Dynamic Multi-Factor Authentication via Port Scanning Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-factor authentication systems rely heavily on single methods of verification, such as email or one-time codes, which can be compromised, leading to potential unauthorized access to multiple accounts. There is a need for a system that dynamically determines the necessary verification methods based on context and risk associated with each connection.

Innovation Solution

A system and method for risk analysis using port scanning to determine a required verification score for accessing network resources, which involves monitoring network traffic, scanning network ports at the intended destination, and requiring users to accumulate verification points through multiple verification methods to access the resource.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single verification method (email or one-time code) is used for authentication, then the authentication process is simple and fast, but the security is compromised when that single method is breached

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic multi-factor authentication where the system automatically selects and adjusts verification methods based on real-time risk assessment. The authentication requirements change dynamically based on factors like destination risk level, user behavior patterns, and connection context, rather than using a fixed set of verification methods for all scenarios.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of authentication by adjusting the number and type of verification factors required based on the assessed risk level. Low-risk connections may require only one factor, while high-risk connections trigger multiple verification methods, effectively changing the authentication parameters to match the threat level.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple verification methods are always required, then security is enhanced, but the authentication process becomes slower and more complex for users

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by requiring only the necessary number of verification factors based on risk assessment. Instead of always requiring all possible verification methods, the system applies just enough authentication factors to achieve the required security level for each specific connection attempt, avoiding unnecessary time loss for low-risk scenarios.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The authentication process is made dynamic, adjusting the number of verification steps in real-time based on risk evaluation. The system starts with baseline verification and adds additional factors only when risk thresholds are exceeded, creating a flexible authentication flow that adapts to each connection attempt rather than following a rigid multi-step process for all users.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If port scanning is performed on all connection destinations, then risk assessment accuracy is improved, but the system resource consumption and processing time increase

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidconnection establishment speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs preliminary risk assessment using available connection context information (such as known good destinations, user profiles, and historical data) before initiating full port scanning. This preliminary evaluation allows the system to skip scanning for low-risk connections while reserving comprehensive scanning for suspicious or high-value targets, optimizing the balance between accuracy and speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies local quality by performing different levels of scanning based on the specific characteristics of each connection destination. Instead of uniform scanning for all targets, the system adjusts the scanning depth and methodology according to the local context—using lightweight checks for trusted destinations and comprehensive scanning only when necessary, thereby improving efficiency without sacrificing accuracy where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12015596B2Risk analysis using port scanning for multi-factor authentication
Publication Date: 2024.06.18 QOMPLX INC
  • US12015596B2 patent drawing
  • US12015596B2 patent drawing
  • US12015596B2 patent drawing

AI summary

A system for risk analysis using port scanning for multi-factor authentication having a multi-dimensional time series data server configured to monitor and record a network's traffic data and to serve the traffic data to other modules and a directed computational graph module configured to scan open ports on connection destinations, analyze the scan results, and determine a verification score needed before granting access based at least in part on the analysis of the received responses. A plurality of verification methods build up a user's verification score to required level to gain access.