Dynamic Authentication Level Adjustment for Mobile Banking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in mobile banking lack dynamic adjustment based on user circumstances, leading to potential security vulnerabilities and inconsistent user experience.

Innovation Solution

An authentication bucket system that determines a circumstances score using circumstantial data to assess the appropriateness of the current authentication level, applying weighting factors and sorting rules to dynamically adjust authentication levels, ensuring appropriate access to mobile banking functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication level is fixed for all users, then system complexity is reduced, but security is compromised due to inability to adapt to different circumstances

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system dynamically adjusts the required authentication level based on real-time circumstance analysis. The system evaluates multiple factors including user behavior patterns, device characteristics, location data, and transaction risk indicators to determine the appropriate authentication level for each specific scenario, transforming a static authentication system into a dynamic one that adapts to changing conditions

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameter (authentication level) based on calculated circumstance scores. By modifying the authentication requirement parameter in response to varying circumstance conditions, the system achieves flexible security adaptation without requiring complete system redesign, simply adjusting the authentication level parameter based on real-time analysis

Inventive Principle:
Principle #35Parameter changes

2Reliability

If authentication level is increased for all functions, then security is improved, but user experience deteriorates due to excessive authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different authentication levels to different functions or transactions based on their specific risk profiles and circumstance evaluations. Rather than uniformly applying high authentication to all operations, the system locally adjusts authentication requirements for each specific function or transaction based on its own characteristics and the user's current circumstances, making the system both secure and user-friendly

Inventive Principle:
Principle #3Local quality

3Ease of operation

If authentication level is decreased for convenience, then user experience is improved, but security vulnerabilities increase

Engineering Contradiction:
Improveuser experienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system continuously monitors user behavior, device state, and transaction characteristics, feeding this information back into the circumstance score calculation. This feedback loop enables the system to automatically adjust authentication levels in response to changing conditions, providing convenient access during normal circumstances while automatically increasing security when risk indicators are detected

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9647999B2Authentication level of function bucket based on circumstances
Publication Date: 2017.05.09 BANK OF AMERICA CORP
  • US9647999B2 patent drawing
  • US9647999B2 patent drawing
  • US9647999B2 patent drawing

AI summary

Embodiments are directed to systems, methods and computer program products for assigning a level of authentication to an authentication bucket. Embodiments determine a current level of authentication corresponding to a first authentication bucket comprising a plurality of mobile banking functions; collect a set of circumstantial data corresponding with the apparatus; determine a circumstances score based at least in part on the set of circumstantial data; and determine whether the current level of authentication corresponding to the first authentication bucket is appropriate based at least in part on the circumstances score.