Dynamic Authentication Method Selection Based on Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for user devices accessing services do not effectively adapt to changing security risks, potentially leading to vulnerabilities and compromised security.

Innovation Solution

A system that analyzes device security behavior and network intelligence data using machine learning to dynamically determine and recommend a more secure authentication method based on identified risk levels, allowing for real-time adjustments to ensure secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If third-party user credentials are used for authentication to provide user convenience and lower barrier for acquisition, then ease of operation is improved, but security risk increases

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts authentication methods based on real-time risk assessment. Instead of using a static authentication approach, the system evaluates device security behavior, network intelligence data, and threat intelligence to determine the appropriate authentication method for each access attempt, thereby adapting security measures to current conditions while maintaining user convenience.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters dynamically by switching between different authentication methods (e.g., from third-party credentials to more secure methods) based on identified risk levels. This parameter change allows the system to respond to varying security conditions while preserving ease of operation when risks are low.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic risk assessment and authentication method determination are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary authentication management component that sits between the user device and service providers. This intermediary handles the complex tasks of risk assessment, machine learning analysis, and authentication method determination, thereby isolating the complexity from both the user device and service providers while improving overall security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback loops where authentication outcomes, security events, and risk assessments are continuously monitored and fed back into the machine learning models. This feedback mechanism enables the system to automatically learn and improve its security decisions over time, reducing the need for manual configuration and managing complexity through self-optimization.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If real-time security monitoring and machine learning analysis are performed, then security risk mitigation is improved, but use of energy increases

Engineering Contradiction:
Improvesecurity riskVSAvoidcomputational energy
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The system applies partial monitoring and analysis by focusing computational resources on specific high-risk scenarios, device behaviors, or authentication attempts rather than continuously analyzing all traffic. Machine learning models evaluate only the necessary parameters for risk assessment, performing excessive analysis only when initial indicators suggest potential threats, thereby reducing overall energy consumption while maintaining effective security monitoring.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11882158B2Methods, systems, and devices to dynamically determine an authentication method for a user device to access services based on security risk
Publication Date: 2024.01.23 AT&T INTELLECTUAL PROPERTY I L P
  • US11882158B2 patent drawing
  • US11882158B2 patent drawing
  • US11882158B2 patent drawing

AI summary

A device, method or executable instructions that include receiving, over a network, an authentication request from a user device for performing a function utilizing a first authentication method, obtaining network intelligence data for a mobile network over the network, and identifying a risk for each of multiple authentication methods in response to analyzing device security behavior and the network intelligence data. Further embodiments include identifying a first risk for the first authentication method and identifying a second risk for the function, determining the first risk is higher than the second risk, and identifying a second authentication method that is associated with the second risk. Additional embodiments include notifying the user device of the second risk for the function, and providing a recommendation to the user device to utilize the second authentication method to perform the function. Other embodiments are disclosed.