Risk-Based Authentication Directory Server for Fraud Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems for electronic payment networks face challenges such as high costs, limited data access, lack of sophisticated authentication capabilities, and equipment malfunctions in access control servers (ACS), leading to increased fraud and friction in online transactions.

Innovation Solution

A computer-implemented risk-based authentication (RBA) platform that leverages a directory server and engine to generate risk scores and reason codes, embedding this data into authentication requests to enable ACSs to make informed decisions, even if they lack RBA capabilities, using the 3DS 2 Protocol for comprehensive data analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strong consumer authentication (SCA) is implemented for all digital transactions, then fraud is reduced, but transaction friction increases leading to abandoned transactions

Engineering Contradiction:
Improvefraud reductionVSAvoidtransaction friction
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically changes authentication parameters based on risk assessment. Instead of applying uniform SCA to all transactions, the system adjusts authentication requirements according to the calculated risk score, transaction amount, device familiarity, and user behavior patterns. Low-risk transactions proceed with minimal friction while high-risk transactions trigger enhanced authentication.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The authentication system transitions from a static, one-size-fits-all approach to a dynamic, adaptive system. The risk score and authentication requirements are continuously adjusted based on real-time data including device recognition, location, transaction patterns, and user behavior, enabling the system to optimize between security and user experience.

Inventive Principle:
Principle #15Dynamics

2Reliability

If access control servers (ACS) are contracted for authentication services, then authentication capability is provided, but data access is limited and costs increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoiddata access limitation
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The payment network server acts as an intermediary between the ACS and the authentication data sources. It collects comprehensive transaction data from multiple sources including merchant systems, user devices, and historical databases, then processes this data through risk scoring algorithms before presenting enhanced authentication requests to the ACS, thereby overcoming the ACS's limited direct data access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The payment network server performs multiple functions: it collects data from diverse sources, performs risk assessment and scoring, generates authentication requests, and communicates with the ACS. This multi-functional approach consolidates capabilities that would otherwise require separate systems, reducing costs while improving data access.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If access control servers (ACS) are contracted for authentication services, then authentication is performed, but the system becomes expensive for issuers

Engineering Contradiction:
Improveauthentication serviceVSAvoidcost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Instead of requiring full SCA for all transactions, the system applies partial authentication for low-risk transactions and reserves full authentication for high-risk cases. The risk score thresholds are configured to allow a majority of normal transactions to proceed with minimal authentication, reducing the frequency and cost of ACS interactions while maintaining security for problematic transactions.

Inventive Principle:
Principle #16Partial or excessive action

4Measurement precision

If sophisticated authentication procedures are implemented, then authentication accuracy is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional components: data collection from multiple sources, risk scoring algorithms, authentication request generation, and ACS communication. This modular architecture allows each component to be optimized independently and enables the system to achieve high authentication accuracy without proportionally increasing overall complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3588419B1Systems and methods for authenticating online users with an access control server
Publication Date: 2023.11.15 MASTERCARD INT INC
  • EP3588419B1 patent drawingFigure 1
  • EP3588419B1 patent drawingFigure 2
  • EP3588419B1 patent drawingFigure 3

AI summary

A computer-implemented method for authenticating an online user with an access control server (ACS) is provided. The method includes receiving, at a risk-based authentication enabled (RBA-enabled) directory server, an authentication request message including authentication data, extracting, using the RBA-enabled directory server, the authentication data from the authentication request message, transmitting the extracted authentication data to an RBA engine, generating, using the RBA engine, based at least in part on the extracted authentication data, RBA result data including a risk score, a risk analysis, and at least one reason code, transmitting the RBA result data to the RBA-enabled directory server, embedding, using the RBA-enabled directory server, the RBA result data into the authentication request message to generate an enhanced authentication request message, and transmitting the enhanced authentication request message to the ACS to enable the ACS to make an authentication decision based on the RBA result data.