Dynamic Authentication Scoring for Internet Banking Fraud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet banking faces challenges in mitigating fraud risks due to inadequate security measures, particularly with single-factor authentication methods that compromise ease of use and convenience, and existing intrusion detection systems often generate false positives, affecting user experience.

Innovation Solution

A method and system that employ a composite scoring system to assess the improbability of login attributes, requiring additional authentication if the score exceeds a threshold, and provide real-time and daily reports on unusual login activity to enhance security without compromising convenience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multifactor authentication or hardware tokens are implemented, then security against fraud is improved, but ease of use and convenience deteriorate

Engineering Contradiction:
Improvesecurity against fraudVSAvoidease of use and convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically analyzes login attributes and calculates improbability scores without requiring user intervention. The system self-determines when additional authentication is needed based on the calculated scores, eliminating the need for users to manually select or configure security measures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes the authentication requirement parameter based on the calculated improbability score. When the score exceeds the threshold, the system transitions from single-factor to multifactor authentication. This dynamic parameter adjustment resolves the contradiction by applying enhanced security only when necessary.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional intrusion detection systems are implemented, then fraud detection capability is improved, but false positive rate increases affecting user experience

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system uses multiple login attributes (IP address, browser ID, time of day, time since last logon) and dynamically calculates improbability scores based on combinations of these parameters. This multi-parameter approach improves fraud detection accuracy while reducing false positives compared to single-parameter detection systems.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system creates a composite improbability score by combining multiple login attributes together. Just as composite materials combine different properties to achieve superior performance, the composite score combines multiple attributes to achieve more accurate fraud detection with fewer false positives.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS8788419B2Method and system for mitigating risk of fraud in internet banking
Publication Date: 2014.07.22 APITURE INC
  • US8788419B2 patent drawing
  • US8788419B2 patent drawing
  • US8788419B2 patent drawing

AI summary

A method and system are provided for mitigating the risk of fraud in Internet banking. In an embodiment comprising an end user seeking access to the Internet banking site of a financial institution, the end user having already satisfied a first authentication requirement (such as providing a valid user ID and password), the end user is required to satisfy a second authentication test when a measure of improbability associated with the login exceeds a threshold. The measure of improbability, in an embodiment, is based on the improbability of a combination of session statistics such as IP address, browser ID, hour of day, and time since the user's last valid login.