Polymorphic Authentication System for Unpredictable Security Challenges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face security risks in protecting customer information and user accounts due to predictable authentication methods, making them vulnerable to scripted, replay, and phishing attacks.

Innovation Solution

Implementing just-in-time polymorphic authentication techniques that dynamically select and vary authentication methods based on time-based, counter-based, external risk, geographic, event-based, and user-specific factors to create unpredictable authentication prompts, thereby enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If predictable authentication methods are used, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system dynamically selects and presents different authentication challenges based on polymorphic factors such as time, counter values, external risks, geography, events, and user-specific characteristics. This makes the authentication process adaptive and unpredictable, preventing attackers from using scripted or replay attacks while still providing a user-friendly experience for legitimate users.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If static authentication prompts are used, then device complexity is reduced, but adaptability is worsened

Engineering Contradiction:
Improveauthentication systemVSAvoidauthentication method
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system changes multiple parameters of the authentication process including the type of challenge presented, the timing of challenges, the sequence of authentication steps, and the selection of authentication methods. These parameter changes are based on polymorphic factors that vary between authentication attempts, allowing the system to adapt to different contexts without requiring complex custom authentication flows for each scenario.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9619643B2Just in time polymorphic authentication
Publication Date: 2017.04.11 BANK OF AMERICA CORP
  • US9619643B2 patent drawing
  • US9619643B2 patent drawing
  • US9619643B2 patent drawing

AI summary

Methods, systems, apparatuses, and computer-readable media for utilizing just-in-time polymorphic authentication techniques to secure information are presented. In one or more embodiments, a computing platform may receive, from a computing device, a request to access a user account. In response to receiving the request to access the user account, the computing platform may dynamically select, based on one or more polymorphic authentication factors, an authentication method for authenticating a user of the computing device, and the authentication method may be selected from a plurality of predefined authentication methods. Subsequently, the computing platform may generate one or more authentication prompts based on the selected authentication method. The computing platform then may provide the one or more authentication prompts to the user of the computing device. The authentication prompts that are selected for and presented to a particular user during a given access attempt may vary across different attempts.