Dynamic Authentication Engine for Financial Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing customer authentication methods, such as static and semi-static out-of-wallet questions, are ineffective in preventing identity theft and misrepresentation, especially in online and mobile banking, as they can be easily guessed or obtained by others, and are costly to implement.

Innovation Solution

A dynamic authentication system that generates behavioral, historical, and transaction-based out-of-wallet questions constantly changing, using a processor to access customer account information and determine risk ratings for each authentication request, ensuring unique questions are asked each time and based on real-time data or third-party information when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static and semi-static out-of-wallet questions are used for authentication, then implementation cost is reduced and simplicity is improved, but security effectiveness deteriorates because answers can be easily guessed or obtained by others

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication questions that change based on real-time account activity, transaction history, and behavioral patterns. Instead of static questions with fixed answers, the system generates unique questions for each authentication attempt based on current account state, making it difficult for thieves to obtain valid answers through information gathering.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of authentication questions based on account risk ratings, transaction types, and user behavior patterns. Questions are dynamically adjusted in terms of content, difficulty, and timing, transforming the authentication process from a fixed state to a variable state that adapts to different security contexts.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic authentication questions based on real-time account information are implemented, then security effectiveness is improved, but implementation cost and system complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem implementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system uses the account holder's own transaction history and account data to generate authentication questions, eliminating the need for external question databases or third-party services. The account information itself becomes the source of authentication challenges, reducing external dependencies and implementation costs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication system leverages existing account management infrastructure and transaction processing systems to generate authentication questions, making the same data serve dual purposes: transaction recording and security verification. This multi-functionality reduces the need for separate authentication data collection systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If authentication questions are changed for each request, then protection against identity theft is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveidentity theft riskVSAvoidauthentication processing time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system pre-generates pools of potential authentication questions based on account history and transaction patterns, so that when authentication is needed, questions can be quickly selected and presented without extensive real-time computation. This preliminary preparation reduces authentication latency while maintaining dynamic security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies different levels of authentication complexity based on the specific account, transaction type, and risk assessment. Not all authentication requests require equally complex or time-consuming question generation, allowing low-risk transactions to use simpler verification while reserving dynamic question generation for higher-risk scenarios.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8745698B1Dynamic authentication engine
Publication Date: 2014.06.03 BANK OF AMERICA CORP
  • US8745698B1 patent drawing
  • US8745698B1 patent drawing
  • US8745698B1 patent drawing

AI summary

Embodiments of the invention relate to apparatuses and methods for identity verification. For example, in one embodiment, a financial institution has a system to generate authentication questions to be used when authenticating a customer when the customer is trying to access and/or use the customer's account. The authentication system is configured to ask one or more authentication questions each time the customer tries to access or use the account, where the authentication questions are generally out-of-wallet questions that constantly change from one authentication attempt to the next. For example, in one embodiment, the questions include behavioral, historical, and transaction based questions generated from information available about a customer's financial account. In some embodiments, the authentication engine is configured to generate authentication questions based at least partially on a risk rating associated with the authentication request and/or on the communication channel from which the request is received.