Contextual Network Authentication with Adaptive Privileges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user authentication methods in networks are binary, do not consider contextual factors, lead to vulnerability to attacks, require re-authentication upon mobility, and are incompatible with diverse client devices, causing inconvenience and security risks.

Innovation Solution

A method that evaluates a security context for network access, assigns adaptive access privileges, generates and stores a security token on the client device for subsequent connections, and supports multiple authentication schemes to facilitate seamless reconnection and enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional binary authentication methods are used, then authentication simplicity is maintained, but network security is compromised due to lack of contextual evaluation

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system transitions from static binary authentication to dynamic contextual authentication. The network authentication server evaluates multiple contextual factors (device security posture, user behavior, location, time) in real-time to dynamically determine authentication outcomes and access privileges, resolving the contradiction between security and simplicity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of authentication by introducing multiple evaluation dimensions beyond simple credential verification. Instead of binary pass/fail, the system evaluates device security state, user context, and environmental factors to determine authentication results, thereby improving security without requiring overly complex user actions

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If full access is granted upon successful authentication, then user convenience is improved, but network vulnerability to attacks increases

Engineering Contradiction:
Improveuser convenienceVSAvoidnetwork vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies the principle of local quality by granting different levels of access privileges to different users based on their specific contextual evaluation. Instead of uniform full access, each user receives tailored access rights appropriate to their device security state, user role, and contextual factors, thereby maintaining convenience for legitimate users while limiting vulnerability to attackers

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Access privileges are dynamically adjusted based on real-time contextual evaluation. The system can elevate or reduce access rights depending on the user's device security posture, behavior patterns, and environmental context, resolving the contradiction between providing convenient full access and maintaining security against attacks

Inventive Principle:
Principle #15Dynamics

3Reliability

If re-authentication is required upon network mobility, then authentication security is maintained, but user experience deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidre-authentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary contextual evaluation and establishes security tokens during initial authentication. These tokens allow users to move within the network without repeated full authentication, as the preliminary security assessment remains valid. This resolves the contradiction by maintaining security through pre-established contextual validation while eliminating time-consuming re-authentication

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication state and security tokens continue to be valid during network mobility, allowing uninterrupted access as users move between network locations. The system maintains continuous authentication validity rather than requiring periodic re-authentication, thereby preserving both security and user experience during mobility

Inventive Principle:
Principle #20Continuity of useful action

4Adaptability or versatility

If a single authentication scheme is supported, then system simplicity is maintained, but adaptability to diverse client devices is reduced

Engineering Contradiction:
Improvedevice compatibilityVSAvoidauthentication scheme complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network authentication server is designed with multi-functionality to support multiple authentication schemes and protocols simultaneously. It can evaluate contextual factors and perform authentication using different methods (certificate-based, token-based, behavioral biometrics) depending on the client device capabilities, thereby achieving universal compatibility without requiring each device to implement every scheme

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The network authentication server acts as an intermediary that translates between diverse client device authentication capabilities and unified network access control. It mediates the interaction by adapting its evaluation and authentication methods to match the specific client device while maintaining consistent security policies, resolving the contradiction between supporting diversity and maintaining simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10764264B2Technique for authenticating network users
Publication Date: 2020.09.01 AVAYA INC
  • US10764264B2 patent drawing
  • US10764264B2 patent drawing
  • US10764264B2 patent drawing

AI summary

A technique for authenticating network users is disclosed. In one particular exemplary embodiment, the technique may be realized as a method for authenticating network users. The method may comprise receiving, from a client device, a request for connection to a network. The method may also comprise evaluating a security context associated with the requested connection. The method may further comprise assigning the client device one or more access privileges based at least in part on the evaluation of the security context.