Cloud-based application security
Systems, methods, and computer program products for providing cloud-based application security are disclosed. For example, a server part of a cloud-based application may determine a plurality of security challenges for authorizing a request based on a plurality of security settings of a user account and one or more attributes of the request, issue a first-level authorization challenge and a second-level authorization challenge based on the determining, identify a plurality of available resources from the user account for the request, and responsive to successful completion of the first-level authorization challenge and the second-level authorization challenge, automatically apply two or more of the available resources from the user account to fulfill the request based on the one or more attributes of the request and a physical location associated with the request.
1 . A system, comprising:
a non-transitory memory, and
one or more hardware processors coupled to the non-transitory memory and configured to read instructions from the non-transitory memory to cause the system to perform operations comprising:
receiving, from a user device associated with a user, a request for processing a transaction through a user account;
providing a first-level authentication challenge to the user device, wherein the first-level authentication challenge is performed locally on the user device;
authenticating the user for accessing the user account at a first access level based on a first set of inputs received from the user device in response to the first-level authentication challenge;
determining a set of criteria for processing the transaction without requiring a second-level authentication challenge based on a balance of the user account and a risk profile associated with a user of the user account, wherein the risk profile is generated for the user account based on historic interactions between the user and the system;
determining whether the second-level authentication challenge is required for authenticating the user for the transaction based on the set of criteria and attributes associated with the request, wherein the second-level authentication challenge is performed via communications between the user device and a service provider server via a network; and
in response to determining that the second-level authentication challenge is not required, enabling the user device to process the transaction according to the first access level.
2 . The system of claim 1 , wherein the first set of inputs is associated with a first modality, and wherein the second-level authentication challenge requires a second set of inputs associated with a second modality different from the first modality.
3 . The system of claim 2 , wherein the first set of inputs comprises a passcode, and wherein the second set of inputs required by the second-level authentication challenge comprises biometric information of the user.
4 . The system of claim 3 , wherein the second set of inputs comprises a fingerprint scan of the user.
5 . The system of claim 1 , wherein the set of criteria comprises a threshold, and wherein the operations further comprise:
determining whether an attribute of the transaction exceeds the threshold; and
determining that the second-level authentication challenge is not required based on the attribute not exceeding the threshold.
6 . The system of claim 5 , wherein the transaction is a payment transaction, and wherein the attribute comprises a payment amount associated with the payment transaction.
7 . The system of claim 1 , wherein the determining whether the second-level authentication challenge is required for authenticating the user is further based on a user preference associated with the user account.
8 . A method comprising:
receiving, from a user device associated with a user, a request for processing a transaction through a user account;
authenticating, by a computer system and via a first-level authentication challenge, the user for accessing the user account according to a first access level, wherein the first-level authentication challenge is performed locally on the user device;
determining, by the computer system, a set of criteria for processing the transaction without requiring a second-level authentication challenge based on historic interactions between the user and the computer system;
determining, by the computer system, whether the second-level authentication challenge is required for processing the transaction for the user based on the set of criteria and a first attribute associated with the transaction, wherein the second-level authentication challenge is performed via communications between the user device and a service provider server via a network; and
in response to determining that the second-level authentication challenge is not required for processing the transaction, processing the transaction for the user using a first set of resources associated with the user account.
9 . The method of claim 8 , wherein the request is a first request for processing a first transaction for the user, and wherein the method further comprises:
subsequent to processing the first transaction, receiving, from the user device, a second request for processing a second transaction through the user account;
determining that the second-level authentication challenge is required for processing the second transaction;
providing the second-level authentication challenge to the user device; and
authenticating the user for accessing the user account according to a second access level based on the communications between the user device and the service provider server and a response from the second-level authentication challenge by the user device.
10 . The method of claim 9 , wherein the authenticating the user for accessing the user account according to the second access level enables the user to access a second set of resources associated with the user account, and wherein the method further comprises:
processing the second transaction for the user using the second set of resources associated with the user account.
11 . The method of claim 8 , wherein the transaction comprises a data access transaction for accessing first content, wherein the set of criteria comprises a content sensitivity threshold, and wherein the method further comprises:
determining a sensitivity level corresponding to the first content; and
determining that the second-level authentication challenge is not required for processing the data access transaction based on the sensitivity level corresponding to the first content not exceeding the content sensitivity threshold.
12 . The method of claim 8 , wherein the transaction comprises a payment transaction, wherein the set of criteria comprises a threshold, and wherein the method further comprises:
determining whether an attribute of the payment transaction exceeds the threshold; and
determining that the second-level authentication challenge is not required based on the attribute not exceeding the threshold.
13 . The method of claim 12 , wherein the attribute comprises a payment amount associated with the payment transaction.
14 . The method of claim 8 , wherein the first-level authentication challenge requires a first set of inputs associated with a first modality, and wherein the second-level authentication challenge requires a second set of inputs associated with a second modality different from the first modality.
15 . A non-transitory machine-readable medium having stored thereon machine-readable instructions executable to cause a machine to perform operations comprising:
receiving, from a user device of a user, a request associated with a user account;
authenticating, using a first-level authentication challenge, the user for the request according to a first access level, wherein the first-level authentication challenge is performed locally on the user device;
determining a set of criteria for processing the request without requiring a second-level authentication challenge based on a risk profile associated with the user, wherein the risk profile is generated for the user based on historic transactions conducted by the user through the user account;
determining whether the user is required to be authenticated using the second-level authentication challenge based on one or more attributes associated with the request and the set of criteria, wherein the second-level authentication challenge is performed via communications between the user device and a service provider server via a network; and
in response to determining that the user is not required to be authenticated using the second-level authentication challenge, providing the user device access to a first set of resources associated with the user account for the request according to the first access level.
16 . The non-transitory machine-readable medium of claim 15 , wherein the request is for accessing content from the user account, wherein the set of criteria comprises a content sensitivity threshold, and wherein the operations further comprise:
determining a sensitivity level corresponding to the content; and
determining that the user is not required to be authenticated using the second-level authentication challenge for processing the request based on the sensitivity level corresponding to the content not exceeding the content sensitivity threshold.
17 . The non-transitory machine-readable medium of claim 15 , wherein the request is for processing a payment transaction through the user account, wherein the set of criteria is associated with a threshold, and wherein the operations further comprise:
determining whether an attribute of the payment transaction exceeds the threshold; and
determining that the user is not required to be authenticated using the second-level authentication challenge for processing the payment transaction based on the attribute not exceeding the threshold.
18 . The non-transitory machine-readable medium of claim 17 , wherein the attribute comprises a payment amount associated with the payment transaction.
19 . The non-transitory machine-readable medium of claim 15 , wherein the first-level of authentication challenge requires a first set of inputs associated with a first modality, and wherein the second-level of authentication challenge requires a second set of inputs associated with a second modality different from the first modality.
20 . The non-transitory machine-readable medium of claim 15 , wherein the determining whether the user is required to be authenticated using the second-level authentication challenge for processing the request is further based on a user preference associated with the user account.