Endpoint Authentication via Dynamic Behavioral Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing continuous authentication solutions in information processing systems often rely on strict rules and ignore contextual data and behavioral patterns, limiting their effectiveness in ensuring user authentication and authorization.
Innovation Solution
A method that uses an endpoint device to obtain behavioral anomalies from a remote engine, generates features based on authentication data, and applies these features to behavior models to determine a behavior score for user authentication decisions, considering both local and global user behaviors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If strict rules are used for continuous authentication, then security control is improved, but user convenience deteriorates
Solution Approach 1:
The system dynamically changes authentication parameters by transitioning between continuous authentication mode (using behavioral biometrics) and traditional authentication mode (using passwords or multi-factor authentication) based on the calculated risk level. When risk is low, the system uses seamless continuous authentication; when risk increases, it escalates to stronger authentication methods, thus balancing security and convenience
Solution Approach 2:
The authentication system is made dynamic by continuously monitoring user behavior and adjusting the authentication level in real-time. The risk engine dynamically calculates risk scores based on behavioral patterns, and the system adapts its authentication requirements accordingly, rather than applying static strict rules at all times
2Ease of operation
If traditional authentication methods are used, then user convenience is improved, but security control deteriorates
Solution Approach 1:
The system merges traditional authentication methods with continuous behavioral biometric authentication. Instead of relying solely on periodic password authentication, the system combines this with continuous monitoring of user interactions, device characteristics, and behavioral patterns to create a layered security approach that maintains both convenience and enhanced security
3Reliability
If continuous authentication is implemented, then security is improved, but system complexity increases
Solution Approach 1:
The continuous authentication system operates autonomously by automatically collecting behavioral data, analyzing patterns, calculating risk scores, and making authentication decisions without requiring user intervention. The system serves itself by continuously monitoring and adapting to user behavior, reducing the need for complex manual security management while maintaining high security levels
Data Source
AI summary
Techniques are provided for authenticating a user using an endpoint device of the user with a local policy and endpoint data. One method comprises obtaining, at an endpoint device of a given user, behavioral anomalies from a remote engine that generates the behavioral anomalies based on behavior of multiple users; in response to an access request by the given user, performing the following steps at the endpoint device: obtaining authentication data related to the given user and/or the endpoint device; generating features based on the authentication data; applying the features to a behavior model incorporating the behavioral anomalies to determine a behavior score for the access request; and evaluating the access request to make an authentication decision based on the behavior score. The behavior score indicates, for example, a confidence that the given user is an expected user and/or a same user who has previously been validated.


