Mobile Transaction Risk Engine with Segmented Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile transaction systems face challenges in authenticating users remotely, making them vulnerable to fraud as fraudsters can exploit stolen identities and accounts, especially in faceless transactions initiated through mobile devices.

Innovation Solution

A system comprising an application server, authentication system, and risk determination system that collects and aggregates data from multiple sources to perform multifactor authentication and fraud risk determination, using device data collectors and risk models to verify user identities and detect fraudulent activities in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used in mobile transactions, then user convenience is maintained, but security against fraud is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is divided into multiple independent components: device data collector, authentication system, risk determination system, and transaction system. Each component performs a specific function, allowing the overall system to achieve high security through coordinated operation of specialized subsystems without overwhelming complexity in any single component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary systems and components that bridge different parts of the authentication process. The device data collector acts as an intermediary between the mobile device and the authentication system, while the risk determination system serves as an intermediary that analyzes data before final authentication decisions are made.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multifactor authentication and risk assessment are implemented, then fraud detection capability is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The device data collector continuously gathers device information, identifiers, and characteristics in advance before transactions occur. This preliminary data collection allows the risk determination system to perform rapid assessments during actual transactions without requiring time-consuming data gathering at the moment of transaction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the risk determination system analyzes collected data and provides results back to the authentication system, which then makes informed decisions. This feedback loop enables efficient processing by using pre-analyzed information rather than requiring complex real-time computations for each transaction.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11210670B2Authentication and security for mobile-device transactions
Publication Date: 2021.12.28 EARLY WARNING SERVICES LLC
  • US11210670B2 patent drawing
  • US11210670B2 patent drawing
  • US11210670B2 patent drawing

AI summary

A method including collecting transactional information from a mobile application on the mobile device. The mobile device can be used by a user to initiate an activity at a risk moment. The method also can include aggregating a set of risk signals. The method additionally can include obtaining a first set of risk rules for a model specific to the activity requested by the user. Each risk rule of the first set of risk rules can define weights when the risk rule is triggered based on one or more risk signals of the set of risk signals. The method further can include executing a risk engine using the first set of risk rules for the model and using the set of risk signals to generate a risk score. The risk score can be based on the weights of triggered risk rules of the first set of risk rules. The method additionally can include generating a disposition based on a comparison of the risk score to one or more predefined thresholds scores for the model. Other embodiments of related systems and methods are disclosed.