App Profile Verification for Personalized Transaction Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication (MFA) systems are vulnerable to attacks such as dictionary attacks and SIM swapping, as they rely on traditional methods that are easily replicable by nefarious users, lacking a personalized layer of security.
Innovation Solution
Enhance transaction authentication by checking the state of one or more other applications on a user's device, requiring them to be in specific states or transition within a specified period, leveraging a personalized security framework that aligns with user preferences and transaction sensitivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional single-factor authentication methods (passwords or PINS) are used, then the ease of operation is maintained, but the security and reliability are insufficient against sophisticated cyber threats
Solution Approach 1:
The authentication process is segmented into multiple independent verification steps: checking the first application's transaction request, verifying the state of the second application, confirming state transitions within specified time periods, and validating multiple factors before approving the transaction. This segmentation transforms a single complex authentication into multiple simpler verification steps that collectively enhance security while maintaining operational ease.
Solution Approach 2:
The system performs preliminary actions by pre-configuring transaction authorization data records that specify required states of second applications before transactions occur. These pre-established security parameters and state requirements are prepared in advance, allowing the authentication system to quickly verify compliance without adding operational burden during actual transactions.
2Reliability
If multi-factor authentication systems combining multiple verification methods are implemented, then the reliability and security are improved, but the device complexity and authentication process complexity increase
Solution Approach 1:
The authentication system leverages existing applications and their states as multi-functional security factors. Instead of requiring dedicated hardware tokens or separate authentication applications, the system uses the functional states of applications the user already has installed and uses regularly. This universal approach allows existing application ecosystems to serve dual purposes: their primary functions plus authentication verification, thereby enhancing security without proportionally increasing system complexity.
Solution Approach 2:
The system enables self-service authentication by automatically monitoring and verifying the states of second applications without requiring user intervention. The authentication process autonomously checks whether required applications are in specified states or have transitioned states within time periods, eliminating the need for users to manually configure or manage additional security devices while maintaining high security standards.
3Reliability
If application state verification is added to the authentication process, then the personalized security layer is enhanced, but the loss of time for authentication processing increases
Solution Approach 1:
The system implements periodic action by checking application states at specific intervals and within defined time periods. Instead of continuous monitoring that would consume excessive resources and time, the authentication process verifies whether state transitions occur within predetermined time windows. This periodic verification approach provides robust personalized security while limiting the time overhead to manageable, predictable intervals.
Solution Approach 2:
The authentication system dynamically adjusts parameters such as time periods and state requirements based on transaction characteristics and risk levels. By changing verification parameters adaptively rather than applying fixed stringent checks to all transactions, the system achieves personalized security tailored to each transaction's needs while minimizing unnecessary time consumption for low-risk operations.
Data Source
AI summary
Methods, systems, and machine-readable mediums that enhance transaction authentication of a transaction of a first application by checking that a state of one or more other applications matches prespecified states or that one or more of those applications transition states within a prespecified period of time. For example, the prespecified states may correspond to the application being installed on a specified device (e.g., of the user) and having an authenticated session with a specified user.


