Risk-Based Authentication System with Dynamic Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems face challenges in balancing security and convenience, often requiring excessive identifying information for low-risk activities and struggling to adapt to varying user behaviors and channels of interaction, leading to inefficient user access and potential security breaches.

Innovation Solution

A scalable, risk-based authentication system that employs multiple fraud monitoring engines to analyze user and organizational data, generating risk indicators which are then used to create an authentication plan that dynamically adjusts the level of verification required based on user behavior, device assessment, and activity risk, allowing for passive or active authentication methods across various channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication systems require users to provide login, password, and secret questions for all activities, then security is improved, but user convenience deteriorates due to excessive authentication steps for low-risk activities

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system dynamically adjusts the level of verification required based on real-time risk assessment. Multiple fraud monitoring engines continuously evaluate user behavior patterns, device characteristics, and activity context to generate risk scores. When risk is low, minimal authentication is required; when risk increases, additional verification steps are automatically triggered. This dynamic approach resolves the contradiction by making security adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of authentication strength based on risk level. Instead of always requiring full authentication (login, password, secret questions), the system modifies the authentication requirements according to the assessed risk. Low-risk activities may only require device recognition or behavioral biometrics, while high-risk activities trigger enhanced verification. This parameter change allows the system to maintain security while improving convenience for legitimate low-risk operations.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If authentication requirements are reduced for low-risk activities, then user convenience is improved, but security may deteriorate if risk assessment is inaccurate

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary risk assessment before allowing reduced authentication. Multiple fraud monitoring engines proactively analyze user behavior patterns, device fingerprints, and activity context in advance to establish a baseline risk level. This preliminary action ensures that convenience measures are only applied when risk is genuinely low, preventing security deterioration. The system prepares risk scores and authentication recommendations beforehand, so that when low-risk activities are detected, the appropriate reduced verification can be safely applied.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple fraud monitoring engines are deployed to accurately assess user risk, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent fraud monitoring engines, each responsible for specific risk assessment functions. One engine monitors user behavior patterns, another analyzes device characteristics, a third evaluates activity context, and others assess social network relationships. This segmentation allows the system to achieve comprehensive security through specialized components rather than a monolithic complex system. Each engine operates independently and contributes to the overall risk score, making the complexity manageable and modular.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The multiple fraud monitoring engines share a common architecture and risk aggregation framework that processes their outputs uniformly. Despite monitoring different aspects (behavior, device, social network, activity context), all engines feed into a centralized risk scoring system that synthesizes their findings. This multi-functionality approach allows the system to maintain security through diverse monitoring capabilities while reducing overall complexity through shared processing infrastructure and standardized risk evaluation methods.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If authentication plans are dynamically generated based on risk indicators, then adaptability to varying user behaviors and channels is improved, but processing time increases

Engineering Contradiction:
Improveadaptability to user behaviorVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary risk assessment and generates authentication plan recommendations in advance, before the user actually needs to authenticate. Fraud monitoring engines continuously analyze user behavior patterns and device characteristics in the background, maintaining up-to-date risk scores. When authentication is needed, the pre-computed risk indicators and recommended authentication plans are immediately available, minimizing processing time. This preliminary action allows the system to be both adaptive and fast.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The fraud monitoring engines operate continuously in the background, constantly gathering and analyzing data about user behavior, device characteristics, and activity context. This continuous monitoring ensures that risk assessments are always current and accurate, allowing the system to quickly generate appropriate authentication plans when needed. The useful action of risk assessment never stops, so when authentication is required, the system can immediately leverage the continuously updated information without significant processing delays.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12177200B1Scalable risk-based authentication methods and systems
Publication Date: 2024.12.24 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US12177200B1 patent drawing
  • US12177200B1 patent drawing
  • US12177200B1 patent drawing

AI summary

The disclosure describes a scalable, risk-based authentication system including a plurality of fraud monitoring engines configured to: analyze user data and organization data, and generate a set of risk factors based on the user data and the enterprise data; a risk aggregator in communication with the plurality of fraud monitoring engines configured to: receive the set of risk factors, and transform the set of risk factors into risk indicators; and an authentication engine configured to: receive the risk indicators from the risk aggregator, and generate an authentication plan for a requested activity based on the risk indicators and the requested activity.