Threat-Based Authentication Using Confidence Vectors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems face challenges in effectively managing complex Boolean expressions for multiple authentication modes, leading to high false positive and false negative rates in risk-based authentication methods, which do not provide clear insights into risk scoring factors.

Innovation Solution

A threat-based authentication method that calculates a resource confidence value using a threat confidence vector and resource vulnerability scores, comparing it to a resource confidence criterion to grant access, thereby tailoring security policies to mitigate the most likely threats while reducing user burden.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If risk-based authentication methods are used to mitigate unauthorized access, then security against threats is improved, but false positive and false negative rates increase

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidaccuracy of authentication decisions
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent transforms the abstract risk score into a structured threat confidence vector with specific parameters for different threat types. By changing the representation parameters from a single score to a multi-dimensional vector with confidence levels, the system achieves both comprehensive threat coverage and precise authentication decisions, reducing false positives and negatives while maintaining security.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple authentication modes are combined using Boolean expressions, then security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomplexity of authentication management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex Boolean expressions with a parameter-based threat confidence vector system. Instead of managing multiple Boolean conditions for different authentication modes, the system uses a unified vector structure with confidence parameters that automatically evaluate threat levels, significantly reducing system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent substitutes the mechanical Boolean logic system with a confidence-based evaluation mechanism. The threat confidence vector and resource confidence criterion replace the need for complex Boolean expression management, providing a more elegant and manageable approach to multi-mode authentication while preserving security effectiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If risk-based authentication is implemented, then security policy adaptability is improved, but clarity of risk scoring factors deteriorates

Engineering Contradiction:
Improveadaptability of security policyVSAvoidclarity of risk scoring factors
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent segments the overall risk assessment into distinct threat-type-specific confidence parameters within the threat confidence vector. Each parameter corresponds to a specific threat category, providing clear, interpretable information about which threats are most concerning. This segmentation maintains adaptability across different threat scenarios while preserving clarity about the factors influencing authentication decisions.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9787723B2Devices and methods for threat-based authentication for access to computing resources
Publication Date: 2017.10.10 PING IDENTITY CORP
  • US9787723B2 patent drawing
  • US9787723B2 patent drawing
  • US9787723B2 patent drawing

AI summary

In some embodiments, a method includes receiving, at a host device, a signal indicative of an authentication request for a client device to access a resource from a set of resources. A resource confidence value associated with the authentication request is calculated based at least in part on (1) a threat confidence vector associated with at least one risk mitigation score for each threat from a set of threats and (2) a set of resource vulnerability scores associated with the resource and each threat from the set of threats. The resource confidence value is compared to a resource confidence criterion associated with the resource from the set of resources. A signal indicative of a positive authentication is sent from the host device to the client device when the resource confidence value satisfies the resource confidence criterion such that the client device is granted access to the resource.