Context-Aware Authentication System Dynamic Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication techniques fail to dynamically adjust authentication requirements based on context and risk, leading to inefficient resource utilization and potential security vulnerabilities in secure networks.

Innovation Solution

Implementing a context-aware authentication system that uses an enterprise service bus (ESB) and trusted execution environment (TEE) to gather and analyze user identity and contextual data, dynamically adjusting authentication requirements based on risk levels, and requesting additional authentication factors when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication techniques always require multiple authentication factors regardless of context, then security is strengthened, but resource consumption and system complexity increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system dynamically adjusts the number and type of authentication factors required based on real-time risk assessment of the authentication context. When risk is low (e.g., recognized device, normal location), fewer factors are required. When risk is high (e.g., new device, unusual location), additional factors are demanded. This dynamic adaptation resolves the contradiction by making security requirements flexible rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of authentication requirements (number of factors, types of factors) based on contextual parameters such as device reputation, location, time, and user behavior patterns. This parameter adjustment allows the system to maintain high security when needed while reducing complexity when the context is trustworthy.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple authentication factors are always required, then security against unauthorized access is improved, but authentication time and resource usage increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically determines authentication time requirements based on contextual risk factors. Low-risk contexts experience faster authentication with fewer factors, while high-risk contexts undergo more thorough multi-factor authentication. This resolves the time-security contradiction by making authentication duration adaptive to actual risk levels.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary risk assessment before full authentication by evaluating contextual factors such as device recognition, location validity, and time patterns. This preliminary action allows the system to quickly clear low-risk authentication attempts while reserving comprehensive multi-factor authentication for suspicious cases, reducing overall authentication time.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If context-aware authentication is implemented, then resource efficiency is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidsystem implementation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into independent modular components: contextual data collection module, risk assessment module, authentication factor selection module, and authentication execution module. Each module performs a specific function and can be developed, tested, and maintained independently. This segmentation reduces implementation complexity while enabling sophisticated context-aware authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary risk assessment service that sits between contextual data sources and authentication decisions. This intermediary aggregates various contextual parameters (device info, location, time, user behavior) and translates them into risk scores that drive authentication requirements. The intermediary simplifies the overall system architecture by centralizing complex decision logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of energy

If authentication requirements are dynamically adjusted, then unnecessary resource usage is reduced, but ability to detect and measure risk context increases system complexity

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidrisk assessment complexity
Core Design Contradiction:
Loss of energyVSDifficulty of detecting and measuring

Solution Approach 1:

The risk assessment service is designed as a universal multi-functional component that handles diverse contextual parameters (device characteristics, network location, temporal patterns, user behavior) through a unified risk scoring mechanism. This universal approach simplifies resource management by providing a single interface for risk-based authentication decisions regardless of the specific contextual factors involved.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback loops where authentication outcomes and contextual data are continuously monitored and used to refine risk assessment models. This feedback mechanism allows the system to learn from past authentication patterns and improve risk detection accuracy over time, making resource allocation more efficient as the system becomes better at identifying genuine vs. suspicious authentication attempts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3563547B1Fabric assisted identity and authentication making use of context
Publication Date: 2023.04.26 MCAFEE LLC
  • EP3563547B1 patent drawingFigure 1
  • EP3563547B1 patent drawingFigure 2
  • EP3563547B1 patent drawingFigure 3

AI summary

Context-based authentication in a secure network comprised of multiple interconnected programmable devices is described. One technique includes receiving, from a programmable device, identity data and contextual data associated with a current authentication of a user attempting to access a secure network. The user is associated with the programmable device. The technique may include determining, based on the identity data and the contextual data, one or more patterns associated with the current authentication of the user. Furthermore, a risk level associated with the current authentication of the user may be determined based on the identity data, the contextual data, and the one or more patterns. In at least one scenario, access is granted to the secure network in response to the determined risk level. Other advantages and embodiments are described.