Anonymized User Data Exchange for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems fail to prevent unauthorized interactions by not providing exposure-related information, leaving them ineffective in ensuring complete security during user-third party entity interactions.

Innovation Solution

A system that continuously monitors user activity, identifies triggers, communicates with back-end systems to extract information, and facilitates anonymized communication between users and resource entities, using machine learning models to generate lists of supplemental resources and provide real-time alerts to prevent unauthorized interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional authentication systems are used, then authentication process is simplified, but security effectiveness is reduced due to lack of exposure information

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary system that sits between the user and the third-party entity, acting as a mediator that provides exposure information to users without complicating the authentication process. This intermediary layer delivers security-relevant information (exposure data, risk assessments) to帮助用户 make informed decisions while maintaining the simplicity of the original authentication flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback by continuously monitoring user interactions and providing real-time exposure information back to users. This feedback loop includes displaying risk levels, exposure data, and security recommendations during the authentication process, enabling users to adjust their behavior based on the information provided without adding significant complexity to the authentication flow.

Inventive Principle:
Principle #23Feedback

2Loss of information

If anonymized communication is implemented, then user privacy is protected, but information accuracy for authentication is reduced

Engineering Contradiction:
Improveuser privacyVSAvoidauthentication accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent applies local quality by selectively anonymizing different parts of user data based on their sensitivity and relevance to authentication. Critical authentication information (user identifiers, device characteristics) is preserved in identifiable form, while sensitive personal information is anonymized. This selective approach maintains authentication accuracy where needed while protecting privacy where appropriate.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts the level of anonymization based on the authentication context and risk assessment. For low-risk interactions, more detailed information may be retained; for high-risk scenarios, greater anonymization is applied. This parameter-based approach allows the system to balance privacy protection with authentication accuracy flexibly, adapting to different situations without compromising security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11250160B2Machine learning based user and third party entity communications
Publication Date: 2022.02.15 BANK OF AMERICA CORP
  • US11250160B2 patent drawing
  • US11250160B2 patent drawing
  • US11250160B2 patent drawing

AI summary

An electronic communication security system is typically configured for tracking and monitoring user activity of a user, identifying a trigger based on monitoring and tracking the user activity, communicating with back-end system to extract information associated with a resource entity that is associated with the trigger, communicating with the back-end systems to identify user agreement associated with the user and the resource entity, identifying one or more supplemental resources provided by the resource entity, based on the user agreement, prompting the user to authorize transfer of anonymized user data to the resource entity to receive the one or more supplemental resources, anonymizing the user data and transmit the anonymized user data to the resource entity, in response to transmitting the anonymized user data to the resource entity, receiving the one or more supplemental resources from the resource entity, and transmitting the one or more supplemental resources to the user device.