Dynamic Security Score Authentication for Transaction Risk Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems face challenges in evaluating a user's authenticated state over time, particularly in scenarios requiring higher security, such as payments and profile updates, where additional security measures like second-factor authentication are necessary but difficult to implement effectively.

Innovation Solution

A method that computes a security score based on trust scores associated with various authentication events during a session, with scores degrading over time, allowing for dynamic evaluation of the user's authenticated state and determining whether additional authentication events are required for transactions based on the score's sufficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication mechanisms are implemented for higher security scenarios, then security reliability is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter of authentication evaluation from binary (authenticated/not authenticated) to continuous (security score ranging from 0-100). This allows the system to dynamically adjust authentication requirements based on the computed security score, which aggregates trust scores from multiple authentication events with time-based degradation. This resolves the contradiction by providing fine-grained security control without requiring complex multi-layer authentication flows for every transaction.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic authentication where the required authentication level adapts based on the security score. Instead of static multi-factor authentication requirements, the system dynamically determines whether additional authentication is needed based on the computed security score and transaction risk level. This dynamic approach maintains high security reliability while reducing unnecessary authentication complexity for low-risk transactions.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple authentication mechanisms are implemented for higher security scenarios, then security reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiduser operation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By transforming authentication from a binary state to a continuous security score parameter, the system can operate transparently for users. When the security score is sufficient, no additional user action is required. Only when the score falls below the threshold does the system prompt for additional authentication. This parameter transformation resolves the contradiction by making security evaluation invisible to users during normal operation while maintaining strong security controls.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs self-evaluation of authentication strength by automatically computing security scores based on accumulated trust scores from authentication events. This self-service mechanism eliminates the need for users to manually select or manage multiple authentication methods, as the system autonomously determines the appropriate authentication level based on the computed security score and transaction context.

Inventive Principle:
Principle #25Self-service

3Reliability

If trust scores are maintained indefinitely, then authentication reliability is improved, but loss of time and adaptability deteriorate

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication validity duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic re-evaluation of trust scores through time-based degradation. Each authentication event's trust score decreases over time according to a degradation rate, requiring periodic refreshment of authentication credibility. This periodic decay mechanism resolves the contradiction by automatically invalidating old authentication evidence over time, ensuring authentication reliability remains current without requiring indefinite maintenance of trust scores.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The trust score system is made dynamic through time-based degradation, where authentication reliability automatically adapts to the passage of time. This dynamic approach resolves the contradiction by allowing the system to maintain high authentication reliability for recent events while automatically reducing the weight of older events, thus adapting to changing security requirements without manual intervention or fixed time limits.

Inventive Principle:
Principle #15Dynamics

4Measurement precision

If all authentication events are considered equally, then measurement precision is improved, but adaptability deteriorates

Engineering Contradiction:
Improveauthentication evaluation precisionVSAvoidauthentication requirement adaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by assigning different weights and degradation rates to different types of authentication events based on their security strength. Stronger authentication methods (e.g., biometrics, hardware tokens) receive higher initial trust scores and slower degradation rates, while weaker methods receive lower scores and faster degradation. This local differentiation resolves the contradiction by providing precise measurement of authentication strength while adapting to different security requirements through configurable event-specific parameters.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of authentication evaluation from uniform treatment to differentiated scoring based on authentication event characteristics. By introducing event-type-specific trust scores and degradation rates as adjustable parameters, the system achieves both precise measurement of authentication strength and adaptability to different security scenarios through parameter configuration rather than structural complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12169838B2Communications server apparatus, method and communications system for managing authentication of a user
Publication Date: 2024.12.17 GRAB TECHNOLOGY LLC
  • US12169838B2 patent drawing
  • US12169838B2 patent drawing
  • US12169838B2 patent drawing

AI summary

A communications server apparatus for managing authentication of a user based on one or more authentication events in a session is provided, to, in one or more data records, generate, for each authentication event, data indicative of a trust score corresponding to the authentication event; and generate, data indicative of a security score based on the trust scores corresponding to the one or more authentication events in the session, and, in response to receiving request data indicative of an authentication request associated with the user corresponding to a transaction in the session, the transaction having a value indicator, authenticate the user if the security score satisfies a condition for authentication corresponding to the transaction according to the value indicator, wherein security scores for satisfying the condition are variable according to value indicators of transactions.