Persistent Authentication for Mobile Banking Calls
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional mobile banking systems require customers to authenticate repeatedly for balance inquiries, leading to a less customer-friendly experience and increased burden on banking staff, as customers often need to share private information and remember lengthy account numbers.
Innovation Solution
A method where customers can enroll their mobile phone number and register accounts through various channels, allowing for immediate authentication and automatic provision of balance information upon subsequent calls, eliminating the need for repeated authentication by linking the communication device to their account profile.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication systems are used where customers must provide personal credentials for every balance inquiry, then security is maintained, but customer service time increases and customer satisfaction decreases
Solution Approach 1:
The system performs preliminary authentication by registering and storing the customer's device identification (phone number) in advance. When the customer calls, the system automatically retrieves and verifies the pre-stored device ID against the database, eliminating the need for real-time credential verification and reducing service time while maintaining security
Solution Approach 2:
The system creates a digital copy of the customer's authentication credentials by storing their device identification in the database. This copy serves as a persistent authentication token that can be automatically verified without requiring the customer to repeatedly provide their actual credentials, thus speeding up the authentication process
2Reliability
If customers are required to authenticate every time they call for balance information, then account security is maintained, but the burden on banking staff increases
Solution Approach 1:
The system enables self-service authentication by automatically verifying the customer's device identification without requiring banking staff intervention. The automated verification process compares the calling device ID against stored records and provides balance information directly, reducing the workload on banking staff while maintaining security through persistent authentication
3Reliability
If traditional verification methods are used requiring customers to share private information, then authentication can be performed, but customer convenience decreases and information security risks increase
Solution Approach 1:
The system extracts and isolates only the essential authentication element (device identification/phone number) from the customer's personal information. By using this extracted identifier for persistent authentication, the system eliminates the need for customers to repeatedly share sensitive private information like social security numbers or account details, improving convenience while reducing information security risks
Data Source
AI summary
Techniques for supporting a mobile financial service that enables a customers to enroll the customer's mobile phone number and register accounts are disclosed. A persistent authentication request is received from a customer, and the customer is authenticated based on authentication information provided by the customer. The customer enters a device identification of the communication device so that the device identification is registered and linked to the customer's profile. When the customer requests non-actionable information (e.g., account balance and transaction history information) by calling a customer service center with a registered communication device, the calling identification is provided to the customer service center by the incoming call. The customer service determines whether the calling identification corresponds to a registered number. If so, the customer service center provides the requested non-actionable information to the communication device without further authentication.


