Endpoint Authentication via Dynamic Behavioral Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing continuous authentication solutions in information processing systems often rely on strict rules and ignore contextual data and behavioral patterns, limiting their effectiveness in ensuring user authentication and authorization.

Innovation Solution

A method that uses an endpoint device to obtain behavioral anomalies from a remote engine, generates features based on authentication data, and applies these features to behavior models to determine a behavior score for user authentication decisions, considering both local and global user behaviors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strict rules are used for continuous authentication, then security control is improved, but user convenience deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically changes authentication parameters by transitioning between continuous authentication mode (using behavioral biometrics) and traditional authentication mode (using passwords or multi-factor authentication) based on the calculated risk level. When risk is low, the system uses seamless continuous authentication; when risk increases, it escalates to stronger authentication methods, thus balancing security and convenience

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The authentication system is made dynamic by continuously monitoring user behavior and adjusting the authentication level in real-time. The risk engine dynamically calculates risk scores based on behavioral patterns, and the system adapts its authentication requirements accordingly, rather than applying static strict rules at all times

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If traditional authentication methods are used, then user convenience is improved, but security control deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system merges traditional authentication methods with continuous behavioral biometric authentication. Instead of relying solely on periodic password authentication, the system combines this with continuous monitoring of user interactions, device characteristics, and behavioral patterns to create a layered security approach that maintains both convenience and enhanced security

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If continuous authentication is implemented, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The continuous authentication system operates autonomously by automatically collecting behavioral data, analyzing patterns, calculating risk scores, and making authentication decisions without requiring user intervention. The system serves itself by continuously monitoring and adapting to user behavior, reducing the need for complex manual security management while maintaining high security levels

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11151232B2User authentication by endpoint device using local policy engine and endpoint data
Publication Date: 2021.10.19 EMC IP HLDG CO LLC
  • US11151232B2 patent drawing
  • US11151232B2 patent drawing
  • US11151232B2 patent drawing

AI summary

Techniques are provided for authenticating a user using an endpoint device of the user with a local policy and endpoint data. One method comprises obtaining, at an endpoint device of a given user, behavioral anomalies from a remote engine that generates the behavioral anomalies based on behavior of multiple users; in response to an access request by the given user, performing the following steps at the endpoint device: obtaining authentication data related to the given user and/or the endpoint device; generating features based on the authentication data; applying the features to a behavior model incorporating the behavioral anomalies to determine a behavior score for the access request; and evaluating the access request to make an authentication decision based on the behavior score. The behavior score indicates, for example, a confidence that the given user is an expected user and/or a same user who has previously been validated.