Nodal Random Authentication for Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems in transaction processing often face a trade-off between usability and security, where enhanced security measures can be cumbersome and expensive, and are vulnerable to attacks by automated malware that exploit predictable authentication patterns.

Innovation Solution

An authentication module that randomly selects nodes for re-authentication, weighting them based on risk factors or randomly, requiring re-authentication only when the cumulative weight exceeds a threshold, to dynamically enhance security without noticeable user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication systems use fixed authentication points (login and password only), then usability is maintained, but security is insufficient against automated malware attacks

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic authentication by randomly selecting authentication nodes during user sessions rather than using fixed authentication points. The authentication module dynamically determines which nodes require re-authentication based on random selection and risk factor weighting, making the authentication process adaptive and unpredictable to malware attacks while maintaining usability for legitimate users

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary risk assessment and random node selection during login events, pre-weighting nodes before user traversal. This preliminary action establishes the authentication framework in advance, allowing the system to quickly enforce security decisions during actual user interactions without noticeable delays

Inventive Principle:
Principle #10Preliminary action

2Reliability

If re-authentication is required at every node, then security is maximized, but user experience deteriorates and system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial action by requiring re-authentication only at selectively chosen nodes rather than at every node. The authentication module randomly selects specific nodes for re-authentication based on risk factor weighting, implementing security measures partially rather than universally, which reduces system complexity and improves user experience while maintaining adequate security

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes the parameter of authentication frequency from fixed (at every node) to variable (randomly selected nodes based on risk weights). By dynamically adjusting which nodes require re-authentication based on weighted risk factors and random selection, the system optimizes the balance between security and complexity

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If authentication patterns are predictable (fixed login and password points), then system simplicity is maintained, but vulnerability to automated attacks increases

Engineering Contradiction:
Improvesystem simplicityVSAvoidvulnerability to attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces asymmetry by breaking the symmetric, predictable authentication pattern (login → password → access) into an asymmetric, unpredictable sequence. The authentication module randomly selects which nodes require re-authentication, creating an asymmetric authentication flow that varies for each user session, thereby eliminating predictable patterns that malware could exploit while maintaining system simplicity

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS9560030B2Nodal random authentication
Publication Date: 2017.01.31 KAISER FOUNDATION HOSPITALS
  • US9560030B2 patent drawing
  • US9560030B2 patent drawing
  • US9560030B2 patent drawing

AI summary

Systems, methods, and computer program products related to transaction application security are disclosed. In a particular embodiment, application nodes are randomly selected for requiring re-authentication of a user traversing nodes of the application. These and other embodiments are more fully disclosed herein.