB challenge being based on at least some of the tracked credential usage of the end-user. The processing logic receives a response to the dynamic KB challenge from the end-user and sends temporary credentials to the relying party for the end-user when the response is validated.


