Continuous Passwordless Authentication Using Adaptive Trust Scores
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Digital transactions are often compromised by unauthorized parties or malicious actors using stolen credentials or network bots, leading to fraudulent activities, as conventional authentication methods fail to effectively differentiate between legitimate and illegitimate access attempts.
Innovation Solution
A system that monitors network access by capturing contextual and behavioral factors of user entities and network conditions, calculating a trust score, and dynamically adjusting the level of assurance for user authentication, utilizing a risk engine with AI and ML analytics to continuously authenticate and authorize user access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication methods are used, then ease of operation is maintained, but reliability of authentication is compromised due to inability to differentiate between legitimate and illegitimate access attempts
Solution Approach 1:
The system dynamically adjusts the level of assurance required for authentication based on real-time trust scores calculated from contextual and behavioral factors. The authentication requirements are not static but adapt continuously to the assessed risk level, allowing the system to maintain reliability while managing complexity through adaptive rather than universally complex procedures
Solution Approach 2:
The system changes the parameter of authentication strictness based on the calculated trust score. When trust scores are high (low risk), the system uses lighter authentication methods, while when trust scores are low (high risk), it implements stricter verification procedures. This parameter adjustment resolves the contradiction by making authentication reliability context-dependent rather than uniformly complex
2Reliability
If dynamic level of assurance adjustment is implemented, then reliability of access control is improved, but ease of operation deteriorates due to continuous monitoring requirements
Solution Approach 1:
The system performs continuous monitoring and trust score calculation automatically without requiring active user participation. The contextual and behavioral factors are collected and analyzed by the system itself, and the level of assurance is adjusted autonomously based on the assessed risk, eliminating the need for users to manually request different authentication levels
Solution Approach 2:
The system continuously monitors user behavior and contextual factors, feeds this information into the trust score calculation, and adjusts the level of assurance accordingly. This closed-loop feedback mechanism maintains access control reliability while keeping the user experience smooth, as the system adapts automatically without requiring user awareness or action
3Reliability
If continuous behavioral authentication is performed, then reliability of fraud detection is enhanced, but use of energy increases due to constant analysis of user behavior
Solution Approach 1:
The system applies continuous monitoring at different levels of intensity based on the assessed risk. For high-trust users with consistent behavioral patterns, the system performs lighter monitoring, while for low-trust users or when anomalies are detected, it intensifies the analysis. This partial action approach maintains fraud detection reliability while reducing unnecessary energy consumption during low-risk periods
Solution Approach 2:
The system performs trust score calculations and behavioral analysis at periodic intervals rather than continuously at maximum intensity. The monitoring frequency and depth are adjusted based on the current trust score and detected anomalies, allowing the system to maintain effective fraud detection while managing energy consumption through rhythmic rather than constant high-intensity processing
Data Source
AI summary
Aspects of the disclosure provide techniques for using egocentric and allocentric information for providing and restricting access to a secure network and its assets to a user entity. The system may include capturing user habits and fingerprinting with ability to detect abnormalities through artificial intelligence/machine learning (AIML) using mobile and wearable device applications.


