Virtual Host Authentication with Dynamic Key Splitting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network security solutions, such as firewalls and dual-factor authentication, are inadequate in preventing hackers from gaining access to internal networks using compromised user login credentials, especially with the rise of remote work and external device access, which can lead to data breaches and legal liabilities.
Innovation Solution
A security tool that sits between external networks and internal systems, using virtual hosts to authenticate users based on both login credentials and dynamic alpha-numeric keys stored on user devices, which change with each access session, thereby limiting the effectiveness of stolen credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network security solutions (firewalls, anti-virus software, dual-factor authentication) are used, then basic network protection is provided, but they are ineffective against hackers using compromised user login credentials
Solution Approach 1:
The patent segments the authentication process into multiple independent verification stages: (1) traditional credential verification, (2) behavioral biometric analysis, and (3) continuous session monitoring. This multi-layered segmentation ensures that even if one layer is compromised, other layers remain to detect and prevent unauthorized access.
Solution Approach 2:
The system implements continuous feedback loops by monitoring user behavior patterns during authentication and throughout the session. Behavioral biometrics (keystroke dynamics, mouse movements, typing rhythm) provide real-time feedback to verify user identity, and the system continuously adjusts security measures based on detected anomalies in user behavior.
2Reliability
If dual-factor authentication is implemented, then enhanced security is provided, but it is still vulnerable to phishing attacks where attackers capture verification codes
Solution Approach 1:
The patent replaces traditional mechanical authentication methods (entering verification codes) with behavioral biometric authentication. Instead of relying on codes that can be captured through phishing, the system uses continuous analysis of user behavior patterns (keystroke dynamics, mouse movements, typing rhythm) to verify identity, making phishing attacks ineffective.
Solution Approach 2:
The system introduces behavioral biometrics as an intermediary layer between traditional authentication and system access. This intermediary continuously verifies user identity through behavior analysis, adding a layer of protection that cannot be compromised by phishing attacks that target code-based authentication.
3Ease of operation
If external devices are permitted to access internal systems, then user flexibility and productivity are improved, but network security risks increase
Solution Approach 1:
The patent implements dynamic security measures that adapt to each user session and device. Behavioral biometric profiles are created and updated continuously based on user behavior patterns. Security controls dynamically adjust based on risk assessment, allowing flexible access for legitimate users while automatically detecting and blocking suspicious activities from external devices.
Data Source
AI summary
A system includes a hardware processor, a virtual host, and a first subsystem. The processor receives a request indicating that a user is seeking to access the first subsystem. The processor uses the virtual host to perform a first authentication of the user, without yet connecting the user to the first subsystem, based on the login credentials of the user. In response to performing the first authentication, the virtual host provides the user with access to the first subsystem. The first subsystem then generates a key associated with the user and stores the key in a database. The first subsystem splits the key into a first part and a second part. The first subsystem additionally sends the first part to the user, for storage in an authentication string stored in a device of the user. The first subsystem also stores the second part in a second authentication server.


