Dynamic Authentication for Cloud Asset Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based computing systems face security vulnerabilities due to the large number of users accessing multiple devices and computing assets, which increases the risk of data breaches, especially as the number of users and applications grows.

Innovation Solution

An asset access learning system employing machine learning algorithms, such as neural networks, to analyze user access data, generate risk analytics, and dynamically control authentication processes and access privileges, enhancing security by providing real-time risk assessments and recommendations to users and system administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud-based computing systems provide broad access to multiple devices and computing assets for increased productivity, then accessibility and productivity improve, but security vulnerabilities and data breach risks increase

Engineering Contradiction:
Improveaccessibility to computing assetsVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic authentication that adjusts security requirements in real-time based on user behavior patterns, device characteristics, and access context. The system transitions from static access control to dynamic risk-based authentication, where security measures adapt to current conditions rather than applying uniform rules to all access attempts.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates continuous monitoring of user behavior and access patterns, using this feedback to adjust authentication requirements. Machine learning algorithms analyze historical and real-time data to identify anomalies and modify security responses, creating a closed-loop system that learns and adapts to emerging threats while maintaining productivity.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If the number of users and applications grows to meet organizational needs, then service coverage and utility improve, but security threats and vulnerability exposure increase

Engineering Contradiction:
Improveservice coverageVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments the authentication process into multiple factors and layers, including device authentication, user identity verification, behavioral analysis, and contextual risk assessment. This segmented approach allows the system to apply appropriate security measures to different aspects of access control independently, managing complexity while enhancing security for diverse user and application combinations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes security parameters dynamically based on the specific combination of user, device, application, and context. Rather than treating all access requests uniformly, the system adjusts authentication strength, required factors, and monitoring levels according to risk parameters derived from system growth and usage patterns.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11301551B2Computing asset access control
Publication Date: 2022.04.12 EBAY INC
  • US11301551B2 patent drawing
  • US11301551B2 patent drawing
  • US11301551B2 patent drawing

AI summary

Access to computing assets is controlled by dynamically selecting an authentication process for an access attempt to a computing asset. In an example embodiment, when an indication of an access attempt for a computing asset is received, a security level associated with the computing asset is determined. Based on the security level associated with the computing asset, an authentication process is selected from a plurality of authentication processes, and the selected authentication process is executed in relation to the access attempt for the computing asset. In further embodiments, the authentication process is further selected based on a comparison of an access characteristic associated with the access attempt for the computing asset and an access characteristic for a user associated with the access attempt.