Identity Risk Score Generation for Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing systems lack effective validation and monitoring of user identities after initial validation, leading to potential fraudulent activities, as they do not continuously verify user credentials and monitor application usage.

Innovation Solution

An authentication server generates an identity risk score based on various identity factors and encapsulates it in an authentication assertion, which is used to validate users and monitor application usage, limiting fraudulent activities by applying operating heuristics and providing identity risk scores to third parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If initial user validation is performed, then user identity verification is achieved, but continuous monitoring and validation after initial authentication are lacking

Engineering Contradiction:
Improveuser identity verificationVSAvoidcontinuous validation period
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The system performs preliminary actions by establishing baseline user profiles and access patterns during initial legitimate authentication, then uses these pre-established criteria to continuously evaluate subsequent actions without requiring repeated full validation processes

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where each user action is monitored against established baselines, and the system dynamically adjusts risk scores based on deviations from normal patterns, enabling ongoing validation without complete re-authentication

Inventive Principle:
Principle #23Feedback

2Reliability

If heavy monitoring of application usage is implemented, then fraudulent activities are detected, but system complexity and processing overhead increase

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring system operates autonomously by automatically comparing user actions against established baselines, dynamically adjusting risk scores, and triggering appropriate responses without requiring manual intervention or complex centralized control mechanisms

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system monitors changes in behavioral parameters and access patterns rather than every individual action, using threshold-based triggers to determine when full monitoring should activate, thereby reducing overall system complexity while maintaining detection capability

Inventive Principle:
Principle #35Parameter changes

3Reliability

If identity risk scores are continuously generated and enforced, then fraudulent use is prevented, but user experience and access speed may be degraded

Engineering Contradiction:
Improvefraud prevention effectivenessVSAvoidaccess speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies partial monitoring and risk score generation only when necessary based on detected anomalies or risk thresholds, rather than continuously evaluating every user action, thereby maintaining security effectiveness while minimizing impact on normal access speed

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Risk score generation and full validation occur periodically or event-driven based on specific triggers rather than continuously, allowing normal operations to proceed at full speed between evaluation points while maintaining security oversight

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10055561B2Identity risk score generation and implementation
Publication Date: 2018.08.21 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10055561B2 patent drawing
  • US10055561B2 patent drawing
  • US10055561B2 patent drawing

AI summary

Embodiments are directed to providing an identity risk score as part of an authentication assertion, applying operating heuristics to determine an operating application's validity and to providing identity risk scores to requesting third parties. In one scenario, an authentication server receives from a cloud service portal various user credentials from a user. The user credentials identify a user to the authentication server. The authentication server verifies the user's identity using the received credentials and generates an identity risk score based on one or more identity factors. The identity factors indicate a likelihood that the user is a valid user. The authentication server encapsulates the generated identity risk score in an authentication assertion and sends the authentication assertion that includes the generated identity risk score to the cloud service portal.