Dynamic Reauthentication Interval Based on Endpoint Location
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems face challenges in preventing unauthorized access to sensitive resources due to inconsistent reauthentication intervals and weak multi-factor authentication (MFA) factors, which can lead to data leakage, and also cause user frustration with frequent reauthentication requests.
Innovation Solution
The security system adjusts the reauthentication interval and authentication factors based on the physical locations of endpoint devices connected to the primary device, shortening the interval and increasing authentication stringency if an endpoint device is identified as being in a suspicious or anomalous location, and extending the interval for authorized devices in trusted locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If frequent reauthentication is implemented to enhance security, then security against unauthorized access is improved, but user convenience and system productivity deteriorate due to repeated authentication interruptions
Solution Approach 1:
The reauthentication interval is made dynamic rather than fixed. The system adjusts the interval based on the trust level of connected endpoint devices, extending the interval when devices are trusted and shortening it when suspicious activity is detected. This resolves the contradiction by making security enforcement adaptive to actual risk conditions.
Solution Approach 2:
Different reauthentication policies are applied to different endpoint devices based on their location and trust level. Trusted devices receive extended intervals while suspicious devices trigger immediate reauthentication. This local differentiation allows the system to maintain high security for at-risk connections while providing convenience for trusted users.
2Reliability
If complex multi-factor authentication factors are used to strengthen security, then authentication strength is improved, but ease of operation deteriorates due to increased input difficulty
Solution Approach 1:
The system applies complex multi-factor authentication only partially - specifically when suspicious endpoint devices are detected. For trusted devices, the system uses simpler authentication or extends intervals without requiring additional factors. This selective application of strong authentication resolves the contradiction by using complex factors only when necessary for security.
3Reliability
If fixed short reauthentication intervals are used to prevent data leakage, then security against unauthorized access is improved, but loss of time increases due to frequent authentication interruptions
Solution Approach 1:
The reauthentication interval transitions from a fixed short duration to a dynamic duration based on endpoint trust assessment. The system monitors connected devices and adjusts intervals in real-time, extending them for trusted devices to minimize authentication interruptions and time loss, while maintaining short intervals for suspicious devices to prevent data leakage.
Data Source
AI summary
This disclosure describes techniques for setting and/or adjusting a security policy associated with a device based on the physical locations of endpoint devices exchanging data with the device. An example method includes performing, at a first time, a first authentication of a first device connecting to a service; determining addresses of second devices exchanging data with the first device; determining physical locations of the second devices based on the addresses; and defining a reauthentication interval based on the physical locations of the second devices. At a second time that is after the first time by the reauthentication interval, the example method further includes disconnecting the first device from the service; and based on disconnecting the first device from the service, triggering a second authentication of the first device.


