Context-Aware Authentication Continuum for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user authentication methods are inefficient and insecure, particularly in mobile or public settings, as they require users to remember and manually enter credentials, which can be prone to errors and interception, and do not effectively leverage additional user information for validation.

Innovation Solution

Determining user authentication requirements based on the current location and pattern of movement, allowing for varying levels of authentication (no, partial, or full authentication) depending on proximity to designated locations, thereby reducing the need for manual credential entry in secure zones and enhancing security in insecure areas.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional user authentication methods are used requiring manual credential entry, then security validation is achieved, but user convenience and efficiency deteriorate due to the burden of remembering and entering credentials

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs automatic authentication by having the user device send its identifier to the server, which then validates the device against stored authentication credentials. This eliminates the need for manual credential entry by the user, allowing the system to authenticate the user automatically based on device identification alone.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical process of manual credential entry (typing passwords, PINs) with an automated electronic authentication system. The server automatically receives device identifiers, compares them against stored credentials, and performs authentication without requiring physical user interaction for credential input.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual authentication credential entry is required, then security validation is performed, but time efficiency and productivity worsen due to the time-consuming nature of the process

Engineering Contradiction:
Improveauthentication validationVSAvoidtransaction efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication validation by having the server store authentication credentials associated with user devices in advance. When a user attempts to access a transaction, the server automatically retrieves and validates the device identifier against pre-stored credentials, eliminating the need for real-time credential verification and speeding up the transaction process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated authentication system allows transactions to proceed efficiently by performing validation in the background without requiring user participation in the credential verification process, thus maintaining security while improving transaction throughput and user productivity.

Inventive Principle:
Principle #25Self-service

3Reliability

If authentication credentials are entered manually in public settings, then access validation is achieved, but security risks increase due to potential interception of credentials

Engineering Contradiction:
Improveaccess controlVSAvoidcredential interception risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication credentials from the user device and stores them securely on the server. During authentication, only a device identifier (not the actual credentials) is transmitted from the user device to the server. The server performs the validation by comparing the identifier against stored credentials, thereby eliminating the need for users to transmit or enter sensitive credentials over potentially insecure networks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The server acts as an intermediary that handles the sensitive credential verification process. Instead of users directly transmitting credentials over the network, the server mediates the authentication by storing credentials securely and performing validation based on device identifiers, thus protecting credentials from interception during transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If uniform authentication requirements are applied to all users and locations, then security consistency is maintained, but adaptability to different contexts and user states deteriorates

Engineering Contradiction:
Improvesecurity consistencyVSAvoidcontext-aware authentication
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts authentication requirements based on the user's current state and context. The server can modify authentication parameters such as credential complexity, multi-factor authentication requirements, or session duration based on factors like user location, device type, time of day, or historical behavior patterns, allowing security to adapt to different situations while maintaining consistency in its decision-making process.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10050962B2Determining user authentication requirements along a continuum based on a current state of the user and/or the attributes related to the function requiring authentication
Publication Date: 2018.08.14 BANK OF AMERICA CORP
  • US10050962B2 patent drawing
  • US10050962B2 patent drawing
  • US10050962B2 patent drawing

AI summary

Systems, apparatus, methods, and computer program products are provided for determining a user's authentication requirements/credentials for function requiring authentication based on determining a location along an authentication continuum. The location along the authentication continuum defines the degree of authentication/credentials required to access the function and is determined based on a current state of the user and/or function attributes. The more or less that is known about the current state of the user the more or less likely the user is the user that is attempting to access the function and, thus, the authentication requirements required to access the function can be adjusted according (increased or decreased).