Continuous Authentication via Risk Orchestration and Behavioral Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital transactions are often compromised by unauthorized parties or threat actors, necessitating the validation of user identity and behavior beyond initial authentication to prevent fraud and ensure security.

Innovation Solution

A method for secure continuous authentication that involves a primary identity provider collecting contextual and behavioral information from a user entity, delegating a risk-based multi-factor authentication process to a third-party identity provider, and conducting policy orchestration to detect anomalies and adjust authorization levels accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If continuous authentication and behavioral monitoring are implemented, then security against fraudulent activities is improved, but system complexity and computational resources increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent components: primary identity provider, third-party identity provider, risk engine, and policy orchestration module. Each component performs a specific function (authentication, risk assessment, policy enforcement), allowing the complex continuous authentication system to be managed through modular, independently deployable units that reduce overall system complexity while maintaining high security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A risk engine acts as an intermediary between the identity providers and the services. It collects contextual and behavioral information, performs risk calculations, and communicates risk levels to the policy orchestration module. This intermediary layer simplifies the architecture by centralizing complex analytical functions and preventing direct coupling between authentication components and service access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If risk-based multi-factor authentication and continuous monitoring are performed, then detection precision of unauthorized access is improved, but processing time and user friction increase

Engineering Contradiction:
Improvedetection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary risk assessment during the initial authentication phase by collecting contextual information (device characteristics, location, network environment) and behavioral baselines. This preliminary action establishes a risk profile before the user accesses services, enabling faster real-time decisions later without requiring extensive processing during critical access moments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial monitoring strategies where not all users undergo the same level of continuous authentication. Low-risk users experience minimal friction with basic authentication, while the system performs excessive monitoring (collecting detailed behavioral data) only when risk thresholds are exceeded or anomaly detection is triggered, optimizing the balance between detection precision and processing time.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If contextual and behavioral information is collected and analyzed in real-time, then accuracy of anomaly detection is improved, but data processing load and energy consumption increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata processing load
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The risk engine implements feedback mechanisms where anomaly detection results from behavioral analysis feed back into updating risk profiles and adjusting monitoring intensity. When anomalies are detected, the system increases data collection and analysis intensity; when behavior is normal, it reduces processing load. This feedback-driven adaptive approach maintains high anomaly detection accuracy while dynamically optimizing energy consumption based on actual security needs.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes processing parameters dynamically based on risk levels. Contextual information collection frequency, behavioral analysis depth, and computational resources allocated to monitoring are adjusted as parameters according to the user's risk profile and current activity patterns. This allows the system to maintain high detection accuracy for suspicious activities while minimizing data processing load during normal operations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11888839B1Continuous authentication through orchestration and risk calculation post-authentication system and method
Publication Date: 2024.01.30 SECUREAUTH CORP
  • US11888839B1 patent drawing
  • US11888839B1 patent drawing
  • US11888839B1 patent drawing

AI summary

A system and method for secure authentication of user entity and user entity device identity. The system and method described herein allows an identity to be continuously proven because of user entity's behavior and their biometrics. With all the fraud and risk that exists today, if someone has a user entity's driver's license they can do a lot of harm. A primary identity provider passes user contextual and behavioral information to third party secondary identity providers to allow risk based continuous authentication and step up post-authorization authentication or termination of session as required upon detection of an anomaly.