Zero-Trust Session Authentication Risk-Based Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Zero-trust systems often enforce stringent mitigation actions on all users equally, which can lead to reduced productivity for users with limited access to enterprise resources, as they are frequently flagged for location and network changes, despite posing a lower risk of data leakage.

Innovation Solution

A computing environment that assesses the security posture of users, client devices, and network conditions, considering the user's role and access level, to tailor remedial actions based on individual risk levels, allowing for more nuanced and context-dependent mitigation strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If zero-trust systems enforce stringent mitigation actions on all users equally, then security posture is improved, but productivity deteriorates for users with limited access

Engineering Contradiction:
Improvesecurity postureVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by differentiating mitigation actions based on user risk levels. Instead of uniform treatment, the system tailors security measures to individual users' access levels and risk profiles, applying stricter controls to high-risk users while allowing more flexible access to low-risk users, thus resolving the contradiction between security and productivity

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments users into different risk levels (e.g., low, medium, high risk) and applies differentiated mitigation actions to each segment. This segmentation allows the system to maintain strong security for high-risk users while minimizing interruptions for low-risk users, thereby addressing the contradiction between maintaining security posture and preserving productivity

Inventive Principle:
Principle #1Segmentation

2Reliability

If zero-trust systems apply uniform mitigation actions to all users, then security consistency is improved, but user experience deteriorates

Engineering Contradiction:
Improvesecurity consistencyVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements local quality by customizing the user experience based on individual risk levels. Each user receives tailored mitigation actions appropriate to their access level and risk profile, improving ease of operation for low-risk users while maintaining security consistency through standardized risk assessment frameworks

Inventive Principle:
Principle #3Local quality

3Reliability

If zero-trust systems continuously monitor and flag location/network changes, then security detection is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically adjusts monitoring intensity and mitigation actions based on real-time risk assessment. Instead of continuous uniform monitoring, the system adapts its detection and response behaviors to individual user risk levels, improving security detection effectiveness while managing system complexity through conditional logic

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250106260A1Zero-Trust Session Authentication
Publication Date: 2025.03.27 OMNISSA LLC
  • US20250106260A1 patent drawing
  • US20250106260A1 patent drawing
  • US20250106260A1 patent drawing

AI summary

Various examples are disclosed for a zero-trust authentication model for user sessions. Upon user authentication of a session, security posture assessments can be performed that analyze an ongoing or continuous state of the user, client device, or network conditions. Remedial measures or mitigation procedures can be performed to address potential non-compliance of the session.