Dynamic Authentication for Sensitive Application Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current application security systems fail to adequately protect sensitive transactions within applications, as they rely on a single authentication method that does not differentiate between transaction types, leaving them vulnerable to abuse and breaches, especially since re-engineering applications to implement additional authentication measures has low adoption.
Innovation Solution
An application security system that monitors transactions and applies security policies dynamically, identifying sensitive transactions through classification and interrupting them to prompt for additional authentication factors, such as multifactor authentication, without requiring changes to the application code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If developers re-engineer applications to add additional authentication measures, then security protection for sensitive transactions is improved, but implementation complexity and development cost increase
Solution Approach 1:
The patent introduces a transaction monitoring system as an intermediary layer between the application and the authentication mechanism. This system monitors transactions, identifies sensitive ones, and triggers supplemental authentication without requiring changes to the application code itself. The intermediary handles the complexity of security monitoring and authentication coordination, allowing existing applications to benefit from enhanced security without re-engineering.
2Ease of operation
If a single authentication method is used for all transactions, then ease of operation is maintained, but security protection for sensitive transactions deteriorates
Solution Approach 1:
The patent applies different authentication requirements to different transactions based on their sensitivity. Instead of uniform authentication for all transactions, the system identifies sensitive transactions (such as those involving financial data or critical operations) and applies supplemental authentication only to those specific transactions. This maintains simple authentication for routine operations while providing enhanced security where needed.
Solution Approach 2:
The authentication mechanism is made dynamic rather than static. The system continuously monitors transaction characteristics and adjusts authentication requirements in real-time based on the transaction type, sensitivity level, and risk assessment. This dynamic approach allows the system to adapt authentication complexity to actual security needs, maintaining ease of operation for low-risk transactions while providing robust protection for high-risk transactions.
3Reliability
If supplemental authentication is required for all transactions, then transaction security is improved, but user workflow efficiency deteriorates
Solution Approach 1:
The system applies supplemental authentication selectively only to transactions that meet specific security criteria, such as those involving sensitive data, high-value operations, or unusual access patterns. Routine transactions continue to proceed with the standard authentication mechanism, avoiding unnecessary security steps for low-risk operations and thus maintaining workflow efficiency.
Solution Approach 2:
The transaction monitoring system continuously analyzes transaction characteristics and provides feedback to the authentication mechanism. Based on this feedback, the system dynamically determines whether supplemental authentication is required, allowing users to proceed through workflows efficiently when transactions are deemed low-risk while triggering additional authentication steps only when security concerns are identified.
Data Source
AI summary
The present technology includes applying a security policy by an application security system to a transaction within an application that is monitored by the application security system. The present technology includes monitoring transaction occurring between a client device an application over a network. The present technology also includes identifying a first transaction from the transactions as a sensitive transaction. The sensitive transaction is associated with an authentication policy requiring an authentication. The present technology also includes interrupting the application. The present technology also includes prompting the client device for the authentication.


