Mobile Device Authentication Automation Using Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-factor authentication schemes increase security but decrease ease of access, as they require user input for each authentication factor, which can be cumbersome and may lead to fraudulent activity if not properly managed.

Innovation Solution

Implementing an unsupervised computer learning module on a mobile device to automate authentication decisions based on various parameters, such as user input and environmental data, without requiring user input for each authentication request, while verifying the authenticity of automated responses through risk scoring mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication requires user input for each authentication factor, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile device automatically responds to authentication requests using unsupervised machine learning without requiring user input. The device monitors its own state and parameters to make authentication decisions autonomously, eliminating the need for manual user intervention while maintaining security through automated risk assessment

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the state of the mobile device by monitoring multiple parameters (location, time, device state) and uses these parameter changes to determine authentication decisions. The unsupervised learning module analyzes patterns in parameter changes to automatically approve or deny authentication requests based on learned behaviors

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If automated authentication responses are implemented without user input, then ease of operation is improved, but reliability deteriorates due to potential fraudulent activity

Engineering Contradiction:
Improveease of accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication server receives the automated response from the mobile device and provides feedback by determining whether the response is authentic based on risk scores. This feedback mechanism allows the system to verify the legitimacy of automated responses and prevent fraudulent activities while maintaining ease of use

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The authentication server acts as an intermediary between the mobile device and the authentication request. It receives automated responses, evaluates them using risk scoring mechanisms, and determines authenticity before allowing access. This intermediary verification step ensures security while preserving the convenience of automated authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If extensive user input is required for authentication, then security is maintained, but loss of time increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The mobile device performs preliminary monitoring and analysis of its state and parameters continuously, building a profile of legitimate usage patterns through unsupervised learning. When an authentication request occurs, the device can immediately respond based on pre-established patterns without requiring real-time user input, significantly reducing authentication time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230244775A1Verification of Automatic Responses to Authentication Requests on Authorized Mobile Devices
Publication Date: 2023.08.03 SALESFORCE INC
  • US20230244775A1 patent drawing
  • US20230244775A1 patent drawing
  • US20230244775A1 patent drawing

AI summary

Techniques are disclosed relating to determining risk associated with automated authentication decisions for a multi-factor authentication scheme. In disclosed embodiments, a server system sends requests corresponding to factors in a current multi-factor authentication procedure to a mobile device. The system receives, from the mobile device, automatically generated responses for the factors, where the responses are automatically generated at the mobile device using a machine learning model based on a current set of parameters for the current procedure and a previous set of parameters for a prior procedure. Based on a current state of the mobile device received with the automatically generated responses and prior states of the mobile device stored at the server computer system, the system determines a risk score for the automatically generated responses. Based on the risk score, the system generates an authorization decision for an authorization request corresponding to the current multi-factor authentication procedure.