Dynamic Authentication Challenge System Using Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Standard knowledge-based authentication (KBA) schemes used by financial institutions are vulnerable to fraud as proprietary information can be easily obtained by criminals, and step-up authentication methods like one-time codes are also being compromised.

Innovation Solution

A system that stores account activity data in a secure database, using machine learning to determine authentication scores for challenge questions based on customer interactions, making it difficult for fraudsters to answer correctly and allowing only verified customers to perform high-risk activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard knowledge-based authentication (KBA) schemes are used, then authentication is simple to implement, but security is compromised as proprietary information can be easily obtained by criminals

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static challenge questions into dynamic, adaptive authentication by changing parameters such as question selection, answer validation criteria, and scoring thresholds based on risk assessment and machine learning analysis of customer interactions

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional mechanical KBA systems with a machine learning-based authentication system that automatically analyzes customer interactions, generates challenge questions, and validates answers through computational models rather than static rule-based mechanisms

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If step-up authentication methods like one-time codes are used, then security is improved, but these methods are also being compromised by fraud

Engineering Contradiction:
Improveauthentication securityVSAvoidfraud vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces machine learning models and risk assessment systems as intermediaries between the customer and authentication verification, analyzing patterns in customer interactions to detect fraudulent behavior and validate challenge question answers

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops where machine learning models analyze authentication outcomes and customer interactions to dynamically adjust challenge questions, scoring criteria, and risk thresholds, improving security over time based on observed patterns

Inventive Principle:
Principle #23Feedback

3Measurement precision

If proprietary data is used for challenge questions, then authentication accuracy is improved, but the data can be obtained by fraudsters

Engineering Contradiction:
Improveauthentication accuracyVSAvoiddata breach risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent makes the authentication system dynamic by continuously updating challenge questions and scoring criteria based on real-time analysis of customer interactions, ensuring that proprietary data remains secure while maintaining high authentication accuracy through adaptive question selection

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11790078B2Computer-based systems configured for managing authentication challenge questions in a database and methods of use thereof
Publication Date: 2023.10.17 CAPITAL ONE SERVICES LLC
  • US11790078B2 patent drawing
  • US11790078B2 patent drawing
  • US11790078B2 patent drawing

AI summary

A system and a method are performed by a processor. A set of challenge questions for authenticating a plurality of customers to perform high-risk activities in their respective accounts associated with an entity is received. A machine learning model is used to determine an authentication score for each challenge question in the set and used to rank them. An electronic request on a computing device from an unverified customer who desires to perform a high-risk account activity is received. The unverified customer is authenticated either as a fraudster or a verified customer based on answers to the ranked challenge questions. The processor performs either allowing the verified customer to perform the at least one high-risk account activity with a respective account associated with the verified customer or blocking the fraudster to perform the at least one high-risk account activity.