Mobile Banking Authentication Bucketing for Security-Convenience Trade-offs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures for personal information, particularly in financial institutions, lack an efficient method to dynamically adjust authentication levels based on user behavior, location, and transaction patterns, leading to potential vulnerabilities in accessing sensitive mobile banking functions.
Innovation Solution
Implementing a system that sorts mobile banking functions into authentication buckets based on a continuum of authentication levels, where each bucket corresponds to specific authentication requirements, which can be dynamically adjusted based on user behavior, location, and transaction patterns, ensuring appropriate security levels for various functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single high-level authentication method is applied to all mobile banking functions, then security for sensitive functions is improved, but user convenience and ease of operation deteriorate due to overly stringent requirements for all functions
Solution Approach 1:
The patent segments mobile banking functions into multiple authentication buckets based on risk levels and sensitivity. Each bucket has its own authentication requirements, allowing low-risk functions to use simpler authentication while high-risk functions use stricter authentication. This segmentation resolves the contradiction by applying differentiated security measures rather than a blanket approach.
Solution Approach 2:
The patent implements local quality by assigning different authentication strengths to different functions based on their specific security needs. Critical functions like fund transfers require multi-factor authentication, while less critical functions like viewing balances use simpler authentication. This ensures security is strengthened where needed without unnecessarily complicating user interaction elsewhere.
2Reliability
If multiple authentication methods are required for all functions, then security is improved, but device complexity and system complexity increase
Solution Approach 1:
The patent implements dynamic authentication where the system automatically adjusts the authentication method and strength based on the requested function, user behavior patterns, location data, and transaction history. This dynamic approach allows the system to use simple authentication when appropriate and complex authentication only when necessary, avoiding permanent system complexity while maintaining security.
Solution Approach 2:
The patent changes authentication parameters dynamically based on risk assessment. Factors such as location consistency, transaction amount, time of day, and user behavior patterns modify the authentication requirements in real-time. This parameter-based approach allows the system to maintain security through multiple authentication methods without requiring all methods to be always active, thus managing system complexity.
3Reliability
If authentication requirements are dynamically adjusted based on user behavior and location, then security is improved through contextual awareness, but difficulty of detecting and measuring increases
Solution Approach 1:
The patent implements feedback mechanisms where the system continuously monitors user behavior, location data, and transaction patterns to dynamically adjust authentication requirements. The system provides feedback to users about why certain authentication methods are required and allows users to review and contest the assessment. This feedback loop makes the complex detection and measurement processes more transparent and manageable.
Data Source
AI summary
Embodiments are directed to systems, methods and computer program products for sorting mobile banking functions into authentication buckets. Embodiments determine, for each of a plurality of mobile banking functions, a corresponding authentication buckets, where each authentication bucket corresponds with a level of authentication. Some embodiments receive a request, from a user, to access a function; access the plurality of authentication buckets to determine which of the authentication buckets corresponds with the requested function; determine the level of authentication associated with the determined authentication bucket; determine which authentication types are associated with the level of authentication; request authentication credentials corresponding to the authentication types; receive authentication credentials from the user; validate the authentication credentials, thereby resulting in a successful validation of the authentication credentials; and, in response to the successful validation of the authentication credentials, enable access to the function requested by the user.


