Token-Based Re-Authentication Apparatus for Dynamic Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face inefficiencies in re-authenticating users due to changes in device, network, or resource conditions, which can compromise access control and security.

Innovation Solution

An apparatus that detects changes by storing and analyzing tokens indicating user access, prompting for a password generated using personal information, and requesting a second password to re-authenticate the user, ensuring secure and efficient re-authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional re-authentication methods are used, then security can be maintained, but the process is inefficient and time-consuming

Engineering Contradiction:
Improvere-authentication efficiencyVSAvoidre-authentication time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing authentication tokens and personal information databases before re-authentication is needed. When re-authentication is required, the system can quickly retrieve pre-stored tokens and personal information, significantly reducing the time needed for the re-authentication process while maintaining security standards.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of authentication tokens and personal information for verification purposes. Instead of requiring users to re-enter all their information, the system uses copied token data to verify user identity quickly, improving efficiency while maintaining security through cryptographic verification of these copies.

Inventive Principle:
Principle #26Copying

2Reliability

If frequent re-authentication is performed, then security is improved, but user convenience deteriorates

Engineering Contradiction:
Improveaccess control securityVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts the re-authentication frequency and method based on real-time risk assessment. When risk is low, the system allows continued access without re-authentication, improving convenience. When risk increases due to detected changes, the system triggers re-authentication, maintaining security. This dynamic approach balances both requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors network conditions, device status, and user behavior, providing feedback to the authentication decision-making process. This feedback mechanism allows the system to intelligently determine when re-authentication is necessary, avoiding unnecessary interruptions to user convenience while maintaining appropriate security levels.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If simple password verification is used, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improvepassword entry simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system merges multiple authentication factors including password verification, token validation, and personal information verification into a unified re-authentication process. Users still enter their password simply, but the system combines this with automated token checks and personal information verification to provide enhanced security without significantly complicating the user experience.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces authentication tokens as intermediaries between the user and the password verification process. These tokens mediate the authentication by providing an additional layer of verification that doesn't directly burden the user with complex procedures, while enhancing the overall security of the authentication process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8572683B2Method and apparatus for token-based re-authentication
Publication Date: 2013.10.29 BANK OF AMERICA CORP
  • US8572683B2 patent drawing
  • US8572683B2 patent drawing
  • US8572683B2 patent drawing

AI summary

According to one embodiment, an apparatus may store a plurality of tokens that indicate a user is using a device to access a resource over a network. The apparatus may detect at least one token indicating a change associated with at least one of the device, the network, or the resource. The apparatus may then determine to re-authenticate the user in response to the change. The apparatus may then request a password generated using personal information of the user, and receive a re-authentication token comprising the password generated using personal information of the user. The apparatus may then request, from the user, a second password. The request for the second password may include instructions on how to form the second password. The apparatus may receive a response comprising the second password and determine that the second password matches the password. The apparatus may then re-authenticate the user.