Automated Device Identifier Determination for Risk-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise computer networks face challenges in providing adequate security due to their growing size and complexity, which strains existing network security systems, and conventional credential-based authentication techniques often fail to detect and remediate advanced persistent threats (APTs) effectively.

Innovation Solution

Implementing automated determination of device identifiers for risk-based access control, which supplements conventional authentication methods by using additional device identifiers to generate risk scores for access requests, thereby enhancing security against APTs and other attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional credential-based authentication techniques are used, then the authentication process is simple and fast, but the system fails to detect advanced persistent threats (APTs) and sophisticated attacks

Engineering Contradiction:
Improvedetection accuracyVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by collecting multiple device identifiers (hardware ID, OS type, browser type, screen resolution, etc.) before the authentication decision is made. These identifiers are gathered in advance and stored for comparison, enabling the system to detect APTs and sophisticated attacks without adding complexity to the user authentication process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces device identifiers as an intermediary element between the user credentials and the authentication decision. These identifiers serve as mediators that provide additional information about the device characteristics without requiring users to directly interact with or understand the complex authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network security systems process security alerts and deploy attack remediation measures in large enterprise networks, then security coverage is improved, but the limited resources of the network security system become strained

Engineering Contradiction:
Improvesecurity protection levelVSAvoidsystem resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary risk assessment by comparing device identifiers against stored profiles before security incidents occur. This preliminary action enables the system to pre-identify suspicious devices and prioritize security resources, avoiding the need to process all security alerts with equal resource allocation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of risk assessment from binary (secure/not secure) to a continuous scale by incorporating multiple device identifier characteristics. This enables more nuanced risk scoring that helps security systems prioritize responses based on actual risk levels, improving resource efficiency.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If conventional authentication systems are used in growing enterprise networks with diverse devices, then system simplicity is maintained, but the ability to detect access anomalies at an early stage is insufficient

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidaccess control complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the authentication verification process into multiple independent checks: collecting device identifiers, comparing each identifier against stored profiles, evaluating mismatches, and making authentication decisions. This segmentation enables precise anomaly detection at each stage without requiring a complete redesign of the authentication system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of device identification from relying solely on user-provided credentials to incorporating multiple objective device characteristics (hardware ID, OS type, browser type, screen resolution). This parameter expansion enables more precise anomaly detection while maintaining automated processing.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10885162B2Automated determination of device identifiers for risk-based access control in a computer network
Publication Date: 2021.01.05 RSA SECURITY INC
  • US10885162B2 patent drawing
  • US10885162B2 patent drawing
  • US10885162B2 patent drawing

AI summary

A processing device in an illustrative embodiment includes a processor coupled to a memory and is configured to receive user credentials from a user device in conjunction with an access request, to apply one or more automated tests in order to determine one or more device identifiers of the user device, to generate a risk score for the access request based at least in part on the received user credentials and the one or more determined device identifiers, and to grant or deny the access request based at least in part on the risk score.