Heat Map-Based Dynamic Authentication for Adaptive Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods are inflexible and do not adapt authentication levels based on the location of a user's device, requiring the same strong authentication even in trusted environments, which can be burdensome and inconvenient for users.
Innovation Solution
A method using a heat map to define different zones of trustworthiness within a geographic region, dynamically adjusting authentication requirements based on the device's location, allowing for weaker authentication in trusted zones and stronger authentication in less-trusted zones, enabling virtual geofencing over any geographic area.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication methods are used, then security is maintained through consistent authentication requirements, but user convenience deteriorates due to requiring strong authentication even in trusted environments
Solution Approach 1:
The patent implements dynamic authentication by adjusting authentication requirements based on the device's geographic location. The system transitions from static authentication (same requirements everywhere) to dynamic authentication (varying requirements based on location), allowing strong authentication only in less-trusted zones while using weaker authentication in trusted zones, thus resolving the contradiction between security and user convenience
Solution Approach 2:
The patent applies different authentication strengths to different geographic locations. By dividing the geographic space into trusted and less-trusted zones, the system applies local quality principles where authentication requirements are tailored to the specific security needs of each location, rather than applying uniform authentication requirements globally
2Adaptability or versatility
If geofencing technology is installed to enable location-based authentication, then authentication flexibility improves, but device complexity increases due to specialized equipment requirements
Solution Approach 1:
The patent uses GPS reception, which is a universal function already present in modern mobile devices, to determine geographic location for authentication purposes. By leveraging an existing multi-functional capability (GPS) rather than adding specialized geofencing hardware, the system achieves location-based authentication flexibility without increasing device complexity
Solution Approach 2:
The patent creates a virtual geofencing system through software-based location tracking using GPS coordinates, rather than implementing physical geofencing infrastructure. This virtual copy of geofencing functionality achieves the same authentication flexibility without requiring specialized physical equipment
3Reliability
If strong authentication is required at all locations, then security is improved, but user burden increases due to always requiring multiple authentication factors
Solution Approach 1:
The patent applies partial authentication action by requiring strong multi-factor authentication only in less-trusted geographic zones while using weaker single-factor authentication in trusted zones. This partial application of strong authentication reduces the overall time users spend on authentication while maintaining security where it is most needed
Data Source
AI summary
A technique controls access to a set of protected resources. The technique involves receiving a location signal which identifies a current geolocation of an endpoint device. The technique further involves, based on the current geolocation identified by the location signal, generating a heat map corresponding to a geographic region that includes the current geolocation of the endpoint device, the heat map defining one or more security zones within the geographic region. The technique further involves, selecting a particular security level from multiple security levels based on a security zone of the heat map associated with the current geolocation of the endpoint device, and communicating the selected security level to the endpoint device. The selected security level is associated with security requirements to be satisfied by the endpoint device in order for the endpoint device to access the set of protected resources.


