Non-Intrusive Privacy-Preserving Authenticator for Dynamic Risk-Based Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods face challenges in providing non-intrusive, privacy-preserving, and adaptive authentication solutions that effectively manage risk based on user environment and location, while ensuring strong security against fraudulent transactions and spoofing attacks.

Innovation Solution

The implementation of a non-intrusive privacy-preserving authenticator (NIPPA) that uses a combination of explicit and non-intrusive authentication techniques, including location-based and behavioral data, to dynamically adjust authentication levels and select appropriate authentication modalities based on risk assessment, without disclosing sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods are used, then security is maintained, but user friction and intrusiveness increase

Engineering Contradiction:
Improveauthentication frictionVSAvoidsecurity assurance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system dynamically adjusts the type and strength of authentication required based on real-time risk assessment. When risk is low, non-intrusive authentication methods are used; when risk increases, stronger authentication mechanisms are automatically invoked, creating a dynamic balance between user convenience and security assurance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of authentication by transitioning between different authentication modes (non-intrusive vs. intrusive) based on environmental factors and risk levels. This parameter change allows the system to adapt authentication strength to match the actual security needs of each transaction context.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If non-intrusive authentication is used, then user privacy is protected, but authentication strength may be insufficient

Engineering Contradiction:
Improveprivacy disclosureVSAvoidauthentication strength
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system introduces an intermediary risk assessment mechanism that evaluates transaction context, user behavior, and environmental factors before determining authentication requirements. This intermediary layer ensures that non-intrusive authentication is only used when appropriate, while automatically escalating to stronger methods when needed, thus protecting privacy without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication strength dynamically adapts based on risk assessment results. The system transitions from non-intrusive to intrusive authentication methods as risk levels change, ensuring that privacy is protected when possible while maintaining adequate authentication strength when security concerns arise.

Inventive Principle:
Principle #15Dynamics

3Reliability

If authentication strength is increased, then security is improved, but user friction increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidauthentication friction
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system changes authentication parameters by adjusting the strength and type of authentication required based on real-time risk assessment. Rather than consistently applying strong authentication, the system modulates parameters to apply appropriate security measures only when necessary, reducing unnecessary user friction while maintaining security assurance.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Authentication strength is made dynamic rather than static. The system automatically adjusts authentication requirements based on transaction context, user behavior patterns, and environmental factors, applying strong authentication only when risk assessment indicates it is necessary, thereby balancing security with user convenience.

Inventive Principle:
Principle #15Dynamics

4Reliability

If location-based authentication is used, then risk assessment is improved, but privacy concerns increase

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidlocation privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system uses location information as one of multiple factors in a comprehensive risk assessment model rather than as a standalone authentication mechanism. The location data is processed through an intermediary risk assessment layer that combines it with behavioral patterns, transaction context, and other factors, thereby improving risk assessment accuracy while minimizing direct exposure of sensitive location privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10091195B2System and method for bootstrapping a user binding
Publication Date: 2018.10.02 NOK NOK LABS INC
  • US10091195B2 patent drawing
  • US10091195B2 patent drawing
  • US10091195B2 patent drawing

AI summary

A system, apparatus, method, and machine readable medium are described for bootstrapping an authenticator. For example, one embodiment of a method comprising: confirming an identity of a user by a first relying party using a first identity verification technique responsive to the user acquiring a device having an authenticator; generating or collecting initial user verification reference data upon verifying the identity of the user through the first identity verification technique; securely providing the initial user verification reference data or data derived from the initial user verification reference data to the authenticator; the authenticator implementing a second identity verification technique by comparing the initial user verification reference data or data derived from the initial user verification reference data to data collected from the user or data collected from a device provided to the user; and providing proof of a successful verification of the identity of the user to a second relying party during a registration request of the authenticator with the second relying party.