Device Fingerprint Authentication for Account Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing online accounts lack user-friendly and secure device authentication mechanisms, making them vulnerable to unauthorized access and spoofing, especially in environments like online banking and e-commerce.

Innovation Solution

A user interface and system that allows customers to manage device-based authentication by collecting and analyzing device fingerprints, enabling customers to set preferences for access control and alerts, using a forensic database to authenticate devices and send alerts based on geographic, time, and activity restrictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used, then ease of operation is maintained, but security and reliability are compromised due to vulnerability to unauthorized access and spoofing

Engineering Contradiction:
Improveaccount securityVSAvoiduser operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically collects device parameters and generates device fingerprints without requiring user intervention. The forensic database autonomously assays device characteristics and compares them against stored profiles, enabling security verification without adding operational burden to the user.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A device fingerprinting intermediary layer is introduced between the user and the authentication system. This intermediary automatically captures device parameters, creates unique fingerprints, and verifies them against the forensic database, providing enhanced security while remaining transparent to the user.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device fingerprinting is implemented, then security and reliability are improved, but device complexity increases due to multiple parameters and forensic database requirements

Engineering Contradiction:
Improvedevice authentication accuracyVSAvoidsystem structural complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system collects multiple device parameters (CPU attributes, memory characteristics, storage details, network configuration) that serve universal identification purposes. These same parameters are used across different authentication scenarios, making the complex data collection serve multiple security functions simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Device fingerprints are assayed and stored in the forensic database in advance, before actual authentication is needed. This preliminary action creates a ready reference library of authorized device profiles, enabling rapid verification without complex real-time analysis during authentication events.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If customer-managed device preferences are implemented, then adaptability and versatility are improved, but ease of operation deteriorates due to configuration complexity

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidconfiguration simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system provides dynamic access control preferences that can be adjusted by customers based on their needs. Device fingerprints can be updated as devices change, and access rules can be modified without requiring system reconfiguration, allowing flexible adaptation while maintaining ease of use through automated processes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system provides feedback to customers about device authentication status and access control decisions. This feedback mechanism helps users understand which devices are authorized, why certain devices are blocked, and how to adjust preferences, simplifying the configuration process through informative interaction.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8205790B2System and methods for customer-managed device-based authentication
Publication Date: 2012.06.26 BANK OF AMERICA CORP
  • US8205790B2 patent drawing
  • US8205790B2 patent drawing
  • US8205790B2 patent drawing

AI summary

A system and methods for customer-managed device-based authentication are disclosed. Embodiments of the invention provide a user interface that allows a customer with an on-line account to access and manage device fingerprint information that can be used to control or regulate the customer's access. Such a system can collect user input regarding device preferences related to specified devices to be used to access or to be prohibited or restricted from accessing an account. Information regarding these devices is stored in a database. The system can then assay a device fingerprint for a device to authenticate access by the device to the account based on the device preferences. In some embodiments, input can also be collected regarding alert preferences related to alerts connected with accessing the account from specified devices.