Identity Risk Score Generation for Cloud Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing systems lack effective validation and monitoring of user identities after initial validation, leading to potential fraudulent activities, as they do not continuously verify user credentials and monitor application usage.
Innovation Solution
An authentication server generates an identity risk score based on various identity factors and encapsulates it in an authentication assertion, which is used to validate users and monitor application usage, limiting fraudulent activities by applying operating heuristics and providing identity risk scores to third parties.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If initial user validation is performed, then user identity verification is achieved, but continuous monitoring and validation after initial authentication are lacking
Solution Approach 1:
The system performs preliminary actions by establishing baseline user profiles and access patterns during initial legitimate authentication, then uses these pre-established criteria to continuously evaluate subsequent actions without requiring repeated full validation processes
Solution Approach 2:
The system implements continuous feedback loops where each user action is monitored against established baselines, and the system dynamically adjusts risk scores based on deviations from normal patterns, enabling ongoing validation without complete re-authentication
2Reliability
If heavy monitoring of application usage is implemented, then fraudulent activities are detected, but system complexity and processing overhead increase
Solution Approach 1:
The monitoring system operates autonomously by automatically comparing user actions against established baselines, dynamically adjusting risk scores, and triggering appropriate responses without requiring manual intervention or complex centralized control mechanisms
Solution Approach 2:
The system monitors changes in behavioral parameters and access patterns rather than every individual action, using threshold-based triggers to determine when full monitoring should activate, thereby reducing overall system complexity while maintaining detection capability
3Reliability
If identity risk scores are continuously generated and enforced, then fraudulent use is prevented, but user experience and access speed may be degraded
Solution Approach 1:
The system applies partial monitoring and risk score generation only when necessary based on detected anomalies or risk thresholds, rather than continuously evaluating every user action, thereby maintaining security effectiveness while minimizing impact on normal access speed
Solution Approach 2:
Risk score generation and full validation occur periodically or event-driven based on specific triggers rather than continuously, allowing normal operations to proceed at full speed between evaluation points while maintaining security oversight
Data Source
AI summary
Embodiments are directed to providing an identity risk score as part of an authentication assertion, applying operating heuristics to determine an operating application's validity and to providing identity risk scores to requesting third parties. In one scenario, an authentication server receives from a cloud service portal various user credentials from a user. The user credentials identify a user to the authentication server. The authentication server verifies the user's identity using the received credentials and generates an identity risk score based on one or more identity factors. The identity factors indicate a likelihood that the user is a valid user. The authentication server encapsulates the generated identity risk score in an authentication assertion and sends the authentication assertion that includes the generated identity risk score to the cloud service portal.


