Dynamic Authentication Policy Adjustment for Risk-Based Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Business organizations face inefficiencies in authentication policies as the same policies are applied to all members, failing to account for varying security risks and data confidentiality levels among employees, such as a CFO needing stronger password requirements compared to a helpdesk employee.
Innovation Solution
A system dynamically adjusts authentication policies based on user-specific attributes like organizational role, network activity, historical behavior, and social media presence, calculating a risk assessment score to tailor authentication requirements for each user.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the same authentication policy is applied to all members of the organization, then the implementation is simple and uniform, but the security effectiveness is reduced because it does not account for varying security risks and data confidentiality levels among employees
Solution Approach 1:
The patent applies local quality by customizing authentication policies for different users based on their specific risk profiles, organizational roles, and data access levels. Instead of a uniform policy, each user receives tailored authentication requirements that match their individual security risk characteristics, thereby improving security effectiveness without applying excessive complexity universally.
Solution Approach 2:
The patent implements dynamics by making authentication policies adjustable and adaptive rather than static. The system dynamically modifies authentication requirements based on changing user attributes, risk assessments, and organizational factors, allowing the policy to evolve with the user's security profile while maintaining manageable complexity through automated adjustment.
2Reliability
If stronger authentication requirements are applied to all users, then security is improved, but user convenience and ease of operation deteriorates
Solution Approach 1:
The patent applies local quality by differentiating authentication strength based on individual user risk profiles. Users with lower risk profiles experience simpler authentication processes, while those with higher risk profiles undergo stricter authentication. This ensures strong security protection where needed without imposing unnecessary burdens on low-risk users, maintaining ease of operation for the broader user base.
3Reliability
If authentication policies are customized for each user based on multiple attributes, then security effectiveness is improved, but the complexity of policy management and attribute assessment increases
Solution Approach 1:
The patent applies universality by creating a multi-functional authentication policy management system that handles multiple user attributes, risk assessments, and policy adjustments through a single integrated framework. This universal system manages diverse authentication requirements across the organization using common processes and criteria, reducing the overall complexity of policy management while enabling tailored security protection for each user.
Solution Approach 2:
The patent implements self-service by enabling the system to automatically assess user attributes, calculate risk profiles, and adjust authentication policies without requiring manual intervention for each customization. This automated self-service approach handles the complexity of individualized policy management internally, allowing tailored security protection to be generated and maintained with minimal administrative overhead.
Data Source
AI summary
A computer-implemented method for managing an authentication policy for a user on a network of an organization includes determining at least one social media attribute of the user, and a social media risk value is assigned based on the at least one social media attribute of the user. The method further includes determining at least one network activity risk attribute of the user, and a network activity risk score is assigned based on the at least one network activity risk attribute. A current risk assessment score of the user is calculated based on the social media risk value and the network activity risk value. An authentication policy for the user is determined based on the current risk assessment score.


