Authentication Engine Segments Enrollment Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional enrollment processes for online authentication systems are vulnerable to unauthorized access due to the susceptibility of authentication information and the lack of effective security measures to prevent misuse, especially since customers often receive all authentication details at once and may not recall or agree to terms and conditions.

Innovation Solution

Implementing a system that uses temporary and permanent passcodes, out-of-wallet questions, and a website image identification security system in unique combinations across different locations and times to enhance security, with a processor determining access based on IP addresses and communication channels to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If all authentication information is provided to customers at initial enrollment, then the enrollment process is completed efficiently, but the authentication information becomes susceptible to loss, misplacement, or unauthorized use

Engineering Contradiction:
Improveenrollment completion efficiencyVSAvoidauthentication information security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the authentication information delivery process into multiple stages: initial enrollment provides only a temporary passcode, while permanent passcodes and additional authentication details are distributed separately at later stages or through different channels. This segmentation prevents all authentication information from being compromised simultaneously while maintaining enrollment efficiency.

Inventive Principle:
Principle #1Segmentation

2Loss of time

If customers receive all authentication details at once during enrollment, then the setup process is quick and simple, but unauthorized users can gain access to all credentials simultaneously

Engineering Contradiction:
Improveenrollment setup timeVSAvoidunauthorized access risk
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by providing a temporary passcode during initial enrollment that allows basic access, while restricting the distribution of permanent authentication credentials until subsequent verification steps are completed. This preliminary authentication mechanism enables quick enrollment while preventing premature access to all authentication details.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the authentication system requires multiple verification steps and location checks, then unauthorized access is prevented, but the enrollment process becomes more complex

Engineering Contradiction:
Improveauthentication securityVSAvoidenrollment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system dynamically adjusts the verification process based on detected location and device characteristics. When the system determines the customer is at an authorized location (such as a bank branch), it streamlines the enrollment process. When accessed from unauthorized locations, it implements additional verification steps, thereby adapting security measures to context without imposing uniform complexity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8141134B2Authentication engine for enrollment into a computer environment
Publication Date: 2012.03.20 BANK OF AMERICA CORP
  • US8141134B2 patent drawing
  • US8141134B2 patent drawing
  • US8141134B2 patent drawing

AI summary

Embodiments of the invention are generally directed to a system and method for enrolling a user into an authentication system. In some embodiments of the invention, a user completes a first portion of the enrollment or setup process using a first computer environment, but is not permitted to complete the enrollment or setup process from the first computer environment. The system permits the user to complete the enrollment or setup process only from a second computer environment different from the first computer environment. In one embodiment, the second computer environment is any computer environment outside of the first computer environment.