Dynamic Trust Model for User Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems struggle to dynamically adapt to changes in user behavior and security risks, especially when multiple authentication factors are used, as they often treat these factors equivalently and rely on static thresholds that do not account for real-time changes in user activity or environment.
Innovation Solution
A computer system that dynamically determines a trust level for users based on elapsed time since authentication, transaction risk levels, and user-specific characteristics, requesting additional authentication information when the risk level exceeds the trust level, and adjusting the trust level based on factors like user location and security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple authentication factors are used, then security is improved, but the system treats these factors equivalently and cannot dynamically adapt to changes in user behavior or security risks
Solution Approach 1:
The patent implements a dynamic trust level system where the authentication threshold is not fixed but adjusts continuously based on elapsed time since authentication, user behavior patterns, and security risk assessments. The trust level decreases over time and can be modified by various factors including user location changes and security threats, allowing the system to adapt dynamically rather than treating all authentication factors equivalently throughout the session
Solution Approach 2:
The system changes the authentication parameter (trust level) based on multiple variables including time elapsed, authentication information type, user location, and security threats. This allows the authentication requirements to be adjusted dynamically - for example, requiring additional authentication when trust level drops below transaction risk level, rather than using a static threshold for all scenarios
2Ease of operation
If authentication remains valid until timeout or session termination, then user convenience is improved, but the system cannot respond to dynamically changing security risks
Solution Approach 1:
The trust level is continuously adjusted during the session based on elapsed time, user behavior, and security conditions. Rather than maintaining a static authenticated state until timeout, the system dynamically modifies the trust level, requiring additional authentication when the trust level drops below the transaction risk level, thus responding to changing security risks while the session remains active
Solution Approach 2:
The system continuously monitors user behavior, location changes, and security threats, providing feedback that adjusts the trust level in real-time. This feedback mechanism allows the system to respond dynamically to changing conditions during the session, requesting additional authentication when risk increases, rather than passively maintaining authentication until timeout
3Reliability
If additional authentication is requested frequently, then security is improved, but user experience deteriorates due to repeated authentication requirements
Solution Approach 1:
The system adjusts the authentication threshold (trust level) dynamically based on the specific context including elapsed time, type of authentication information provided, user location, and security threats. This allows the system to request additional authentication only when necessary - for example, when trust level drops below transaction risk level or when security threats are detected - rather than requiring frequent authentication unconditionally, thus balancing security with user convenience
Data Source
AI summary
A system that that dynamically authenticates one or more users is described. During operation, the computer system determines a trust level for a user, where the trust level is a function of elapsed time since the user previously provided authentication information. Next, the computer system calculates a transaction risk level based on a type of user transaction performed by the user. Then, the computer system requests additional authentication information from the user based on the trust level and the transaction risk level.


