Context-Based Adaptive Authentication for Heterogeneous Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional IT management techniques are inadequate for managing heterogeneous environments where client devices and applications are not under the control of enterprise IT departments, particularly in BYOD scenarios and cloud-hosted SaaS applications, leading to security and access control challenges.
Innovation Solution
An adaptive authentication system that uses an access control system to manage access control policies based on context, determining the appropriate security policies for client devices accessing enterprise applications by considering attributes such as location, time, device type, and request parameters, and applying different security measures accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional IT management techniques are used to control client devices and applications, then security and access control are maintained, but the system cannot support heterogeneous environments where devices and applications are not under IT control (BYOD, SaaS)
Solution Approach 1:
The access control system dynamically adjusts authentication requirements based on real-time context attributes such as device type, location, time, and application sensitivity. This allows the system to adapt to heterogeneous environments while maintaining security by applying appropriate controls for each context rather than using static policies
Solution Approach 2:
The system changes security parameters (authentication methods, authorization levels) based on contextual parameters like device characteristics, geographic location, time of access, and application criticality. This enables the system to support diverse devices and applications while maintaining reliable security control through parameter-based policy adjustment
2Reliability
If strict security policies are applied to all access requests, then security is improved, but user convenience deteriorates due to excessive authentication requirements
Solution Approach 1:
The system applies different security measures to different access contexts rather than uniform policies. For example, highly sensitive applications receive stricter authentication while less sensitive ones use simpler methods. This local differentiation maintains security where needed while improving user convenience where possible
Solution Approach 2:
The system applies authentication measures proportionally to the risk level of each access request. Instead of always requiring full authentication, it applies partial authentication for low-risk contexts and excessive (strict) authentication only when necessary based on context analysis, thus balancing security and convenience
3Ease of operation
If context-based adaptive authentication is implemented, then user convenience is improved by reducing unnecessary authentication, but system complexity increases
Solution Approach 1:
The access control system is segmented into independent modules: context attribute collection, context analysis, policy selection, and authentication execution. This modular architecture manages system complexity by allowing each component to be developed and maintained independently while working together to provide adaptive authentication
Data Source
AI summary
A system and method are disclosed for adaptive authentication. An access control system stores policies for an enterprise, where each policy specifies a type of access control. The type of access control includes one or more security rules, which may specify authentication procedures, allowable behaviors, or both. The access control system stores a mapping from contexts of requests to interact with applications and access control policies. When a user requests access to an application associated with the enterprise via a client, the access control system receives the context of the request. The access control system selects an access control policy for the context of the request. The access control system sends access control information from the access control policy selected to the client. The client interacts with the user to perform the authentication.


