Location-Based Authentication Using Transaction Granularity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-factor authentication techniques are vulnerable to attacks, as secondary authentication information can be intercepted or obtained by malicious actors, and rely on information that may be readily available through searches or social engineering, making them prone to fraudulent activities.

Innovation Solution

A system and method for multi-factor authentication using location data, where first location data associated with transactions is analyzed using a machine learning model to identify second location data with higher granularity, generating authentication queries based on this data to verify access attempts, thereby enhancing security by requiring specific location information known only to the user who performed the transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional multi-factor authentication is used, then account access can be verified, but the system is vulnerable to attacks where secondary authentication information can be intercepted or obtained through searches and social engineering

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to interception and social engineering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the location information from transaction records and uses it as a separate authentication factor. The system identifies physical locations associated with exchanges from records, then uses these extracted location data points to generate authentication queries that are not derivable from the records themselves, removing the vulnerability to interception of traditional secondary authentication information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter of authentication from traditional secrets (passwords, tokens) to location-based verification. By transforming the authentication mechanism to rely on physical location data derived from transaction patterns, the system alters the fundamental parameter being verified, making it resistant to traditional attacks while maintaining security.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If location data with high granularity is used for authentication, then security is significantly improved, but the system complexity increases due to machine learning model requirements

Engineering Contradiction:
Improveaccount securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-processing transaction records to identify and store location information associated with exchanges before authentication is needed. The machine learning model analyzes historical transaction data in advance to extract meaningful location patterns, so that when authentication is required, the system can quickly generate location-based queries without complex real-time processing.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If detailed location information is required for authentication, then only the physical user can answer correctly, but obtaining and processing this data becomes more complex

Engineering Contradiction:
Improveauthentication accuracyVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a copy of the location information from transaction records and uses this copied data to generate authentication queries. Instead of requiring direct access to detailed transaction data or complex verification processes, the system extracts and copies relevant location information, transforming it into authentication questions that verify physical presence without exposing sensitive underlying data.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20240095740A1Multi-factor authentication using location data
Publication Date: 2024.03.21 CAPITAL ONE SERVICES LLC
  • US20240095740A1 patent drawing
  • US20240095740A1 patent drawing
  • US20240095740A1 patent drawing

AI summary

In some implementations, a device may obtain first location data associated with one or more exchanges, where the first location data is associated with a first level of granularity. The device may determine second location data associated with the one or more exchanges based on records associated with the one or more exchanges, where the second location data is associated with a second level of granularity that is higher than the first level of granularity. The device may detect an authentication event associated with an access attempt to the account. The device may provide, based on detecting the authentication event, one or more authentication queries that are based on the second location data. The device may authenticate the access attempt to the account based on one or more responses to the one or more authentication queries.