Automated Device Identifier Determination for Risk-Based Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise computer networks face challenges in providing adequate security due to their growing size and complexity, which strains existing network security systems, and conventional credential-based authentication techniques often fail to detect and remediate advanced persistent threats (APTs) effectively.
Innovation Solution
Implementing automated determination of device identifiers for risk-based access control, which supplements conventional authentication methods by using additional device identifiers to generate risk scores for access requests, thereby enhancing security against APTs and other attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional credential-based authentication techniques are used, then the authentication process is simple and fast, but the system fails to detect advanced persistent threats (APTs) and sophisticated attacks
Solution Approach 1:
The system performs preliminary actions by collecting multiple device identifiers (hardware ID, OS type, browser type, screen resolution, etc.) before the authentication decision is made. These identifiers are gathered in advance and stored for comparison, enabling the system to detect APTs and sophisticated attacks without adding complexity to the user authentication process.
Solution Approach 2:
The patent introduces device identifiers as an intermediary element between the user credentials and the authentication decision. These identifiers serve as mediators that provide additional information about the device characteristics without requiring users to directly interact with or understand the complex authentication mechanisms.
2Reliability
If network security systems process security alerts and deploy attack remediation measures in large enterprise networks, then security coverage is improved, but the limited resources of the network security system become strained
Solution Approach 1:
The system performs preliminary risk assessment by comparing device identifiers against stored profiles before security incidents occur. This preliminary action enables the system to pre-identify suspicious devices and prioritize security resources, avoiding the need to process all security alerts with equal resource allocation.
Solution Approach 2:
The patent changes the parameter of risk assessment from binary (secure/not secure) to a continuous scale by incorporating multiple device identifier characteristics. This enables more nuanced risk scoring that helps security systems prioritize responses based on actual risk levels, improving resource efficiency.
3Measurement precision
If conventional authentication systems are used in growing enterprise networks with diverse devices, then system simplicity is maintained, but the ability to detect access anomalies at an early stage is insufficient
Solution Approach 1:
The patent segments the authentication verification process into multiple independent checks: collecting device identifiers, comparing each identifier against stored profiles, evaluating mismatches, and making authentication decisions. This segmentation enables precise anomaly detection at each stage without requiring a complete redesign of the authentication system.
Solution Approach 2:
The system changes the parameter of device identification from relying solely on user-provided credentials to incorporating multiple objective device characteristics (hardware ID, OS type, browser type, screen resolution). This parameter expansion enables more precise anomaly detection while maintaining automated processing.
Data Source
AI summary
A processing device in an illustrative embodiment includes a processor coupled to a memory and is configured to receive user credentials from a user device in conjunction with an access request, to apply one or more automated tests in order to determine one or more device identifiers of the user device, to generate a risk score for the access request based at least in part on the received user credentials and the one or more determined device identifiers, and to grant or deny the access request based at least in part on the risk score.


