Dynamic Authentication Rules for Service Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing sophistication of hackers in identity theft and data compromise in electronic commerce poses a significant threat to service providers and consumers, with existing authentication methods being inadequate in preventing unauthorized access and data breaches.

Innovation Solution

A customizable authentication system that allows users to define and enforce authentication rules based on user characteristics, request characteristics, and enforcement point characteristics, enabling flexible and scalable authentication mechanisms that can include mandatory or optional rules, and trigger-specific actions such as blocking or redirecting access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rigid authentication processes are implemented, then security is improved, but user experience and flexibility deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system transitions from rigid, static authentication processes to dynamic, customizable authentication rules. The system allows service providers to define authentication requirements dynamically based on user characteristics, request characteristics, and enforcement point characteristics, enabling the authentication process to adapt to different scenarios while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements local quality by allowing different authentication rules to be applied to different user groups, service types, and enforcement points. Instead of a uniform authentication process, the system enables granular control where specific authentication requirements can be tailored to local conditions, such as requiring multi-factor authentication for sensitive services while allowing simpler authentication for less critical services.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If customizable authentication rules are enabled, then flexibility and adaptability are improved, but system complexity increases

Engineering Contradiction:
ImproveflexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct components: authentication rules stored in a rules database, enforcement points that evaluate rules, and a rules credential mechanism. This segmentation allows the complex customization capability to be distributed across multiple simple components rather than requiring a single complex system, making the overall system more manageable despite the enhanced flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a rules credential as an intermediary mechanism between the customization capabilities and the authentication enforcement. The rules credential contains the authentication rules and is passed between service providers and enforcement points, simplifying the interaction complexity while maintaining the full customization functionality. This intermediary abstracts the complexity away from individual components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If granular control over authentication is provided, then security customization is improved, but implementation complexity increases

Engineering Contradiction:
Improvesecurity customizationVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication rule engine is designed as a universal system that can handle multiple authentication scenarios through a single framework. The same rule evaluation mechanism works for different user groups, service types, and enforcement points, eliminating the need for separate implementation details for each scenario. This multi-functionality reduces implementation complexity while enabling comprehensive security customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8505077B2Acquisition of authentication rules for service provisioning
Publication Date: 2013.08.06 FMR CORP
  • US8505077B2 patent drawing
  • US8505077B2 patent drawing
  • US8505077B2 patent drawing

AI summary

Described are methods, systems, and apparatus, including computer program products for providing authentication for service provisioning. One or more executable authentication rules are provided for determining access by a user to one or more services. At least a first executable authentication rule is selected from the one or more executable authentication rules. The first executable authentication rule is for determining access by the user to at least a first service from the one or more services, wherein selecting the first executable authentication rule is based on: a characteristic of the user, a characteristic of a request, a characteristic of an acquisition point, or any combination thereof. A rules credential is generated. The rules credential includes the first executable authentication rule.