Risk-Based Authentication System for Adaptive Security Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems are inefficient and inconvenient, as they often require repeated authentication from users and devices, especially when accessing protected services, which can be unnecessary for low-risk scenarios, thereby compromising user experience and security.

Innovation Solution

Implementing a risk-based decision-making system that captures user and device attributes to determine the security risk, allowing for reduced or eliminated additional authentication when the risk is deemed acceptable, thereby enhancing the efficiency and security of the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If repeated authentication is required for all access attempts, then data security is improved, but user convenience and productivity deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system changes the authentication parameters dynamically based on risk assessment. Instead of using a fixed authentication requirement for all access attempts, the system adjusts the authentication level (from none to additional authentication) based on risk factors such as device trust level, location, and access pattern anomalies. This resolves the contradiction by making security measures adaptive rather than static.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The authentication system transitions from a static, one-size-fits-all approach to a dynamic risk-based approach. The system continuously monitors access patterns and device characteristics, adjusting authentication requirements in real-time based on the assessed risk level. This dynamic adaptation allows the system to maintain security while improving user convenience for low-risk scenarios.

Inventive Principle:
Principle #15Dynamics

2Reliability

If additional authentication steps are required for all access attempts, then data security is improved, but authentication time and productivity deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system changes authentication parameters based on risk assessment results. For low-risk access attempts, the system parameters indicate no additional authentication is needed, allowing immediate access. For high-risk attempts, the system switches to requiring additional authentication steps. This parameter adaptation optimizes authentication efficiency while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies partial authentication action only when necessary. Instead of requiring full authentication for all access attempts, the system performs risk assessment first and only applies additional authentication steps when the risk level justifies it. This partial action approach eliminates unnecessary authentication overhead for low-risk scenarios while maintaining security for high-risk scenarios.

Inventive Principle:
Principle #16Partial or excessive action

3Device complexity

If standard authentication systems are used without risk-based decisions, then system simplicity is maintained, but security optimization and adaptability deteriorate

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity optimization
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system introduces a risk assessment intermediary component that sits between the access request and the authentication decision. This intermediary analyzes risk factors and provides a recommendation that influences the authentication outcome. By adding this intermediary layer, the system achieves security optimization without fundamentally redesigning the entire authentication architecture, thus balancing complexity and security improvement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12124556B2Incorporating risk-based decision in standard authentication and authorization systems
Publication Date: 2024.10.22 AETNA INC
  • US12124556B2 patent drawing
  • US12124556B2 patent drawing
  • US12124556B2 patent drawing

AI summary

Embodiments of the disclosure provide a method for enhancing standard authentication systems to include risk-based decisions. Risk-based decisions can be selectively implemented within existing authentication systems to strategically modify and supplement security if an unacceptable risk is detected. Embodiments capture information pertaining to a user and user device. Information is stored to create a profile for the user and user device. A comparison between the stored information and live data can be performed within authentication systems to optimize security. If the results of the comparison demonstrate the presence of an acceptable risk, then the need for subsequent authentication can be reduced or eliminated, which improves a user experience.