Access Control Server Authentication via Risk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user authentication systems for online transactions are inadequate due to reliance on limited password data, which can be compromised, and require users to repeatedly enter passwords, leading to cumbersome processes and potential communication issues.

Innovation Solution

Implementing an access control server that utilizes additional sets of attributes for remote authentication processing, including prior and current authentication methods, to verify users based on risk analysis and authentication indicators, thereby reducing the need for repeated password entries and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional password-based authentication is used, then the authentication process is simple to implement, but security is compromised and the process becomes cumbersome requiring repeated password entries

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication actions by obtaining device information and transaction information before the actual authentication decision. The access control server collects device characteristics, transaction details, and risk factors in advance to pre-assess authentication risk, eliminating the need for repeated password entries while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an access control server as an intermediary between the user and the authentication system. This server acts as a mediator that collects device information, transaction information, and risk factors, then makes authentication decisions based on comprehensive analysis rather than relying solely on password verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication steps are required, then security is enhanced, but processing time increases and communication timeouts may occur

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial authentication action by performing risk-based authentication that may require fewer steps than traditional multi-factor authentication. The access control server assesses risk levels and only requires additional verification steps when risk factors are present, allowing low-risk transactions to proceed with minimal authentication steps.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary risk assessment by collecting device information and transaction information before authentication. This pre-assessment allows the system to determine the appropriate level of verification needed, reducing processing time by avoiding unnecessary authentication steps for low-risk transactions.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If only password data is used for verification, then the authentication system is simple to implement, but fraud detection capability is insufficient

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access control server performs multiple functions including collecting device information, analyzing transaction information, assessing risk factors, and making authentication decisions. This multi-functional approach enhances fraud detection capability while consolidating complexity into a single server rather than distributing it across multiple specialized components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The access control server serves as an intermediary that aggregates various data sources including device information, transaction information, and risk factors. This intermediary consolidates the complexity of analyzing multiple data types into a single point, making the system adaptable to fraud detection while managing complexity centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3776425B1Secure authentication system and method
Publication Date: 2024.09.25 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3776425B1 patent drawingFigure 1
  • EP3776425B1 patent drawingFigure 2
  • EP3776425B1 patent drawingFigure 3

AI summary

A method is disclosed. The method comprising: receiving, by an access control server via a directory server from an authentication requestor, an authentication request comprising an account identifier, and information regarding a prior authentication method on the account identifier and a current authentication method for the account identifier associated with a transaction; performing, by the access control server, a risk analysis for the transaction based at least in part on the information and a threshold; authenticating, by the access control server, the user of the account identifier using the information, the account identifier, and a result of the risk analysis; modifying, by the access control server, an authentication response to include an authentication indicator, and transmitting, by the access control server, the authentication response to the authentication requestor.