Polymorphic Authentication System for Unpredictable Security Challenges
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face security risks in protecting customer information and user accounts due to predictable authentication methods, making them vulnerable to scripted, replay, and phishing attacks.
Innovation Solution
Implementing just-in-time polymorphic authentication techniques that dynamically select and vary authentication methods based on time-based, counter-based, external risk, geographic, event-based, and user-specific factors to create unpredictable authentication prompts, thereby enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If predictable authentication methods are used, then ease of operation is improved, but security is worsened
Solution Approach 1:
The authentication system dynamically selects and presents different authentication challenges based on polymorphic factors such as time, counter values, external risks, geography, events, and user-specific characteristics. This makes the authentication process adaptive and unpredictable, preventing attackers from using scripted or replay attacks while still providing a user-friendly experience for legitimate users.
2Device complexity
If static authentication prompts are used, then device complexity is reduced, but adaptability is worsened
Solution Approach 1:
The system changes multiple parameters of the authentication process including the type of challenge presented, the timing of challenges, the sequence of authentication steps, and the selection of authentication methods. These parameter changes are based on polymorphic factors that vary between authentication attempts, allowing the system to adapt to different contexts without requiring complex custom authentication flows for each scenario.
Data Source
AI summary
Methods, systems, apparatuses, and computer-readable media for utilizing just-in-time polymorphic authentication techniques to secure information are presented. In one or more embodiments, a computing platform may receive, from a computing device, a request to access a user account. In response to receiving the request to access the user account, the computing platform may dynamically select, based on one or more polymorphic authentication factors, an authentication method for authenticating a user of the computing device, and the authentication method may be selected from a plurality of predefined authentication methods. Subsequently, the computing platform may generate one or more authentication prompts based on the selected authentication method. The computing platform then may provide the one or more authentication prompts to the user of the computing device. The authentication prompts that are selected for and presented to a particular user during a given access attempt may vary across different attempts.


