Adaptive Authentication Levels for Financial Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Financial management systems face a challenge in balancing security protection with user experience, as complex authentication processes can deter adoption and usability, despite providing heightened protection, and not all information requires the same level of assurance.
Innovation Solution
Implementing adaptive levels of assurance based on the sensitivity, criticality, or confidentiality of information accessed, using varying authentication strengths, allowing for lower authentication efforts for less sensitive data and escalating to higher efforts for more critical data, thereby enhancing user experience and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex authentication processes are implemented to provide heightened protection, then security is improved, but user experience and usability deteriorate
Solution Approach 1:
The patent applies local quality by implementing different authentication strengths at different flow nodes based on the sensitivity of the information or action. Low authentication strength is used for non-sensitive operations while high authentication strength is used for sensitive operations, allowing security to be tailored locally rather than uniformly applied throughout the system.
Solution Approach 2:
The patent implements dynamics by making the authentication strength adaptive rather than static. The system dynamically adjusts the required authentication strength based on the user's traversal through the flow, the sensitivity of accessed information, and fraud risk assessments, allowing the security level to change in response to system conditions.
2Reliability
If strong authentication processes are required for all users, then protection is heightened, but adoption rates decrease
Solution Approach 1:
The patent applies local quality by implementing different authentication strengths at different flow nodes based on the sensitivity of the information or action. Low authentication strength is used for non-sensitive operations while high authentication strength is used for sensitive operations, allowing security to be tailored locally rather than uniformly applied throughout the system.
Solution Approach 2:
The patent applies partial action by requiring strong authentication only when necessary for sensitive operations rather than for all operations. Users perform only the minimum authentication effort needed for their current task, avoiding excessive authentication requirements that would deter adoption while maintaining adequate protection for critical functions.
3Reliability
If uniform high-level authentication is applied to all information access, then security is improved, but system complexity increases
Solution Approach 1:
The patent applies local quality by implementing different authentication strengths at different flow nodes based on the sensitivity of the information or action. Low authentication strength is used for non-sensitive operations while high authentication strength is used for sensitive operations, allowing security to be tailored locally rather than uniformly applied throughout the system.
Solution Approach 2:
The patent applies segmentation by dividing the authentication system into multiple strength levels (low, medium, high) that are assigned to different flow nodes. This segmentation allows the complex authentication mechanism to be broken down into manageable, context-appropriate components rather than applying a single uniform complex authentication process everywhere.
Data Source
AI summary
Disclosed are methods, systems, and articles of manufacture for implementing adaptive levels of authentication assurance according to sensitivity or criticality of information accessed or actions performed in a financial management system to enhance user experience and usability of the financial management system while providing adequate security to safeguard sensitive data. Various flow nodes are associated with one or more levels of assurance which are further associated with some authentication tokens of different authentication strengths. Users are usually first authenticated with a lower authentication strength token. Risk profiles may also be accessed to examine the users' requests for access for fraud detection or prevention purposes. As users attempt to access more sensitive data at a higher level of assurance beyond the authorized level, further authentication with higher authentication strength and involving more user efforts in completing the authentication is required before users are authorized on the higher level of assurance.


