Dynamic Security Challenge Authentication via User Interaction Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security challenges in cloud computing are static, making them vulnerable to guessing and breaches, leading to unauthorized access and data leakage, as they are predefined and stored on computing systems.

Innovation Solution

Implementing dynamic security challenge authentication that generates challenges based on user interactions with applications, files, and devices, changing over time and retrieved from services involved in these interactions, to enhance security and usability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static security challenges are used, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms static security challenges into dynamic ones by generating challenges based on real-time user interaction data from multiple applications, files, and devices. The challenges change frequently based on current user behavior patterns rather than remaining fixed, thereby improving security reliability while maintaining ease of operation through automated generation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of security challenges from fixed predefined values to dynamically generated values based on user interaction data. By varying the challenge content based on timestamp, application usage patterns, file access history, and device information, the system improves security without requiring users to memorize complex static challenges.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic security challenges are generated, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication system that aggregates user interaction data from multiple applications, files, and devices into a single challenge generation mechanism. This multi-functional approach allows the same system to secure various cloud resources without requiring separate authentication systems for each application, thereby limiting the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary authentication service that collects data from various user interactions and generates challenges. This intermediary layer simplifies the architecture by centralizing the complex challenge generation logic, preventing the complexity from propagating through the entire system while maintaining high security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If security challenges are stored, then ease of operation is improved, but vulnerability to breaches increases

Engineering Contradiction:
Improveauthentication speedVSAvoidbreach vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements disposable security challenges that are generated fresh for each authentication attempt and discarded immediately after use. Instead of storing reusable challenges, the system creates single-use challenges based on current user interaction data, eliminating the security vulnerability of stored challenges while maintaining fast authentication through automated generation.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system takes preliminary anti-action by not storing challenges at all, thereby preventing the potential breach vulnerability before it can occur. By generating challenges on-demand from user interaction data and immediately discarding them, the system eliminates the attack surface that stored challenges would create, while maintaining authentication speed through efficient real-time generation.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS20230098536A1Dynamic security challenge authentication
Publication Date: 2023.03.30 CITRIX SYSTEMS INC
  • US20230098536A1 patent drawing
  • US20230098536A1 patent drawing
  • US20230098536A1 patent drawing

AI summary

A method for dynamic security challenge authentication may include generating, based on data about one or more previous interactions of the user with a plurality of applications, files, and devices, one or more security challenges. Examples of interactions include launching an application, editing a file, and logging onto a device. The data may be retrieved from services or components involved with the interactions. The identity of the user may be authenticated based on the responses to the security challenges. Related systems and computer program products are also provided.