Mobile Authentication Infrastructure for Dynamic Risk-Based Challenges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems are not dynamic, flexible, or adaptable, leading to excessive and iterative authentication processes that require users to respond to multiple challenges, thus sacrificing convenience for security or vice versa, without considering varying levels of authentication assurance needed for different types of communications.

Innovation Solution

A client-side mobile application authentication infrastructure that integrates a framework with components for interpreting and translating server-side challenges, coordinating user interactions, queuing authentication requests, and determining efficient response plans, thereby reducing redundant user inputs and maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication systems require users to provide extensive identifying information for every access request, then security is improved, but user convenience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system dynamically adjusts the level of authentication required based on the risk assessment of each communication request. Low-risk communications (e.g., viewing public information) require minimal authentication, while high-risk communications (e.g., sensitive transactions) require stronger authentication. This dynamic adaptation resolves the contradiction by making authentication requirements flexible rather than static, maintaining security for high-risk operations while improving convenience for low-risk operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameters (level of assurance required) based on the type of communication and risk assessment. Different authentication levels are applied to different communication scenarios, allowing the system to maintain high security where needed while reducing authentication burdens where appropriate, thus resolving the contradiction between security and convenience.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If authentication systems require multiple challenges and iterative verification processes, then security is improved, but authentication time and user effort increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary risk assessment and authentication level determination before the actual authentication process. By pre-evaluating the communication request and determining the appropriate authentication level in advance, the system avoids unnecessary iterative challenges and verification steps, reducing authentication time while maintaining appropriate security levels.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies only the necessary level of authentication for each specific communication request rather than always applying maximum authentication. For low-risk communications, partial authentication is sufficient, avoiding excessive verification steps and reducing authentication time while maintaining adequate security.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If authentication systems apply uniform high-level verification to all communications, then security is improved, but system flexibility and adaptability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies different authentication levels to different communication scenarios based on their specific risk profiles. Rather than uniform high-level verification, each communication request receives the appropriate level of authentication tailored to its local context and risk assessment, maintaining security where needed while providing flexibility for low-risk operations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The authentication requirement is dynamic and adapts to the specific communication request. The system can adjust authentication levels in real-time based on the type of communication, user profile, and risk assessment, providing both security and flexibility rather than rigid uniform verification.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12363089B1Mobile application authentication infrastructure
Publication Date: 2025.07.15 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US12363089B1 patent drawing
  • US12363089B1 patent drawing
  • US12363089B1 patent drawing

AI summary

Various embodiments of the present technology generally relate to authentication. More specifically, some embodiments relate to systems and methods for mobile application infrastructure and framework for application authentication. Currently, methods and systems for authentication are not flexible or dynamic and over-authentication has become a solution because it is cheap and easy. In contrast, in accordance with some embodiments of this application, the methods and systems can analyze authentication challenges and non-authentication challenges received from a server over a network in a client side infrastructure. The client side infrastructure can determine a customized, flexible, and dynamic plan for responding to authentication challenges in manner that avoids over-authentication on the client side.