Adaptive Authentication Levels for Financial Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Financial management systems face a challenge in balancing security protection with user experience, as complex authentication processes can deter adoption and usability, despite providing heightened protection, and not all information requires the same level of assurance.

Innovation Solution

Implementing adaptive levels of assurance based on the sensitivity, criticality, or confidentiality of information accessed, using varying authentication strengths, allowing for lower authentication efforts for less sensitive data and escalating to higher efforts for more critical data, thereby enhancing user experience and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex authentication processes are implemented to provide heightened protection, then security is improved, but user experience and usability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by implementing different authentication strengths at different flow nodes based on the sensitivity of the information or action. Low authentication strength is used for non-sensitive operations while high authentication strength is used for sensitive operations, allowing security to be tailored locally rather than uniformly applied throughout the system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamics by making the authentication strength adaptive rather than static. The system dynamically adjusts the required authentication strength based on the user's traversal through the flow, the sensitivity of accessed information, and fraud risk assessments, allowing the security level to change in response to system conditions.

Inventive Principle:
Principle #15Dynamics

2Reliability

If strong authentication processes are required for all users, then protection is heightened, but adoption rates decrease

Engineering Contradiction:
ImproveprotectionVSAvoidadoption rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing different authentication strengths at different flow nodes based on the sensitivity of the information or action. Low authentication strength is used for non-sensitive operations while high authentication strength is used for sensitive operations, allowing security to be tailored locally rather than uniformly applied throughout the system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by requiring strong authentication only when necessary for sensitive operations rather than for all operations. Users perform only the minimum authentication effort needed for their current task, avoiding excessive authentication requirements that would deter adoption while maintaining adequate protection for critical functions.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If uniform high-level authentication is applied to all information access, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing different authentication strengths at different flow nodes based on the sensitivity of the information or action. Low authentication strength is used for non-sensitive operations while high authentication strength is used for sensitive operations, allowing security to be tailored locally rather than uniformly applied throughout the system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies segmentation by dividing the authentication system into multiple strength levels (low, medium, high) that are assigned to different flow nodes. This segmentation allows the complex authentication mechanism to be broken down into manageable, context-appropriate components rather than applying a single uniform complex authentication process everywhere.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10044730B1Methods, systems, and articles of manufacture for implementing adaptive levels of assurance in a financial management system
Publication Date: 2018.08.07 INTUIT INC
  • US10044730B1 patent drawing
  • US10044730B1 patent drawing
  • US10044730B1 patent drawing

AI summary

Disclosed are methods, systems, and articles of manufacture for implementing adaptive levels of authentication assurance according to sensitivity or criticality of information accessed or actions performed in a financial management system to enhance user experience and usability of the financial management system while providing adequate security to safeguard sensitive data. Various flow nodes are associated with one or more levels of assurance which are further associated with some authentication tokens of different authentication strengths. Users are usually first authenticated with a lower authentication strength token. Risk profiles may also be accessed to examine the users' requests for access for fraud detection or prevention purposes. As users attempt to access more sensitive data at a higher level of assurance beyond the authorized level, further authentication with higher authentication strength and involving more user efforts in completing the authentication is required before users are authorized on the higher level of assurance.