Authentication Risk Score Aggregation via Timeout Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication and access management systems face challenges in improving speed and accuracy, unifying heterogeneous data sources, and effectively aggregating third-party risk measures during the authentication journey, leading to friction and increased risk of fraud.

Innovation Solution

The system employs an autonomous access composer that aggregates and weights risk scores from multiple third-party risk score nodes, utilizing ForgeRock and third-party signals at runtime, with low latency, and includes caching and policy configuration for critical paths, enabling synchronous and asynchronous options, and a scalable API suite for fraud detection and risk management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multiple heterogeneous third-party anomaly detection data sources are integrated, then fraud detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex authentication journey into distinct phases (enrollment, access, fulfillment) and integrates anomaly detection data sources at each phase. This segmentation allows the system to manage multiple heterogeneous data sources in a structured manner, reducing overall system complexity while maintaining comprehensive fraud detection coverage across all authentication stages.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication journey orchestration layer that mediates between multiple heterogeneous third-party anomaly detection data sources and the core authentication system. This intermediary standardizes data integration, manages data flows, and coordinates risk assessment across different sources, thereby reducing system complexity while preserving fraud detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive anomaly detection from multiple sources is implemented, then security is improved, but authentication speed decreases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements partial action by selectively applying anomaly detection checks based on risk levels and authentication phases. Not all data sources are queried for every authentication attempt - instead, the system dynamically determines which anomaly detection sources to engage based on contextual risk factors, maintaining security while preserving authentication speed for low-risk scenarios.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary anomaly detection assessments during enrollment and earlier authentication phases. By pre-evaluating risk factors and establishing baseline anomaly profiles beforehand, the system reduces the computational burden during critical authentication moments, thereby maintaining both security and speed.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If unified access to heterogeneous data sources is established, then data aggregation capability is improved, but integration complexity increases

Engineering Contradiction:
Improvedata aggregation capabilityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication journey framework that can accommodate multiple heterogeneous data sources through standardized integration interfaces. This universal architecture enables the system to aggregate data from diverse sources (enrollment systems, access control systems, fulfillment systems) without requiring separate integration logic for each source, thereby improving data aggregation capability while managing integration complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If real-time aggregation of third-party risk measures is performed, then fraud detection effectiveness is improved, but processing time increases

Engineering Contradiction:
Improvefraud detection effectivenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic action by updating and re-evaluating aggregated risk measures at specific intervals and authentication phases rather than continuously. The system periodically aggregates anomaly detection data from multiple sources at key decision points in the authentication journey, maintaining fraud detection effectiveness while avoiding the continuous processing overhead that would increase time loss.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12015614B2Authentication and access management for heterogeneous sources of anomaly detection data
Publication Date: 2024.06.18 PING IDENTITY INT INC
  • US12015614B2 patent drawing
  • US12015614B2 patent drawing
  • US12015614B2 patent drawing

AI summary

The disclosed technology teaches aggregating 3rd-party risk measures during an authentication journey, including providing a risk measure aggregation node, a JSON transform, and a configuration for 3rd-party risk measures to request. Responsive to invocation of the risk measure aggregation node during the authentication journey, the method includes setting a timer for receipt of a configured 3rd-party risk measure, wherein expiration of the timer causes the risk measure aggregation node to stop waiting for a timed-out 3rd party risk measure provider and requesting the configured 3rd-party risk measures. Upon receiving at least some of the requested 3rd-party risk measures, included is applying the JSON transform to aggregate the returned 3rd-party risk measures into an aggregate score, and the risk measure aggregation node providing to another node in the authentication journey an aggregated score taking into account the configured 3rd-party risk measures received prior to expiration of the timer.