Local Authentication Device Risk Score Computation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication techniques expose sensitive user information, such as location and biometric data, to insecure networks during the authentication process, compromising privacy.

Innovation Solution

A local authentication device computes a risk score using predictor values from an electronic device and sends this score to a remote server, rather than transmitting sensitive data, thereby reducing exposure to insecure networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If transaction data is sent to a remote authentication server for authentication, then authentication can be performed, but sensitive user information is exposed over insecure networks

Engineering Contradiction:
Improveauthentication securityVSAvoidinformation exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential authentication elements (username, password, OTP) from the complete transaction data, sending only these minimal necessary elements to the remote authentication server. This extraction principle reduces information exposure by transmitting only what is strictly required for authentication verification, leaving sensitive transaction details local to the user's device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication server as an intermediary that performs verification without needing to access complete transaction data. The server acts as a mediator that receives authentication credentials, verifies them against stored data, and returns authentication results, thereby eliminating the need to transmit sensitive transaction information over the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complete transaction data is transmitted for authentication verification, then comprehensive security checking is possible, but network security risks increase

Engineering Contradiction:
Improvesecurity verificationVSAvoidnetwork exposure risk
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system extracts and transmits only the critical authentication components (credentials and OTP) rather than complete transaction data. This selective extraction maintains sufficient security verification capability while minimizing network exposure, as the extracted elements are the minimum necessary for authentication purposes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by transmitting a subset of data (authentication credentials only) rather than the complete transaction dataset. This partial transmission approach provides adequate security verification for authentication while reducing the overall risk exposure proportionally to the reduced data volume transmitted over the network.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9160742B1Localized risk analytics for user authentication
Publication Date: 2015.10.13 EMC IP HLDG CO LLC
  • US9160742B1 patent drawing
  • US9160742B1 patent drawing
  • US9160742B1 patent drawing

AI summary

An improved technique involves sending a user's authentication information to a local authentication device that computes a risk score and sends the risk score to a remote authentication server that determines whether the user is able to be authenticated. When the user makes an authentication or transaction request from an electronic device such as a computer or smartphone, the electronic device sends predictor values such as geo location and wireless signal strength to the local authentication device. The local authentication device then computes a risk score based on the received predictor values and historical predictor values. The local authentication device sends this risk score to a remote authentication server which determines from this risk score and other factors whether the user is able to be authenticated.