Dynamic Authentication Service for Continuous Trust Assertion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user authentication methods are inadequate as they rely on static forms that do not consider location, device, and access frequency, lack continuous trust assertion, and are insufficient for cloud-based and mobile access, leading to potential security vulnerabilities and performance issues.
Innovation Solution
An Internet-based authentication service using a cloud service with SAML or web services API that dynamically assesses user trust levels through combinations of authentication methods, periodically re-authenticates users to refresh risk/trust categorization, and provides granular access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static authentication methods (passwords, OTPs) are used, then authentication simplicity is maintained, but security is insufficient as they do not consider location, device, and access frequency
Solution Approach 1:
The patent implements dynamic authentication that adapts based on multiple factors including user location, device characteristics, access frequency, and time of day. The authentication requirements and trust levels are not static but change dynamically based on the assessed risk profile of each authentication attempt, thereby enhancing security without requiring overly complex static authentication mechanisms.
Solution Approach 2:
The system changes authentication parameters dynamically by adjusting the number of authentication factors required, the types of authentication methods used, and the trust level assigned based on real-time analysis of multiple parameters such as geo-location, device fingerprint, access patterns, and behavioral biometrics. This allows the system to optimize security while maintaining ease of use when risk is low.
2Reliability
If authentication is performed only at session beginning, then initial access control is provided, but continuous trust assertion is lacking making sessions vulnerable to hijacking
Solution Approach 1:
The patent implements periodic re-authentication during user sessions where the authentication service periodically reassesses the user's trust level by analyzing current authentication factors such as location, device state, and access patterns. This periodic verification ensures continuous session security without requiring constant user interaction, as the system can quickly reassess risk based on existing and updated parameters.
Solution Approach 2:
The system continuously monitors authentication factors during the session and provides feedback by adjusting trust levels in real-time. If anomalies are detected such as unexpected location changes, device modifications, or unusual access patterns, the system immediately reassesses authentication requirements and can trigger additional verification steps, providing continuous security assurance throughout the session.
3Productivity
If authentication servers are hosted within private enterprise network, then enterprise control is maintained, but performance and accessibility for cloud applications are insufficient
Solution Approach 1:
The patent describes an authentication service architecture that can operate in multiple deployment models including cloud-based, on-premises, or hybrid configurations. The service provides universal authentication capabilities that can serve both enterprise internal applications and cloud-based applications, adapting to different deployment requirements while maintaining consistent security policies and trust assessment mechanisms across diverse environments.
Data Source
AI summary
An authentication technique involves receiving an authentication request which includes a set of authentication factors and performing, in response to the authentication request, an authentication operation based on a set of authentication factors. An authentication result of the authentication operation identifies a particular trust category among a set of trust categories. Each trust category of the set defines a unique set of user permissions. The technique further involves providing the authentication result for use by a web application. The particular trust category identified by the authentication result defines a particular set of user permissions to be imposed by the web application. For example, the trust categories may take the form of trust levels such as Low, Med, and High which control access to certain resources. Furthermore, the technique involves providing periodic and/or random authentication requests to the authentication server to detect hijacking of the user session after successful initial authentication.


