Risk-Based Authentication Using Logon Type Frequency Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods, primarily relying on logon and password combinations, are inadequate in preventing identity theft and online fraud, as they often balance usability and security poorly, leading to either insecurity or cumbersome deployment.

Innovation Solution

A method and apparatus that assess the risk of electronic communications by determining logon types and generating a risk score based on the frequency of logon requests over different time periods, using processing circuitry to evaluate and authenticate user access to computerized resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If logon and password combination is used for authentication, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the parameter of authentication from static credentials (password) to dynamic behavioral characteristics (keystroke dynamics, typing rhythm, pressure patterns). This allows the system to maintain ease of operation while improving security by continuously verifying user identity through subtle typing patterns that are difficult to replicate

Inventive Principle:
Principle #35Parameter changes

2Reliability

If authentication security is enhanced to satisfactory levels, then security is improved, but device complexity and operational burden are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity of authentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs authentication verification automatically in the background without requiring user intervention. The keystroke dynamics analysis occurs seamlessly as users type, eliminating the need for additional security steps or complex user interactions while maintaining high security standards

Inventive Principle:
Principle #25Self-service

3Ease of operation

If traditional logon and password authentication is used, then ease of operation is maintained, but susceptibility to fraud and identity theft is worsened

Engineering Contradiction:
Improvesimplicity of login processVSAvoidvulnerability to fraud
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors and analyzes typing patterns in real-time, providing ongoing feedback about user identity verification. This creates a dynamic authentication process that adapts to behavioral changes and can detect compromised credentials, maintaining simplicity while reducing fraud vulnerability

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10356120B1Method, apparatus and computer program product for assessing the risk of electronic communications using logon types
Publication Date: 2019.07.16 RSA SECURITY USA LLC
  • US10356120B1 patent drawing
  • US10356120B1 patent drawing
  • US10356120B1 patent drawing

AI summary

Disclosed are techniques for use in assessing the risk of electronic communications using logon types. In one embodiment, the techniques comprise a method. The method comprises receiving an electronic communication relating to a login request involving a user and a provider of a computerized resource. The method comprises determining a logon type associated with the logon request. The method comprises determining a first value relating to an amount of logon requests associated with the logon type involving the user and the provider over a first time period and a second value relating to an amount of logon requests associated with the logon type involving the user and the provider over a second time period that is greater than the first time period. The method comprises generating a risk score describing the risk associated with the logon request based on the first and the second values.