Dynamic Authentication State Machine for Adaptive Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user authentication systems lack flexibility and scalability, as they are limited to predetermined linear specifications of authentication mechanisms, which are not effective against malicious threats and do not adapt dynamically to user behavior or network conditions.

Innovation Solution

The implementation of a configurable finite state machine (FSM) that dynamically determines the authentication flow based on user-specific information, including identity, previous credentials, and behavior, incorporating mechanisms like password, CAPTCHA, biometrics, and hardware tokens, to provide a branching and scalable authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional predetermined linear authentication specifications are used, then the authentication process is simple and straightforward, but the system lacks flexibility and scalability against malicious threats

Engineering Contradiction:
Improveflexibility and scalability of authentication systemVSAvoidcomplexity of authentication process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a dynamic authentication system using finite state machines (FSMs) that can adapt the authentication flow in real-time based on user behavior, device characteristics, and security requirements. The system transitions between different states (e.g., initial authentication, multi-factor verification, security challenges) dynamically, allowing the authentication process to become more or less complex based on the specific context and detected threats, rather than following a fixed linear path.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication system is designed to support multiple authentication mechanisms and methods within a single unified framework. The FSM can configure and switch between different authentication types (password, biometric, hardware token, CAPTCHA) based on the situation, making the system universally applicable to various security requirements and threat levels without requiring separate systems for each authentication method.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dynamic authentication mechanisms are implemented to enhance security, then security and flexibility are improved, but the login process becomes more complex and time-consuming

Engineering Contradiction:
Improvesecurity of authentication systemVSAvoidtime required for login process
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies authentication mechanisms proportionally to the security risk. For low-risk situations, the system uses simpler, faster authentication methods. For high-risk situations or detected malicious behavior, the system dynamically introduces additional authentication steps (such as CAPTCHA, multi-factor authentication, or security challenges). This ensures that the time loss is minimized for legitimate users while maintaining strong security when needed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The authentication system continuously monitors user behavior, device characteristics, and authentication patterns, using this feedback to dynamically adjust the authentication flow. The FSM receives feedback from each authentication attempt and subsequent user actions, automatically determining whether to escalate to more stringent verification or return to a simpler flow, thereby optimizing both security and user experience in real-time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10607263B2Computerized systems and methods for authenticating users on a network device via dynamically allocated authenticating state machines hosted on a computer network
Publication Date: 2020.03.31 YAHOO ASSETS LLC
  • US10607263B2 patent drawing
  • US10607263B2 patent drawing
  • US10607263B2 patent drawing

AI summary

Disclosed are systems and methods for improving interactions with and between computers in an authentication system supported by or configured with personal computing devices, servers and/or platforms. The systems interact to identify and retrieve data across platforms, which data can be used to improve the quality of data used in processing interactions between or among processors in such systems. The disclosed systems and methods provide advanced, computerized security features that dynamically, in real-time, determine parameters that must be entered in order for a user to login to a system or platform, as well as the quantity and order such parameters must be entered. The disclosed systems and methods involve computerized mechanisms for authenticating a user or device for which access to a web-based resource is desired. Requested credentials in accordance with the dynamically determined manner in which such credentials are automatically determined and requested must be appropriately entered.