Risk-Based Authentication Directory Server for Fraud Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems for electronic payment networks face challenges such as high costs, limited data access, lack of sophisticated authentication capabilities, and equipment malfunctions in access control servers (ACS), leading to increased fraud and friction in online transactions.
Innovation Solution
A computer-implemented risk-based authentication (RBA) platform that leverages a directory server and engine to generate risk scores and reason codes, embedding this data into authentication requests to enable ACSs to make informed decisions, even if they lack RBA capabilities, using the 3DS 2 Protocol for comprehensive data analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If strong consumer authentication (SCA) is implemented for all digital transactions, then fraud is reduced, but transaction friction increases leading to abandoned transactions
Solution Approach 1:
The system dynamically changes authentication parameters based on risk assessment. Instead of applying uniform SCA to all transactions, the system adjusts authentication requirements according to the calculated risk score, transaction amount, device familiarity, and user behavior patterns. Low-risk transactions proceed with minimal friction while high-risk transactions trigger enhanced authentication.
Solution Approach 2:
The authentication system transitions from a static, one-size-fits-all approach to a dynamic, adaptive system. The risk score and authentication requirements are continuously adjusted based on real-time data including device recognition, location, transaction patterns, and user behavior, enabling the system to optimize between security and user experience.
2Reliability
If access control servers (ACS) are contracted for authentication services, then authentication capability is provided, but data access is limited and costs increase
Solution Approach 1:
The payment network server acts as an intermediary between the ACS and the authentication data sources. It collects comprehensive transaction data from multiple sources including merchant systems, user devices, and historical databases, then processes this data through risk scoring algorithms before presenting enhanced authentication requests to the ACS, thereby overcoming the ACS's limited direct data access.
Solution Approach 2:
The payment network server performs multiple functions: it collects data from diverse sources, performs risk assessment and scoring, generates authentication requests, and communicates with the ACS. This multi-functional approach consolidates capabilities that would otherwise require separate systems, reducing costs while improving data access.
3Reliability
If access control servers (ACS) are contracted for authentication services, then authentication is performed, but the system becomes expensive for issuers
Solution Approach 1:
Instead of requiring full SCA for all transactions, the system applies partial authentication for low-risk transactions and reserves full authentication for high-risk cases. The risk score thresholds are configured to allow a majority of normal transactions to proceed with minimal authentication, reducing the frequency and cost of ACS interactions while maintaining security for problematic transactions.
4Measurement precision
If sophisticated authentication procedures are implemented, then authentication accuracy is improved, but device complexity increases
Solution Approach 1:
The authentication system is segmented into distinct functional components: data collection from multiple sources, risk scoring algorithms, authentication request generation, and ACS communication. This modular architecture allows each component to be optimized independently and enables the system to achieve high authentication accuracy without proportionally increasing overall complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A computer-implemented method for authenticating an online user with an access control server (ACS) is provided. The method includes receiving, at a risk-based authentication enabled (RBA-enabled) directory server, an authentication request message including authentication data, extracting, using the RBA-enabled directory server, the authentication data from the authentication request message, transmitting the extracted authentication data to an RBA engine, generating, using the RBA engine, based at least in part on the extracted authentication data, RBA result data including a risk score, a risk analysis, and at least one reason code, transmitting the RBA result data to the RBA-enabled directory server, embedding, using the RBA-enabled directory server, the RBA result data into the authentication request message to generate an enhanced authentication request message, and transmitting the enhanced authentication request message to the ACS to enable the ACS to make an authentication decision based on the RBA result data.