Dynamic Risk Authentication for Mobile Banking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile banking systems face challenges in efficiently evaluating risk for transactions due to the anonymous nature of wireless communications, leading to increased cyber-attacks and the need for improved security measures that are both computationally and energy efficient, while also balancing usability.

Innovation Solution

A system that estimates an aggregated risk value from a set of dependent or independent risk factors using user input, financial institution authentication, risk computation, and transaction session data, incorporating multi-factor authentication methods such as biometric and hard token authentication, and employing GPU computation for efficient risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If stringent security measures such as multi-factor authentication are applied to all transactions, then security reliability is improved, but system usability deteriorates due to unnecessary authentication for low-risk transactions

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic authentication by adjusting authentication requirements based on real-time risk assessment of transactions. The system evaluates multiple risk factors (device characteristics, transaction patterns, location data) and adapts authentication strength accordingly - applying strong multi-factor authentication only when risk thresholds are exceeded, while allowing seamless access for low-risk transactions. This resolves the contradiction by making security measures flexible rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters dynamically based on risk evaluation. It monitors transaction parameters (amount, frequency, time, location) and device parameters (battery level, signal strength, sensor data) to adjust authentication requirements. When risk parameters indicate potential fraud, the system intensifies authentication; when parameters indicate normal behavior, it reduces authentication burden, thus balancing security and usability.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If computationally intensive security measures are implemented, then security evaluation accuracy is improved, but energy consumption increases which is problematic for battery-powered wireless devices

Engineering Contradiction:
Improverisk evaluation accuracyVSAvoidenergy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies partial computation by selectively evaluating only the most relevant risk factors for each transaction context rather than processing all possible factors. The system uses heuristic rules and machine learning models to identify which risk indicators (device sensors, transaction history, location data) are most predictive of fraud in given scenarios, computing only those to achieve accurate risk assessment with minimal energy expenditure.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The risk evaluation system is segmented into multiple processing levels: lightweight rule-based filtering for initial risk screening, intermediate risk factor evaluation for moderate-risk transactions, and intensive machine learning analysis only for high-value or suspicious transactions. This hierarchical segmentation allows the system to maintain high evaluation accuracy while consuming minimal energy for the majority of low-risk transactions.

Inventive Principle:
Principle #1Segmentation

3Reliability

If multiple authentication factors are required for high-value transactions, then security against cyber-attacks is improved, but transaction processing time increases

Engineering Contradiction:
Improvesecurity against cyber-attacksVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication and risk assessment before the actual transaction is initiated. It continuously monitors device characteristics, user behavior patterns, and transaction context in the background, pre-evaluating risk factors and preparing authentication challenges. When a transaction is requested, the system has already gathered relevant security information, enabling rapid authentication decisions without delaying the user experience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback loops where the system continuously learns from transaction outcomes and risk assessments. It analyzes successful and failed authentication attempts, adjusts risk thresholds, and optimizes authentication factor selection based on observed patterns. This feedback mechanism enables the system to reduce authentication complexity over time for trusted users while maintaining security, thereby reducing processing time without compromising protection against cyber-attacks.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10210518B2Risk-link authentication for optimizing decisions of multi-factor authentications
Publication Date: 2019.02.19 ALNAJEM ABDULLAH ABDULAZIZ I
  • US10210518B2 patent drawing
  • US10210518B2 patent drawing
  • US10210518B2 patent drawing

AI summary

A system for evaluating risk in an electronic banking transaction by estimating an aggregated risk value from a set of risk factors that are either dependent or independent of each other, comprising: user input means for enabling an end user to provide authentication information related to a desired electronic banking transaction; financial institution authentication means for authenticating that an end user is authorized to conduct the desired electronic transaction; risk computation means for imposing authentication requirements upon the end user in adaptation to a risk value of the desired banking electronic banking transaction; transaction session means for tracking an amount of time that the desired electronic banking transaction is taking; and financial institution transaction means for storing data related to the desired electronic banking transaction.