Risk Analysis Apparatus for Risk-Based Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional risk-based authentication techniques fail to adequately differentiate between users with similar risk scores, as they do not consider past risk history and recent behavior patterns, leading to inadequate authentication measures.
Innovation Solution
A risk analysis apparatus and method that collects risk factors from authentication processes, calculates a current risk score and a total risk score based on past history, and determines if additional authentication is required by comparing these scores against thresholds, ensuring stronger authentication for users with higher risk profiles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional risk-based authentication calculates risk score based only on current authentication information, then the authentication process is simple and fast, but it cannot differentiate between users with similar current risk profiles who have different historical risk behaviors
Solution Approach 1:
The patent transitions from a single-dimension risk assessment (current authentication information only) to a multi-dimensional risk assessment by incorporating the time dimension. It introduces a risk score history database that stores risk scores from previous authentications and uses a weighted summation method to combine historical risk scores with current risk score, thereby differentiating users with similar current profiles based on their temporal risk patterns.
Solution Approach 2:
The system performs preliminary risk assessment by continuously collecting and storing risk scores from past authentications in a risk score history database. This preliminary accumulation of historical data enables the system to quickly evaluate user risk profiles by comparing current behavior against established historical patterns, rather than starting fresh with each authentication attempt.
2Reliability
If the system requests additional authentication for every high-risk scenario, then security is improved, but user convenience and authentication speed deteriorate
Solution Approach 1:
The patent dynamically adjusts the authentication threshold parameter based on the calculated total risk score. Instead of applying a fixed threshold to all users, the system modifies the decision criterion by comparing the weighted sum of historical and current risk scores against the threshold. This parameter adaptation allows the system to request additional authentication only when the combined historical and current risk profile justifies it, rather than applying uniform strict authentication to all scenarios.
3Measurement precision
If the system collects and processes extensive risk factor data, then risk assessment accuracy is improved, but processing time and computational resources increase
Solution Approach 1:
The patent extracts only the essential elements needed for risk assessment: it collects specific risk factors (device information, location, authentication method, time of day) and stores only the aggregated risk scores in the history database rather than raw data. This extraction of critical information maintains assessment accuracy while minimizing processing overhead and storage requirements.
Solution Approach 2:
The system implements a balanced approach by collecting a comprehensive set of risk factors but processing them through a simplified weighted summation method. It gathers extensive data (multiple risk factors across multiple dimensions) but applies a relatively simple computational model (weighted sum of historical and current scores) rather than complex machine learning algorithms, achieving good accuracy with moderate processing effort.
Data Source
AI summary
A risk analysis apparatus and method are provided. According to one embodiment of the present disclosure, the risk analysis apparatus includes: at least one processor configured to: a risk factor collector configured to collect risk factors related to one or more authentication processes for authentication of a user of a client device in an authentication system; a risk analyzer configured to calculate a current risk score for the user based on the collected risk factors and calculate a total risk score based on a risk score history of the user and the current risk score based on the one or more authentication processes being successful; and an additional authentication requester configured to determine whether additional authentication of the user is required based on the current risk score and the total risk score and, request the client device for the additional authentication of the user based on the additional authentication being required.


