Dynamic Authentication Timing and Challenge Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for wireless telecommunications terminals lack dynamic adaptation to user location, time, and environmental context, leading to inconsistent security levels, particularly in situations where terminals are more likely to be left behind or stolen.
Innovation Solution
The system varies the timing and type of authentication challenges based on the user's geo-location, current time, presence of nearby users, and their identities, using geo-location-enabled terminals, a user registration store, geo-location store, and user schedules to determine the appropriate authentication strategy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a fixed re-authentication time period is used, then the authentication process is simple and consistent, but security is insufficient in high-risk situations such as public places or when terminals are left behind
Solution Approach 1:
The patent applies dynamics by making the re-authentication time period variable rather than fixed. The system dynamically adjusts the time period based on risk context factors including geo-location, presence of nearby users, user schedules, and historical patterns. High-risk situations trigger shorter re-authentication intervals while low-risk situations allow longer intervals, thereby adapting security levels to actual conditions without unnecessary complexity in safe environments
Solution Approach 2:
The patent changes the parameter of re-authentication time period based on multiple contextual factors. The system monitors geo-location, time of day, presence of other users, and compares against user schedules and historical data to determine appropriate time intervals. This parameter change approach allows the system to maintain simple authentication processes in low-risk contexts while implementing tighter security in high-risk situations without uniformly increasing complexity across all scenarios
2Reliability
If the same authentication challenge type is used always, then the system is simple to implement, but it cannot adapt to different risk contexts and user behaviors
Solution Approach 1:
The patent applies dynamics by making the authentication challenge type variable rather than static. The system dynamically selects challenge types based on risk context, user behavior patterns, and environmental factors. The system can switch between different challenge types including username/password, one-time passwords, biometrics, and knowledge-based questions, adapting the authentication method to the current situation rather than using a fixed approach
Solution Approach 2:
The patent changes the parameter of authentication challenge type based on contextual factors including geo-location, time of day, presence of nearby users, and user schedules. The system compares current conditions against historical patterns and user profiles to determine which challenge type is most appropriate, enabling adaptation to different risk contexts while maintaining system manageability through structured challenge type selection
3Reliability
If re-authentication time is shortened for tighter security, then security is improved, but user convenience and productivity are reduced due to more frequent authentication requirements
Solution Approach 1:
The patent changes the parameter of re-authentication time period based on risk assessment to balance security and convenience. The system extends the time period in low-risk situations (such as when users are at home or in trusted environments) to minimize authentication frequency and maintain user convenience. Conversely, the system shortens the time period in high-risk situations (such as when terminals are in public places or show signs of being left behind) to maintain tighter security. This differential parameter adjustment allows the system to optimize both security and productivity without uniformly impacting all user scenarios
Data Source
AI summary
An apparatus and methods are disclosed for authenticating users of wireless telecommunications terminals. In particular, the present invention enables the timing and type of authentication challenges to vary based on one or more of: the user's current geo-location, the current day and time, the presence or absence of other nearby users, and the identity of any nearby users. In accordance with the illustrative embodiment, the re-authentication time period (i.e., the length of time between authenticating and re-authenticating a user) and the authentication challenge type (e.g., username/password, fingerprint recognition, etc.) can be determined based on these factors. The present invention is advantageous in that it enables the shortening of the re-authentication time and the selection of a more secure type of authentication challenge when it is more likely that a user's wireless telecommunications terminal might be accidentally left behind or stolen.


