Mobile Device Authentication Automation Using Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Multi-factor authentication schemes increase security but decrease ease of access, as they require user input for each authentication factor, which can be cumbersome and may lead to fraudulent activity if not properly managed.
Innovation Solution
Implementing an unsupervised computer learning module on a mobile device to automate authentication decisions based on various parameters, such as user input and environmental data, without requiring user input for each authentication request, while verifying the authenticity of automated responses through risk scoring mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-factor authentication requires user input for each authentication factor, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The mobile device automatically responds to authentication requests using unsupervised machine learning without requiring user input. The device monitors its own state and parameters to make authentication decisions autonomously, eliminating the need for manual user intervention while maintaining security through automated risk assessment
Solution Approach 2:
The system changes the state of the mobile device by monitoring multiple parameters (location, time, device state) and uses these parameter changes to determine authentication decisions. The unsupervised learning module analyzes patterns in parameter changes to automatically approve or deny authentication requests based on learned behaviors
2Ease of operation
If automated authentication responses are implemented without user input, then ease of operation is improved, but reliability deteriorates due to potential fraudulent activity
Solution Approach 1:
The authentication server receives the automated response from the mobile device and provides feedback by determining whether the response is authentic based on risk scores. This feedback mechanism allows the system to verify the legitimacy of automated responses and prevent fraudulent activities while maintaining ease of use
Solution Approach 2:
The authentication server acts as an intermediary between the mobile device and the authentication request. It receives automated responses, evaluates them using risk scoring mechanisms, and determines authenticity before allowing access. This intermediary verification step ensures security while preserving the convenience of automated authentication
3Reliability
If extensive user input is required for authentication, then security is maintained, but loss of time increases
Solution Approach 1:
The mobile device performs preliminary monitoring and analysis of its state and parameters continuously, building a profile of legitimate usage patterns through unsupervised learning. When an authentication request occurs, the device can immediately respond based on pre-established patterns without requiring real-time user input, significantly reducing authentication time while maintaining security
Data Source
AI summary
Techniques are disclosed relating to determining risk associated with automated authentication decisions for a multi-factor authentication scheme. In disclosed embodiments, a server system sends requests corresponding to factors in a current multi-factor authentication procedure to a mobile device. The system receives, from the mobile device, automatically generated responses for the factors, where the responses are automatically generated at the mobile device using a machine learning model based on a current set of parameters for the current procedure and a previous set of parameters for a prior procedure. Based on a current state of the mobile device received with the automatically generated responses and prior states of the mobile device stored at the server computer system, the system determines a risk score for the automatically generated responses. Based on the risk score, the system generates an authorization decision for an authorization request corresponding to the current multi-factor authentication procedure.


