Dynamic Authentication Protocol Adjustment for Traveling Users

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems impose static and burdensome multi-factor authentication requirements on users when they travel, leading to delayed or restricted access due to the inability to account for predetermined travel plans, often resulting in unauthorized access attempts being misclassified as malicious.

Innovation Solution

A system that reduces user authentication requirements by analyzing transportation and event data from reservation emails to determine the user's location and validate access requests, allowing for temporary trust zones and adjusting authentication protocols accordingly, thereby mitigating the need for heightened authentication during travel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication requirements are imposed on users when they travel, then security is improved, but user access convenience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system dynamically adjusts the authentication protocol based on the user's location and travel status. When a user is detected to be traveling (through transportation data analysis), the system automatically reduces authentication requirements from multi-factor to simplified authentication, whereas stationary users receive standard MFA. This dynamic adaptation resolves the contradiction by making security requirements flexible rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameter (authentication protocol type) based on the user's contextual state. By analyzing transportation reservation data and confirming travel plans, the system transitions the authentication parameter from strict MFA to simplified authentication for traveling users, thereby improving convenience while maintaining security through contextual verification.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If static authentication requirements are used, then system complexity is reduced, but adaptability to different user situations deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidadaptability to travel situations
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary analysis of transportation reservation data to determine user travel status before authentication is required. By proactively identifying users with confirmed travel plans through email analysis and confirmation wrappers, the system prepares the appropriate authentication protocol in advance, avoiding the need for complex real-time decisions during the authentication moment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Users confirm their own travel plans by responding to confirmation wrappers, which automatically provides the system with verified travel status information. This self-service approach allows the system to adapt authentication requirements without requiring manual configuration or complex monitoring of user whereabouts, maintaining low system complexity while achieving high adaptability.

Inventive Principle:
Principle #25Self-service

3Reliability

If multi-factor authentication is required for all access requests, then security is improved, but access speed deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccess speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies authentication requirements partially based on user context. For traveling users with confirmed itineraries, only simplified authentication is required rather than full MFA, representing a partial reduction in authentication action. This selective approach maintains security for high-risk scenarios while improving access speed for legitimate traveling users.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system uses feedback from transportation reservation data analysis to determine appropriate authentication levels. By continuously monitoring and analyzing user travel status through confirmed reservations, the system adjusts authentication requirements in real-time, ensuring security when needed while enabling faster access when travel status is confirmed.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11425141B2Reduced user authentication input requirements
Publication Date: 2022.08.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11425141B2 patent drawing
  • US11425141B2 patent drawing
  • US11425141B2 patent drawing

AI summary

Techniques disclosed herein enable a system to reduce user authentication requirements during a user's travels by analyzing transportation data and/or event data sent to the user via a communication service, e.g. email. The system may analyze the data in order to determine where the user will be at some future time and, ultimately, to then validate access requests against such determinations to mitigate the need for heightened user authentication requirements while the user is traveling. For instance, the system may identify an airline reservation sent to the user and enable the user to confirm that she has corresponding travel plans. Once she confirms her travel plans, the system may refrain from increasing authentication requirements from Single-Factor Authentication (SFA) to Multi-Factor Authentication (MFA) input requirements for access requests that match the confirmed travel plans.