Multi-Challenge Authentication System for Granular Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems lack flexibility, employing a binary total-access-granted/total-lock-out paradigm that locks users out of entire networks or channels upon incorrect credentials, making credential resets cumbersome and time-consuming, and failing to provide independent control over access to specific network resources or functionalities.
Innovation Solution
A multi-challenge, multi-level authentication system that allows each authentication challenge to be independently locked or unlocked, tied to specific network resources or functionalities, enabling hierarchical configuration where lower-level challenges can be unlocked by successful upper-level responses, and using counters to manage access attempts and implement locks on specific resources or functionalities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a conventional binary authentication system locks out a user after incorrect credentials, then security is improved by preventing unauthorized access, but user experience deteriorates due to cumbersome credential resets and complete loss of access to all network resources
Solution Approach 1:
The patent segments the authentication system into multiple independent challenges (first challenge, second challenge, etc.) where each challenge can be independently locked or unlocked. This segmentation allows the system to lock only the specific challenge that failed authentication rather than locking all access, thereby maintaining security while preserving user access to other challenges and improving user experience.
2Reliability
If a conventional authentication system grants or locks access to the entire network, then security is improved by controlling overall access, but flexibility deteriorates as specific network resources cannot be independently controlled
Solution Approach 1:
The patent divides network access control into separate authentication challenges, each potentially associated with different network resources or functionality. This allows the system to selectively lock or unlock specific challenges independent of others, providing granular control over access to different network resources while maintaining overall security posture.
Solution Approach 2:
The patent applies different authentication states (locked or unlocked) to different authentication challenges based on their individual authentication status. Each challenge can have its own lock state independent of other challenges, allowing local quality control where specific resources or functionalities can be accessed while others remain restricted.
3Reliability
If a conventional authentication system uses a total lock-out approach, then security is improved by preventing all unauthorized access attempts, but time efficiency deteriorates due to the need for complete credential resets
Solution Approach 1:
The patent segments authentication into multiple independent challenges where only the failed challenge is locked. This allows users to continue accessing other challenges that remain unlocked, eliminating the need for complete credential resets and significantly reducing time loss while maintaining security through selective locking of only the compromised authentication path.
Data Source
AI summary
Embodiments disclosed herein describe multi-challenge, multi-level authentication systems, methods and products. Each authentication challenge may be independent of other challenges and may be associated with a particular network resource or functionality. Counters may track the number of attempts for each authentication challenge and each type of network resource and functionality. Each authentication challenge, network resource, or network functionality may be independently locked and unlocked based on the attempts tracked by the counters. Furthermore, the authentication system may configure the authentication challenges hierarchically, and a higher level challenge may unlock a locked lower level challenge. Therefore, embodiments disclosed herein significantly improve upon the conventional all-in/all-out binary authentication systems and methods.


