Threat-Based Authentication Using Confidence Vectors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems face challenges in effectively managing complex Boolean expressions for multiple authentication modes, leading to high false positive and false negative rates in risk-based authentication methods, which do not provide clear insights into risk scoring factors.
Innovation Solution
A threat-based authentication method that calculates a resource confidence value using a threat confidence vector and resource vulnerability scores, comparing it to a resource confidence criterion to grant access, thereby tailoring security policies to mitigate the most likely threats while reducing user burden.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If risk-based authentication methods are used to mitigate unauthorized access, then security against threats is improved, but false positive and false negative rates increase
Solution Approach 1:
The patent transforms the abstract risk score into a structured threat confidence vector with specific parameters for different threat types. By changing the representation parameters from a single score to a multi-dimensional vector with confidence levels, the system achieves both comprehensive threat coverage and precise authentication decisions, reducing false positives and negatives while maintaining security.
2Reliability
If multiple authentication modes are combined using Boolean expressions, then security coverage is improved, but system complexity increases
Solution Approach 1:
The patent replaces complex Boolean expressions with a parameter-based threat confidence vector system. Instead of managing multiple Boolean conditions for different authentication modes, the system uses a unified vector structure with confidence parameters that automatically evaluate threat levels, significantly reducing system complexity while maintaining comprehensive security coverage.
Solution Approach 2:
The patent substitutes the mechanical Boolean logic system with a confidence-based evaluation mechanism. The threat confidence vector and resource confidence criterion replace the need for complex Boolean expression management, providing a more elegant and manageable approach to multi-mode authentication while preserving security effectiveness.
3Adaptability or versatility
If risk-based authentication is implemented, then security policy adaptability is improved, but clarity of risk scoring factors deteriorates
Solution Approach 1:
The patent segments the overall risk assessment into distinct threat-type-specific confidence parameters within the threat confidence vector. Each parameter corresponds to a specific threat category, providing clear, interpretable information about which threats are most concerning. This segmentation maintains adaptability across different threat scenarios while preserving clarity about the factors influencing authentication decisions.
Data Source
AI summary
In some embodiments, a method includes receiving, at a host device, a signal indicative of an authentication request for a client device to access a resource from a set of resources. A resource confidence value associated with the authentication request is calculated based at least in part on (1) a threat confidence vector associated with at least one risk mitigation score for each threat from a set of threats and (2) a set of resource vulnerability scores associated with the resource and each threat from the set of threats. The resource confidence value is compared to a resource confidence criterion associated with the resource from the set of resources. A signal indicative of a positive authentication is sent from the host device to the client device when the resource confidence value satisfies the resource confidence criterion such that the client device is granted access to the resource.


