Multi-level Authentication Using Application Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Investigating unauthorized dealings and returning funds in mobile transactions is inefficient, necessitating enhanced authentication to prevent and manage unauthorized activities.

Innovation Solution

A multi-level authentication system that uses application-level data to validate user actions, including a first level of authentication with credentials and a second level through a questionnaire based on extracted application data, to ensure authorized transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used, then the authentication process is simple and quick, but unauthorized transactions cannot be effectively prevented

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is divided into multiple levels: first-level authentication using traditional credentials (password, PIN, or biometrics), and second-level authentication using application-level data verification. This segmentation allows the system to maintain simplicity for basic authentication while adding enhanced security layers when needed, resolving the contradiction between security reliability and process complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of authentication by extracting and verifying application-level data (such as call logs, messaging app data, or other mobile application information) beyond traditional credential verification. This additional dimensional layer of verification enhances security without completely replacing the simple traditional authentication flow, allowing the system to balance both simplicity and security.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If additional authentication layers are implemented, then unauthorized transactions are reduced, but processing time increases

Engineering Contradiction:
Improvetransaction securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements partial authentication action by offering two authentication levels: first-level traditional authentication for standard transactions, and optional second-level application-level verification for higher-risk or suspicious transactions. This partial application of enhanced authentication reduces processing time for routine operations while maintaining strong security when needed, resolving the contradiction between security and time efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The authentication requirements are made dynamic by changing parameters based on transaction characteristics. The system adjusts whether second-level authentication is required based on factors such as transaction amount, user behavior patterns, and risk assessment. This parameter-based approach ensures strong security for high-risk transactions while maintaining fast processing for low-risk operations, balancing security reliability with time efficiency.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10327139B2Multi-level authentication using phone application level data
Publication Date: 2019.06.18 BANK OF AMERICA CORP
  • US10327139B2 patent drawing
  • US10327139B2 patent drawing
  • US10327139B2 patent drawing

AI summary

Embodiments of the present invention provide a multi-level authentication system to provide an additional level of authentication using phone application level data. The system extracts application level data and generates a questionnaire based on the extracted application level data. This questionnaire is transmitted to the device of the user by the system to receive an input related to the questionnaire. The system authorizes a request to execute an action upon validating the input received.