Dynamic Trust Model for User Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems struggle to dynamically adapt to changes in user behavior and security risks, especially when multiple authentication factors are used, as they often treat these factors equivalently and rely on static thresholds that do not account for real-time changes in user activity or environment.

Innovation Solution

A computer system that dynamically determines a trust level for users based on elapsed time since authentication, transaction risk levels, and user-specific characteristics, requesting additional authentication information when the risk level exceeds the trust level, and adjusting the trust level based on factors like user location and security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication factors are used, then security is improved, but the system treats these factors equivalently and cannot dynamically adapt to changes in user behavior or security risks

Engineering Contradiction:
Improveauthentication securityVSAvoiddynamic adaptation to user behavior
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic trust level system where the authentication threshold is not fixed but adjusts continuously based on elapsed time since authentication, user behavior patterns, and security risk assessments. The trust level decreases over time and can be modified by various factors including user location changes and security threats, allowing the system to adapt dynamically rather than treating all authentication factors equivalently throughout the session

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameter (trust level) based on multiple variables including time elapsed, authentication information type, user location, and security threats. This allows the authentication requirements to be adjusted dynamically - for example, requiring additional authentication when trust level drops below transaction risk level, rather than using a static threshold for all scenarios

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If authentication remains valid until timeout or session termination, then user convenience is improved, but the system cannot respond to dynamically changing security risks

Engineering Contradiction:
Improveauthentication validity durationVSAvoidresponse to security risk changes
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The trust level is continuously adjusted during the session based on elapsed time, user behavior, and security conditions. Rather than maintaining a static authenticated state until timeout, the system dynamically modifies the trust level, requiring additional authentication when the trust level drops below the transaction risk level, thus responding to changing security risks while the session remains active

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors user behavior, location changes, and security threats, providing feedback that adjusts the trust level in real-time. This feedback mechanism allows the system to respond dynamically to changing conditions during the session, requesting additional authentication when risk increases, rather than passively maintaining authentication until timeout

Inventive Principle:
Principle #23Feedback

3Reliability

If additional authentication is requested frequently, then security is improved, but user experience deteriorates due to repeated authentication requirements

Engineering Contradiction:
Improvesecurity threshold enforcementVSAvoiduser authentication burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system adjusts the authentication threshold (trust level) dynamically based on the specific context including elapsed time, type of authentication information provided, user location, and security threats. This allows the system to request additional authentication only when necessary - for example, when trust level drops below transaction risk level or when security threats are detected - rather than requiring frequent authentication unconditionally, thus balancing security with user convenience

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8635662B2Dynamic trust model for authenticating a user
Publication Date: 2014.01.21 INTUIT INC
  • US8635662B2 patent drawing
  • US8635662B2 patent drawing
  • US8635662B2 patent drawing

AI summary

A system that that dynamically authenticates one or more users is described. During operation, the computer system determines a trust level for a user, where the trust level is a function of elapsed time since the user previously provided authentication information. Next, the computer system calculates a transaction risk level based on a type of user transaction performed by the user. Then, the computer system requests additional authentication information from the user based on the trust level and the transaction risk level.