Passive Security Enforcement via Dynamic Authentication Levels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems face inefficiencies in security enforcement, particularly when users need different authentication levels for various features or transactions, leading to unnecessary active authentication when passive authentication would suffice.

Innovation Solution

Implementing a passive security enforcement mechanism that uses observations of user interactions, such as physical and behavioral data, to dynamically adjust authentication levels, allowing for trusted authentication between proximate devices and enabling seamless access to features based on observed patterns without requiring active credentials for low-risk tasks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If active authentication is enforced for all features, then security is improved, but user convenience deteriorates due to unnecessary authentication prompts for low-risk tasks

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different authentication levels to different features based on their risk profiles. Low-risk features (e.g., browsing public websites) operate with passive authentication, while high-risk features (e.g., electronic commerce transactions) require active authentication. This localized differentiation resolves the contradiction by providing strong security where needed while maintaining convenience where risk is low.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts authentication levels based on observed user behavior, device proximity, and feature risk assessment. The authentication level is not static but adapts in real-time, allowing the system to require active authentication only when necessary while maintaining passive authentication for routine low-risk operations, thus balancing security and convenience.

Inventive Principle:
Principle #15Dynamics

2Reliability

If different authentication levels are required for different features, then security is improved, but system complexity increases due to multiple authentication levels

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs a universal passive authentication mechanism that can serve multiple features and functions. Rather than implementing separate authentication systems for each feature, a single passive authentication framework is established that can dynamically adjust its security level based on the specific feature being accessed, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system is segmented into passive and active components, with passive authentication serving as the baseline for all features and active authentication being selectively applied to high-risk features. This segmentation simplifies the overall architecture by establishing a default low-complexity mode with optional escalation to higher security when needed.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If passive authentication is used for low-risk features, then user convenience is improved, but security may be compromised if authentication levels are insufficient

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system continuously monitors user behavior, device proximity, and transaction characteristics to provide feedback on authentication level adequacy. When passive authentication is being used, the system observes user actions and can dynamically escalate to active authentication if suspicious patterns are detected, ensuring security is maintained while allowing convenience for genuine low-risk operations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system preemptively establishes passive authentication as a baseline security measure for all features, then prepares to escalate to active authentication if risk indicators arise. This preliminary security posture allows convenient operation while maintaining the capability to immediately strengthen security if needed, preventing security compromises before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10389712B2Passive security enforcement
Publication Date: 2019.08.20 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10389712B2 patent drawing
  • US10389712B2 patent drawing
  • US10389712B2 patent drawing

AI summary

Technology is described for enabling passive enforcement of security at computing systems. A component of a computing system can passively authenticate or authorize a user based on observations of the user's interactions with the computing system. The technology may increase or decrease an authentication or authorization level based on the observations. The level can indicate what level of access the user should be granted. When the user or a component of the computing device initiates a request, an application or service can determine whether the level is sufficient to satisfy the request. If the level is insufficient, the application or service can prompt the user for credentials so that the user is actively authenticated. The technology may enable computing systems to “trust” authentication so that two proximate devices can share authentication levels.