Dynamic Authentication Service for Continuous Trust Assertion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user authentication methods are inadequate as they rely on static forms that do not consider location, device, and access frequency, lack continuous trust assertion, and are insufficient for cloud-based and mobile access, leading to potential security vulnerabilities and performance issues.

Innovation Solution

An Internet-based authentication service using a cloud service with SAML or web services API that dynamically assesses user trust levels through combinations of authentication methods, periodically re-authenticates users to refresh risk/trust categorization, and provides granular access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static authentication methods (passwords, OTPs) are used, then authentication simplicity is maintained, but security is insufficient as they do not consider location, device, and access frequency

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication that adapts based on multiple factors including user location, device characteristics, access frequency, and time of day. The authentication requirements and trust levels are not static but change dynamically based on the assessed risk profile of each authentication attempt, thereby enhancing security without requiring overly complex static authentication mechanisms.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters dynamically by adjusting the number of authentication factors required, the types of authentication methods used, and the trust level assigned based on real-time analysis of multiple parameters such as geo-location, device fingerprint, access patterns, and behavioral biometrics. This allows the system to optimize security while maintaining ease of use when risk is low.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If authentication is performed only at session beginning, then initial access control is provided, but continuous trust assertion is lacking making sessions vulnerable to hijacking

Engineering Contradiction:
Improvesession securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic re-authentication during user sessions where the authentication service periodically reassesses the user's trust level by analyzing current authentication factors such as location, device state, and access patterns. This periodic verification ensures continuous session security without requiring constant user interaction, as the system can quickly reassess risk based on existing and updated parameters.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system continuously monitors authentication factors during the session and provides feedback by adjusting trust levels in real-time. If anomalies are detected such as unexpected location changes, device modifications, or unusual access patterns, the system immediately reassesses authentication requirements and can trigger additional verification steps, providing continuous security assurance throughout the session.

Inventive Principle:
Principle #23Feedback

3Productivity

If authentication servers are hosted within private enterprise network, then enterprise control is maintained, but performance and accessibility for cloud applications are insufficient

Engineering Contradiction:
Improveauthentication performanceVSAvoidcloud accessibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent describes an authentication service architecture that can operate in multiple deployment models including cloud-based, on-premises, or hybrid configurations. The service provides universal authentication capabilities that can serve both enterprise internal applications and cloud-based applications, adapting to different deployment requirements while maintaining consistent security policies and trust assessment mechanisms across diverse environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8925053B1Internet-accessible service for dynamic authentication and continuous assertion of trust level in identities
Publication Date: 2014.12.30 EMC IP HLDG CO LLC
  • US8925053B1 patent drawing
  • US8925053B1 patent drawing
  • US8925053B1 patent drawing

AI summary

An authentication technique involves receiving an authentication request which includes a set of authentication factors and performing, in response to the authentication request, an authentication operation based on a set of authentication factors. An authentication result of the authentication operation identifies a particular trust category among a set of trust categories. Each trust category of the set defines a unique set of user permissions. The technique further involves providing the authentication result for use by a web application. The particular trust category identified by the authentication result defines a particular set of user permissions to be imposed by the web application. For example, the trust categories may take the form of trust levels such as Low, Med, and High which control access to certain resources. Furthermore, the technique involves providing periodic and/or random authentication requests to the authentication server to detect hijacking of the user session after successful initial authentication.