Time-Only Authentication Factors for Coordinated Multi-Factor Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems often fail to coordinate access time and authentication factors, leading to reduced security if these systems are not integrated.
Innovation Solution
Implementing a multi-factor authentication system that includes time-only, multi-session, and location-only authentication factors, which are integrated with access rules to grant resource access based on these factors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If access time and authentication factors are administered separately, then administrative flexibility is improved, but security is reduced
Solution Approach 1:
The patent combines separate access time administration and authentication factor administration into a unified system. The authentication policy manager integrates both functions, allowing time-based rules and authentication requirements to be coordinated through a single policy framework, thereby maintaining administrative flexibility while improving security through coordinated control.
2Reliability
If multiple authentication factors are required, then security is improved, but system complexity increases
Solution Approach 1:
The system dynamically determines authentication requirements based on time-of-day rules and access policies. Rather than requiring multiple authentication factors for all access scenarios, the system adaptively applies authentication factors only when necessary according to the configured policies, reducing complexity while maintaining security where needed.
Solution Approach 2:
The patent changes the parameter of authentication requirement based on time and policy conditions. The system adjusts whether authentication factors are required, and which specific factors are needed, based on temporal parameters and access policies, rather than using a static multi-factor authentication approach for all cases.
3Reliability
If access control is based on multiple factors, then security is improved, but processing time increases
Solution Approach 1:
The system performs preliminary configuration of access policies and time-based rules in advance. Authentication policies are pre-defined with specific time windows and required authentication factors, allowing the authentication decision engine to quickly evaluate access requests against pre-configured rules rather than performing complex real-time policy formulation, thus reducing processing time while maintaining security.
Data Source
AI summary
A multi-factor authentication request of a user is received. For example, the multi-factor authentication request may include a valid username/password and a valid fingerprint scan. A first authentication factor of the multi-factor authentication request is an access authentication factor (e.g., the valid username/password) and a second authentication factor (e.g., the valid fingerprint scan) of the multi-factor authentication request is one of: a time-only authentication factor; a multi-session authentication factor; and a location-only authentication factor. The user is authenticated based on the first authentication factor and the second authentication factor. Access is granted to one or more resources according to one or more rules associated with the first authentication factor and second authentication factor.


