Third-Party Authentication Service for Scalable Identity Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication solutions for online consumer applications are not scalable and cost-effective for millions of users, making it difficult to protect consumer identities from identity theft and fraud, especially as more people use computers and mobile devices for online transactions.

Innovation Solution

A network-based authentication and fraud detection system hosted by a third-party service provider that shares intelligence and resources among enterprises, allowing for single authentication credentials and real-time fraud detection across multiple sites without requiring personally identifiable information, using a combination of authentication services and fraud intelligence networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprise authentication solutions are deployed for consumer applications, then security is improved, but cost and scalability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct functional modules: authentication service provider, fraud detection service, and relying parties. This modular architecture allows each component to be independently optimized and scaled, reducing overall system complexity and cost while maintaining enterprise-grade security for consumer applications

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication service provider that mediates between users and relying parties. This intermediary handles authentication and fraud detection centrally, allowing individual enterprises to avoid deploying complex authentication infrastructure while still achieving enterprise-level security through the shared service

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication credentials are required across different sites, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidconvenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal authentication credential that functions across multiple relying parties. The authentication service provider issues credentials that are recognized by any participating site, allowing users to authenticate once and access multiple services without managing separate credentials for each site, thus maintaining security while improving convenience

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If fraud detection requires human intervention, then accuracy is improved, but productivity deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements self-service fraud detection through automated analysis of transaction data, device characteristics, and behavioral patterns. The fraud detection service automatically evaluates transactions and makes decisions without human intervention, achieving both high accuracy through sophisticated algorithms and high productivity through automated processing of large transaction volumes in real-time

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7861286B2System and method for network-based fraud and authentication services
Publication Date: 2010.12.28 GEN DIGITAL INC
  • US7861286B2 patent drawing
  • US7861286B2 patent drawing
  • US7861286B2 patent drawing

AI summary

A system and method for providing identity protection services. According to an embodiment, a validation server receives over a network a response from a credential associated with a user, the credential response provided by the user in order to authenticate the user to one of a plurality of sites on the network that accepts the credential as a factor for authentication, the validation server verifies the credential response on behalf of the one network site, a fraud detection server receives over the network information in connection with a transaction associated with the user at the one network site, and the fraud detection server evaluates the transaction information for suspicious activity based at least in part on information provided to the fraud detection server in connection with one or more transactions at one or more sites on the network other than the one network site.