Messaging Authentication Risk Scoring for Selective Multifactor Operations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing messaging platforms lack integration and multifactor authentication capabilities, leading to unknown messaging activity prior to business engagement, disparate authentication strengths, and potential fraud or repudiation of actions.

Innovation Solution

A system and method for multifactor authentication that assigns an initial risk score upon login, requests additional credentials during a session, and dynamically lowers the risk score to perform operations with external services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a user is authenticated with weak authentication in a messaging system, then the user can access messaging features, but the authentication strength is insufficient for performing actions requiring stronger authentication in integrated services

Engineering Contradiction:
Improvemessaging accessVSAvoidauthentication strength
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic authentication strength adjustment by assigning risk scores to users and dynamically modifying authentication requirements based on the risk score and the specific action being performed. The authentication strength is not fixed but adapts dynamically to the context, allowing weak authentication for low-risk messaging access while requiring stronger authentication for high-risk actions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters by introducing risk scores that quantify authentication strength requirements. Different actions have different risk score thresholds, and the system adjusts authentication requirements by modifying these parameters based on the user's risk score and the requested action, rather than using a fixed authentication level.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multifactor authentication is implemented across all messaging systems, then authentication reliability improves, but system complexity and user burden increase

Engineering Contradiction:
Improveauthentication strengthVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial multifactor authentication by requiring additional credentials only when the user's risk score indicates a need for stronger authentication or when performing high-risk actions. Rather than implementing full multifactor authentication for all users and all actions, the system applies authentication factors partially and selectively based on risk assessment.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The authentication mechanism dynamically adjusts its complexity based on the user's risk score and the specific action being performed. The system starts with a base authentication level and dynamically adds authentication factors only when necessary, rather than requiring all users to go through the same complex multifactor authentication process.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If businesses integrate with multiple messaging platforms, then service accessibility improves, but authentication disparity between platforms causes integration failures

Engineering Contradiction:
Improveplatform integrationVSAvoidauthentication compatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a universal authentication framework that works across multiple messaging platforms by introducing a common risk score system. Different messaging platforms can be integrated without requiring platform-specific authentication adjustments, as the universal risk score mechanism adapts to various platforms while maintaining consistent authentication standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The risk score system acts as an intermediary layer between different messaging platforms and the business services. Rather than directly integrating each platform's authentication mechanism, the risk score intermediary translates and harmonizes authentication strengths across platforms, allowing seamless integration while maintaining authentication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If users are allowed to proceed with actions using initial authentication, then operation speed improves, but fraud risk and action repudiation increase

Engineering Contradiction:
Improveoperation speedVSAvoidfraud risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary risk assessment by assigning risk scores to users before allowing actions to proceed. This preliminary action of evaluating authentication strength and assigning risk scores enables the system to quickly determine whether additional verification is needed, allowing legitimate users to proceed without delay while preventing fraudulent actions before they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The risk score system provides continuous feedback on authentication strength and adjusts authentication requirements accordingly. The system monitors user behavior and risk scores in real-time, providing feedback that dynamically modifies authentication requirements during the session, allowing legitimate operations to proceed quickly while blocking or requesting additional verification for suspicious activities.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12368700B2Multifactor authentication from messaging systems
Publication Date: 2025.07.22 NCR VOYIX CORP
  • US12368700B2 patent drawing
  • US12368700B2 patent drawing
  • US12368700B2 patent drawing

AI summary

A user is assigned an initial risk score during a session with a messaging platform. During the session, the user attempts an operation with an external service. One or more additional authentication factors are requested from the user to dynamically lower the initial risk score. The lowered risk score is processed with the external service to perform the operation on behalf of the user during the session.