Dynamic Identity Authentication Orchestration via Rules Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current fraud prevention methods in identity authentication for financial services and other goods/services are inadequate, as they often rely on expensive custom solutions and fail to adapt effectively to varying environments and device capabilities, leading to authentication failures and increased risk of fraud.

Innovation Solution

The orchestration server and rules engine system, which integrates multiple authentication factors and vendors across various communication channels, dynamically selects the most effective authentication methods based on business rules, device capabilities, and environmental conditions, ensuring flexible and secure authentication experiences without requiring extensive custom solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional identity authentication methods are used, then security against fraud is maintained, but authentication failures increase and customer experience deteriorates

Engineering Contradiction:
Improveauthentication success rateVSAvoidadaptability to varying environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication system dynamically adapts its methodology based on environmental conditions, device capabilities, and risk assessments. The system transitions from static authentication rules to dynamic rule selection, where the authentication approach changes in real-time based on contextual factors such as location, device type, transaction amount, and detected fraud patterns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple parameters simultaneously including authentication threshold levels, required verification factors, time limits for completion, and risk tolerance levels based on environmental conditions. This allows the system to adjust its security posture dynamically rather than using fixed parameters.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If custom authentication solutions are implemented, then fraud prevention capability is improved, but system complexity and cost increase

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs a universal rules engine that can handle multiple authentication methodologies and fraud prevention strategies through a single platform. This engine evaluates various authentication factors and selects appropriate verification methods based on pre-configured rules, eliminating the need for separate custom solutions for different scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The rules engine acts as an intermediary layer between the authentication request and the verification processes. It mediates between multiple authentication factors, device capabilities, and fraud prevention rules, coordinating their interaction to achieve fraud prevention without requiring direct complex integration between all components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple authentication factors are required, then security is improved, but authentication time and customer convenience worsen

Engineering Contradiction:
Improvesecurity levelVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial authentication action by requiring only the necessary number of authentication factors based on risk assessment. For low-risk transactions or familiar devices, fewer factors are required, while high-risk scenarios trigger additional verification steps. This prevents excessive authentication requirements while maintaining adequate security.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system uses real-time feedback from authentication attempts, device responses, and environmental data to dynamically adjust the number and type of authentication factors required. If initial authentication attempts succeed quickly with low risk indicators, the system reduces subsequent verification requirements, creating a feedback loop that balances security with convenience.

Inventive Principle:
Principle #23Feedback

4Reliability

If stringent authentication rules are applied, then fraud detection is improved, but false positives increase and legitimate transactions are blocked

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidtransaction throughput
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different authentication stringency levels to different aspects of the transaction based on local risk characteristics. Rather than applying uniform stringent rules to all transactions, it tailors the authentication depth to specific risk factors such as transaction amount, location, device familiarity, and user behavior patterns, allowing high security where needed and faster processing where risk is low.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The authentication rules dynamically adjust their stringency based on real-time risk assessment. The system monitors transaction patterns, device behavior, and environmental factors, automatically increasing or decreasing authentication requirements during the transaction process rather than applying fixed stringent rules from the start.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10313341B2System and method for identity authentication
Publication Date: 2019.06.04 GENESYS CLOUD SERVICES INC
  • US10313341B2 patent drawing
  • US10313341B2 patent drawing
  • US10313341B2 patent drawing

AI summary

A system, comprising includes an orchestration server including a processor, the orchestration server to receive authentication factors. A rules engine connects with the orchestration server, the orchestration to send the authentication factors to the rules engine and to request a decision on authentication from the rules engine. The rules engine to send the decision on authentication to the orchestration server based on the received authentication factors and a rules set.