Dynamic Cookie Authentication for Banking Fraud Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for customer devices lack effectiveness in preventing fraud, as they rely on static device attributes that can be easily compromised by fraudsters, leading to potential unauthorized access.

Innovation Solution

The system employs a dynamic approach by sequentially issuing cookies with changing attributes, requiring multi-factor authentication when an old cookie is detected, thereby increasing the time a fraudster needs to steal and use a legitimate cookie, and tracking device attributes across sessions to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static device attributes are used for authentication, then the authentication process is simple and fast, but the security effectiveness is poor and fraudsters can easily compromise the authentication

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by transitioning from static device attributes to dynamic attributes that change over time. The system issues new device attributes (cookies) sequentially and requires re-authentication when old attributes are detected, making the authentication process adaptive and time-dependent rather than static, thereby improving security without requiring complex multi-factor authentication procedures

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of device attributes from static to dynamic by sequentially issuing new attributes and detecting when old ones are used. This parameter change allows the system to maintain simple authentication flow while improving security, as the attributes evolve over time rather than remaining fixed

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multi-factor authentication is implemented, then the security effectiveness is improved, but the authentication process becomes more complex and time-consuming

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-issuing and tracking device attributes before actual authentication events. The system maintains a record of previously issued attributes and proactively detects when old attributes are reused, allowing for automated fraud prevention without requiring additional authentication steps during normal use

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by continuously monitoring for the presence of old device attributes and providing automated responses when they are detected. The system compares current authentication attempts against historical records and automatically triggers re-authentication or blocks access, creating a closed-loop security mechanism that prevents fraud without adding user burden

Inventive Principle:
Principle #23Feedback

3Difficulty of detecting and measuring

If device attributes are tracked across sessions, then the detection of fraudulent usage is improved, but the system complexity and data storage requirements increase

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidsession tracking system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts only the essential device attribute information needed for fraud detection rather than tracking all device data comprehensively. By focusing on specific attributes (such as cookies or device fingerprints) that can be easily stored and compared, the system achieves effective fraud detection without implementing complex comprehensive device monitoring infrastructure

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses copies of device attributes (such as storing hashed versions or fingerprints of cookies) for comparison purposes rather than storing complete device state information. This copying approach allows the system to track and detect fraudulent usage patterns while minimizing data storage requirements and system complexity

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8818906B1Systems and methods for performing authentication of a customer interacting with a banking platform
Publication Date: 2014.08.26 JPMORGAN CHASE BANK NA
  • US8818906B1 patent drawing
  • US8818906B1 patent drawing
  • US8818906B1 patent drawing

AI summary

The invention provides systems and methods of authenticating a customer device, in conjunction with a requested interaction, the customer device associated with a customer, the method performed by an authentication entity processing portion in the form of a tangibly embodied computer. The method may include receiving data from the customer device, the data related to a requested interaction of the customer device with the authentication entity processing portion, the authentication entity processing portion maintained by an authentication entity; inputting a device attribute, from the customer device, that constitutes an observed device attribute; securing a determined device attribute; performing an authentication test including comparing the observed device attribute vis-à-vis the determined device attribute; and based on the comparing, determining whether the authentication test is passed, and (i) outputting approval of the requested interaction and a new device attribute to the customer device, if the authentication test is passed; and (ii) outputting disapproval of the requested interaction, if the authentication test is not passed.