Scalable Authentication via Device-Specific Challenge Workflows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication techniques are burdensome for authorized users and fail to differentiate effectively between authorized and unauthorized devices, leading to increased unauthorized access to digital information.
Innovation Solution
A computer-implemented method and system for scalable authentication using challenge workflows, where a user device's request for access is authenticated through a set of challenge workflows, with parameters generated based on the device identifier and executed based on threshold conditions, ensuring secure access to resource data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication techniques are used, then access control is maintained, but user burden increases and authorized/unauthorized device differentiation is insufficient
Solution Approach 1:
The authentication process is segmented into multiple challenge workflows with different authentication factors (knowledge-based, possession-based, inherence-based). The system divides the authentication decision into discrete steps where challenge workflows are selected and executed based on device characteristics and risk assessment, allowing flexible combination of authentication methods without overwhelming users.
Solution Approach 2:
The authentication system dynamically adjusts the challenge workflows based on real-time risk assessment. The system monitors device behavior, location, and other parameters to dynamically select which authentication factors to apply, making the authentication process adaptive rather than static. This allows the system to maintain security while reducing burden on low-risk authorized devices.
2Ease of operation
If authentication processes are simplified, then user burden is reduced, but security against unauthorized access deteriorates
Solution Approach 1:
Different authentication factors are applied selectively based on the specific device and access context. The system evaluates device characteristics (mobile device, tablet, computer) and assigns appropriate authentication challenges locally for each access attempt. This allows simplified authentication for trusted devices while maintaining robust security for suspicious or unauthorized devices.
Solution Approach 2:
The system introduces an intermediary authentication server that mediates between the user device and the resource access. This intermediary evaluates challenge workflows and coordinates the authentication process, allowing the system to maintain strong security measures while presenting a simplified interface to users. The intermediary handles the complexity of multiple authentication factors behind the scenes.
3Reliability
If multiple authentication factors are applied, then device differentiation and security are improved, but authentication complexity increases
Solution Approach 1:
The system performs preliminary device characterization and risk assessment before initiating authentication. By pre-evaluating device traits, location data, and access patterns, the system can pre-determine which challenge workflows are most appropriate, reducing the complexity of real-time authentication decisions. This preliminary action allows the system to present users with streamlined authentication options based on pre-analyzed risk factors.
Data Source
AI summary
Authentication systems and methods can selectively authenticate a request to access a resource data store storing access rights associated with a user device. The systems and methods can scalably execute challenges workflows as part of the authentication process. For example, a request to access one or more access rights stored in the data store can be received from the user device. The user device can be authenticated using challenge workflows selected based on a device identifier of the user device. The selected challenge workflows can be executed to determine whether or not to grant access to the access rights stored in the resource data store.


