Dynamic Authentication Mechanism Adjusting Complexity by Location
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems lack the ability to dynamically adjust their complexity based on external factors, leading to unnecessary high security measures in situations where additional security is already provided by the proximity of other users or devices, which can hinder productivity and increase authentication errors.
Innovation Solution
A method that collects location data of agents attempting to authenticate to a data processing system, determines if the proximity meets a threshold value, and relaxes the authentication scheme accordingly, allowing for a dynamic adjustment of authentication complexity based on the presence and proximity of other users or devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a complex authentication scheme is used to ensure system security, then security strength is improved, but authentication time and user productivity deteriorate
Solution Approach 1:
The authentication scheme dynamically adjusts its complexity based on the user's location and environmental context. The system transitions from static authentication to dynamic authentication, where the authentication requirements change in real-time based on location data and proximity assessments, resolving the contradiction between security strength and authentication time
Solution Approach 2:
The system changes authentication parameters (such as requiring location verification, proximity checks, or alternative authentication methods) based on the evaluated security context. When the user is in a secure environment with trusted devices nearby, the system modifies authentication parameters to reduce complexity while maintaining overall security
2Reliability
If a complex authentication scheme is used to ensure system security, then security strength is improved, but ease of operation deteriorates
Solution Approach 1:
The authentication mechanism becomes dynamic and adaptive, adjusting its operational complexity based on real-time location assessment. The system automatically determines the appropriate authentication level required, making the operation easier when security conditions permit without manual user intervention
Solution Approach 2:
The system performs self-assessment of the security context by automatically collecting and evaluating location data and proximity information. This self-service capability eliminates the need for users to manually assess security conditions or choose authentication methods, improving ease of operation while maintaining security
3Reliability
If high security measures are always applied, then system security is improved, but productivity deteriorates due to repeated authentication requirements
Solution Approach 1:
The system implements periodic reassessment of security conditions through location-based triggers. Instead of requiring authentication at fixed time intervals or for every action, the system periodically evaluates the security context and adjusts authentication requirements accordingly, improving productivity when security conditions remain favorable
Solution Approach 2:
The authentication requirements dynamically adapt to changing security contexts. When the system detects that the user has moved to a different location or that trusted devices are no longer in proximity, it automatically adjusts the authentication scheme, allowing users to maintain productivity in secure environments while ensuring security when conditions change
Data Source
AI summary
According to one aspect of the present disclosure, a method and technique for dynamic adjustment of authentication mechanism is disclosed. The method includes: collecting location data of one or more agents relative to an agent attempting to authenticate to a data processing system; determining if the location data meets a threshold value; and responsive to the location data meeting the threshold value, relaxing an authentication scheme for the attempting agent to authenticate to the data processing system.


