Event-Based Authentication Sequence for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security systems face a challenge in balancing rigorous network resource protection with user accessibility, often requiring complex authentication processes that are difficult for users to navigate.

Innovation Solution

A method that involves selecting previous user-initiated events on an enterprise computing platform to generate a user-specific authentication sequence, requiring users to provide valid responses to event-information requests as a precondition for successful authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (passwords, security questions) are used, then security protection is provided, but user accessibility and ease of operation deteriorate due to difficult-to-remember passwords and extra login steps

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing user event data (login locations, devices, times, application usage patterns) before authentication is needed. This pre-collected behavioral baseline enables the authentication system to evaluate current login attempts against established patterns, providing security without requiring users to remember complex passwords or answer security questions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system utilizes data that users naturally generate during their normal interaction with the enterprise system (login events, application usage, device information) to automatically create their authentication profile. Users effectively authenticate themselves through their own behavioral patterns without needing to manually provide additional security information.

Inventive Principle:
Principle #25Self-service

2Reliability

If complex authentication processes are implemented to improve security, then security protection is enhanced, but device complexity and difficulty of operation increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical authentication systems (password entry, security question responses, multi-factor authentication devices) with an automated behavioral analysis system. The system uses software-based monitoring and analysis of user event patterns to dynamically assess authentication risk, substituting complex physical authentication mechanisms with an intelligent software evaluation process that operates in the background.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If user-specific event information is collected and analyzed, then authentication accuracy and security are improved, but information processing requirements and system complexity increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system achieves multi-functionality by using the same collected event data for multiple purposes: normal system operation/logging, user profile management, and security authentication evaluation. The event collection infrastructure serves both operational monitoring and security assessment functions, reducing the need for separate dedicated authentication data collection systems and minimizing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10326748B1Systems and methods for event-based authentication
Publication Date: 2019.06.18 QUEST SOFTWARE INC
  • US10326748B1 patent drawing
  • US10326748B1 patent drawing
  • US10326748B1 patent drawing

AI summary

In one embodiment, a method is performed by a computer system. The method includes receiving a request to authenticate a user of an enterprise computing system. The method further includes, responsive to the request, selecting a set of previous user-initiated events of the user on the enterprise computing platform. Further, the method includes accessing user-specific event information related to the selected set of previous user-initiated events. In addition, the method includes generating, from at least a portion of the user-specific event information, a user-specific authentication sequence comprising a plurality of event-information requests. Additionally, the method includes administering the user-specific authentication sequence to the user, the administering comprising requiring the user to provide a valid response to each of the event-information requests as a precondition to successful authentication.