Dynamic Stepped Multi-Level Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems using instrument devices with integrated circuit chips for near field or radio frequency communication lack the ability to determine user authorization and activity validity, leading to potential unauthorized activities.
Innovation Solution
A dynamic stepped multi-level authentication system that progressively authenticates activity processing data over escalating authentication levels using electronic communications between network devices over separate communication channels, determining spatial congruence and security exposure values to trigger additional authentication levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional instrument devices with integrated circuit chips are used for near field or radio frequency communication, then ease of operation is improved, but security is worsened due to inability to determine user authorization and activity validity
Solution Approach 1:
The authentication system is segmented into multiple independent components: a resource instrument device (e.g., card reader), a user device (e.g., mobile device), and a processing device. These segments communicate through separate communication channels to perform multi-level authentication, dividing the security function into manageable parts that work together to verify both user identity and activity validity.
Solution Approach 2:
The processing device acts as an intermediary between the resource instrument device and the user device. It receives activity processing data from the instrument device, determines spatial congruence, evaluates security exposure values, and coordinates the multi-level authentication process, mediating the interaction to ensure secure authorization.
2Reliability
If multi-level authentication is implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The processing device performs multiple functions within a single system: determining spatial congruence between devices, evaluating security exposure values, triggering appropriate authentication levels, and coordinating communication between different devices. This multi-functionality consolidates complex authentication logic into one device, reducing overall system complexity.
Solution Approach 2:
The authentication system dynamically adjusts the number and type of authentication levels based on the evaluated security exposure value. For low-risk activities, fewer authentication steps are required, while high-risk activities trigger additional authentication levels. This dynamic adaptation simplifies the user experience for routine tasks while maintaining high security for sensitive operations.
3Reliability
If spatial congruence determination is performed, then security is improved, but loss of time is worsened due to additional authentication steps
Solution Approach 1:
The system performs only the necessary level of authentication for each specific activity based on its security risk profile. For low-risk activities, the system performs partial authentication (spatial congruence only), while reserving excessive authentication steps for high-risk activities. This selective approach minimizes time loss for routine operations while maintaining comprehensive security when needed.
Solution Approach 2:
The system changes the parameter of authentication intensity based on the security exposure value. By dynamically adjusting the authentication threshold and required verification steps according to the assessed risk level, the system optimizes the balance between security and processing time, requiring minimal authentication for low-risk parameters and maximal verification for high-risk parameters.
Data Source
AI summary
Embodiments of the invention are directed to systems, methods, and computer program products for dynamic stepped multi-level authentication. The invention is structured for progressively authenticating transmitted activity processing data over escalating authentication levels using electronic communications between network devices over separate communication channels. Specifically, the invention is structured to authenticate the first activity for a first authentication level based on determining a spatial congruence of the user device and the resource instrument device associated with the first activity. Moreover, the invention is structured to trigger a second authentication level requirement above the first authentication level based on at least the first authentication level and resource activity processing data. In addition, the invention is structured to escalate the authentication of the first activity to the second authentication level based on successful validation of the authentication response provided by the user at the user device.


