Dynamic Authentication Levels for User Convenience
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods are static and require users to repeatedly authenticate across different electronic resources, often necessitating different information, which can be inconvenient and may not adapt to the user's context or previous activity, potentially leading to unnecessary security obstacles or vulnerabilities.
Innovation Solution
Implementing an intelligent authentication system that dynamically adjusts authentication levels based on the user's historical activity and transaction context, using a combination of transaction logic, activity logic, and authentication logic to assess the likelihood of the user's identity and apply appropriate authentication requirements, such as light, baseline, or heightened authentication, depending on the situation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static authentication techniques are used for each electronic resource, then security is maintained, but user convenience deteriorates due to repeated authentication requirements
Solution Approach 1:
The patent applies dynamics by transitioning from static authentication techniques to dynamic authentication levels. The system continuously monitors user activity patterns, device information, and transaction context to dynamically adjust authentication requirements in real-time. This allows the system to adapt authentication strength based on current risk assessment rather than using fixed authentication rules for all transactions.
Solution Approach 2:
The patent implements parameter changes by modifying authentication parameters based on monitored factors such as time of day, location, device type, and transaction amount. The system changes authentication parameters (e.g., requiring biometric verification, password entry, or leaving transaction open) based on the assessed risk level, thereby optimizing both security and user convenience through parameter adaptation.
2Reliability
If authentication techniques are standardized for each resource, then security is ensured, but adaptability deteriorates as users cannot use the same credentials across different resources
Solution Approach 1:
The patent applies universality by creating a unified authentication framework that works across multiple electronic resources and channels. Instead of requiring resource-specific authentication techniques, the system uses a single activity monitoring and risk assessment mechanism that adapts to different transaction types, devices, and channels, allowing consistent user experience while maintaining security.
Solution Approach 2:
The patent implements local quality by tailoring authentication requirements to specific transaction contexts and risk levels rather than applying uniform authentication across all resources. The system assesses local risk factors (such as transaction amount, location, device reputation) and adjusts authentication strength accordingly, providing appropriate security measures for each specific situation while maintaining overall system flexibility.
3Reliability
If repeated authentication is required for each transaction, then security is maintained, but time consumption increases
Solution Approach 1:
The patent applies preliminary action by continuously monitoring and recording user activity patterns, device information, and transaction history in advance. This accumulated data is then used to pre-assess risk levels before transactions occur, enabling the system to make informed decisions about authentication requirements without requiring real-time analysis during each transaction, thereby reducing authentication time.
Solution Approach 2:
The patent implements feedback by continuously monitoring user behavior patterns, device characteristics, and transaction outcomes to refine risk assessment models. The system uses feedback from actual transaction data to improve future authentication decisions, allowing for more accurate risk prediction and reducing unnecessary authentication steps while maintaining security through adaptive learning.
Data Source
AI summary
Intelligent authentication is disclosed. Data associated with a request for resource access by a user is compared to values of factors related to previous resource access by the user. A score is computed based on a result of the compare. Here, the score represents a degree of likelihood the user is the user associated with the previous resource access. An authentication level can then be determined based on the score, and authentication of the user triggered at the authentication level. In one instance, the authentication can be triggered to re-authenticate a user after a user session times out.


