Dynamic Challenge-Response Authentication for Online Fraud Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

E-commerce merchants face challenges in authenticating cardholders for online transactions, as they cannot verify possession or authorization of transaction cards, leading to increased fraudulent activities.

Innovation Solution

Implementing a challenge-response authentication system that integrates with password-based systems, using static, semi-dynamic, and dynamic questions based on transaction risk factors, device information, and transaction history to authenticate cardholders in real-time, reducing fraud and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based authentication is used, then the authentication process is simple, but it cannot effectively prevent fraudulent activities

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic challenge-response questions that adapt based on transaction risk factors, device information, and transaction history. The authentication system dynamically adjusts the type and complexity of challenges presented to cardholders, moving from static password verification to dynamic contextual authentication that responds to real-time risk assessments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where transaction outcomes, device information, and authentication patterns are continuously analyzed to improve future authentication decisions. The system learns from past transactions and adjusts challenge selection and risk thresholds based on accumulated data, creating a self-improving authentication mechanism.

Inventive Principle:
Principle #23Feedback

2Reliability

If challenge-response authentication is implemented, then fraud detection capability improves, but the authentication process time increases

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidauthentication process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies challenge-response authentication selectively rather than universally. Low-risk transactions may receive simplified or no challenges, while high-risk transactions receive more rigorous authentication. This partial application of authentication measures reduces overall processing time while maintaining security for problematic transactions.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes authentication parameters dynamically based on risk assessment. Challenge difficulty, number of challenges, and verification stringency are adjusted as parameters based on transaction characteristics, device familiarity, and historical patterns, optimizing the balance between security and speed.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple authentication factors are verified, then authentication security improves, but the ease of operation decreases

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts the number and type of authentication factors required based on real-time risk assessment. Familiar devices and low-risk transactions may require only simple verification, while unfamiliar devices or high-risk transactions trigger additional challenges. This dynamic adaptation maintains security while preserving user convenience for legitimate transactions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses automatically collected device information, transaction history, and behavioral patterns to perform risk assessment without requiring users to manually provide additional information. The authentication system serves itself by gathering necessary data passively and making intelligent decisions about verification requirements.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9898740B2Online challenge-response
Publication Date: 2018.02.20 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US9898740B2 patent drawing
  • US9898740B2 patent drawing
  • US9898740B2 patent drawing

AI summary

Embodiments of the invention enable cardholders conducting an online transaction to be authenticated in real-time using a challenge-response application. The challenge-response application can be administered by an issuer or by a third party on-behalf-of an issuer. A challenge question can be presented to the cardholder, and the cardholder's response can be verified. The challenge question presented can be selected based on an analysis of the risk of the transaction and potentially other factors. A variety of dynamic challenge questions can be used without the need for the cardholder to enroll into the program. Additionally, there are many flexible implementation options of the challenge-response application that can be adjusted based on factors such as the location of the merchant or the location of the consumer.