Dynamic Authentication Protocol Adjusting Complexity via Risk Scores

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication systems lack a comprehensive and holistic approach for evaluating authentication risks and adjusting authentication complexity based on these risks.

Innovation Solution

The system creates and maintains usage profiles that capture unique computing behavior and patterns of individual users, using these profiles to evaluate risks by analyzing geolocation, network characteristics, and historical authentication data to generate a risk score, which determines the complexity of the authentication protocol.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional authentication factors are added to increase security, then authentication reliability improves, but authentication complexity and user convenience deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system dynamically adjusts the number and type of authentication factors based on real-time risk assessment. The system transitions from static authentication to dynamic authentication where the complexity level changes according to the perceived risk of each authentication attempt, resolving the contradiction between security and convenience

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of authentication complexity based on risk score calculations. By modifying the authentication protocol parameters (number of factors, type of factors) according to the assessed risk level, the system optimizes the balance between security reliability and user convenience for each authentication event

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive risk assessment is performed to improve authentication accuracy, then authentication reliability improves, but processing time and system complexity worsen

Engineering Contradiction:
Improveauthentication accuracyVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously collecting and storing network characteristics, device information, and user behavior patterns before authentication events occur. This pre-processing creates a knowledge base that enables faster risk assessment during actual authentication, reducing real-time processing requirements

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where authentication outcomes and user behavior patterns are continuously fed back into the risk assessment model. This enables iterative improvement of risk detection accuracy over time, allowing the system to become more accurate without linearly increasing processing time

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10601800B2Systems and methods for user authentication using pattern-based risk assessment and adjustment
Publication Date: 2020.03.24 FMR CORP
  • US10601800B2 patent drawing
  • US10601800B2 patent drawing
  • US10601800B2 patent drawing

AI summary

A computer-implemented method is provided for authenticating an identity of a user requesting access to a computerized resource via a client computing device. The method includes receiving, by the client computing device, a request to authenticate the identity of the user, determining, by the client computing device, a time period of the request, determining, by the client computing device, an approximate geolocation of the user, and determining, by the client computing device, one or more network characteristics associated with a current network of the client computing device. The method further includes transmitting, by the client computing device to an authentication device, authentication data including the request, the time period of the request, the approximate geolocation of the user and the one or network characteristics.