Dynamic Authentication for Sensitive Application Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current application security systems fail to adequately protect sensitive transactions within applications, as they rely on a single authentication method that does not differentiate between transaction types, leaving them vulnerable to abuse and breaches, especially since re-engineering applications to implement additional authentication measures has low adoption.

Innovation Solution

An application security system that monitors transactions and applies security policies dynamically, identifying sensitive transactions through classification and interrupting them to prompt for additional authentication factors, such as multifactor authentication, without requiring changes to the application code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If developers re-engineer applications to add additional authentication measures, then security protection for sensitive transactions is improved, but implementation complexity and development cost increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a transaction monitoring system as an intermediary layer between the application and the authentication mechanism. This system monitors transactions, identifies sensitive ones, and triggers supplemental authentication without requiring changes to the application code itself. The intermediary handles the complexity of security monitoring and authentication coordination, allowing existing applications to benefit from enhanced security without re-engineering.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a single authentication method is used for all transactions, then ease of operation is maintained, but security protection for sensitive transactions deteriorates

Engineering Contradiction:
Improveauthentication simplicityVSAvoidtransaction security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies different authentication requirements to different transactions based on their sensitivity. Instead of uniform authentication for all transactions, the system identifies sensitive transactions (such as those involving financial data or critical operations) and applies supplemental authentication only to those specific transactions. This maintains simple authentication for routine operations while providing enhanced security where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The authentication mechanism is made dynamic rather than static. The system continuously monitors transaction characteristics and adjusts authentication requirements in real-time based on the transaction type, sensitivity level, and risk assessment. This dynamic approach allows the system to adapt authentication complexity to actual security needs, maintaining ease of operation for low-risk transactions while providing robust protection for high-risk transactions.

Inventive Principle:
Principle #15Dynamics

3Reliability

If supplemental authentication is required for all transactions, then transaction security is improved, but user workflow efficiency deteriorates

Engineering Contradiction:
Improvetransaction securityVSAvoidworkflow efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies supplemental authentication selectively only to transactions that meet specific security criteria, such as those involving sensitive data, high-value operations, or unusual access patterns. Routine transactions continue to proceed with the standard authentication mechanism, avoiding unnecessary security steps for low-risk operations and thus maintaining workflow efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The transaction monitoring system continuously analyzes transaction characteristics and provides feedback to the authentication mechanism. Based on this feedback, the system dynamically determines whether supplemental authentication is required, allowing users to proceed through workflows efficiently when transactions are deemed low-risk while triggering additional authentication steps only when security concerns are identified.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240364748A1Frictionless supplementary multi-factor authentication for sensitive transactions within an application session
Publication Date: 2024.10.31 CISCO TECHNOLOGY INC
  • US20240364748A1 patent drawing
  • US20240364748A1 patent drawing
  • US20240364748A1 patent drawing

AI summary

The present technology includes applying a security policy by an application security system to a transaction within an application that is monitored by the application security system. The present technology includes monitoring transaction occurring between a client device an application over a network. The present technology also includes identifying a first transaction from the transactions as a sensitive transaction. The sensitive transaction is associated with an authentication policy requiring an authentication. The present technology also includes interrupting the application. The present technology also includes prompting the client device for the authentication.