Adaptive Multi-factor Authentication (MFA) in BFSI

Date:

Trending

- Advertisement -

A few months back (just after the Covid pandemic had started) an important change was implemented by a popular retail US Bank, Bank of America.  This was regarding how their retail net-banking customers would be logging into their banking account.  

All users of this bank can now set up an additional security measure during login in the form of a one-time authorization code, that would be sent to their registered mobile.  This will be in addition to their user id and password.  In the case of some users who are deemed to have a security risk during login (due to their high-risk score presumably arrived due to their inconsistent login patterns), this process has been made mandatory.  

- Advertisement -

Since the bank had suspected that post-covid the number of internet logins and transactions is going to be high, they probably implemented these changes to protect attempts to hijack genuine customer accounts by fraudulent means by hackers.

- Advertisement -

This shows that the era of Multi-Factor Authentication (MFA) has truly arrived and is here to stay.  Previously MFA was used only when bank transactions were performed by users, but now they are required even during the login process.  

The bank was using security questions as a second factor, but now probably had deemed that as risky, as typical user answers for popular security questions of theirs, can be lifted from their social media accounts by hackers.  

- Advertisement -

So where does this lead to?  Probably, to the next stage of MFA, which is Adaptive MFA in BFSI.  

What is Adaptive MFA? 

When a user login into a bank, several patterns about the login can be measured by the bank.  They can use this data to protect the customer from phishing and other hacker attacks. Like the typical time of the day the user logs in, the network & computer the login happens from, the Geolocation (GPS location) the user logs in from, the time they typically spend during the login, the type of transactions they normally perform, etc.  

With this wealth of data in-store, the banks can now assign risk scores for each activity through AI (Artificial Intelligence) and ML (Machine Learning) methods. If during any login there is an abnormal risk score detected for the user, an adaptive MFA authentication can be triggered.  That is, the user during that login session would be made to go through additional factors of authentication as part of their MFA Auth, for example, an OTP coupled with a Push based authentication sent through to the user’s mobile app, plus a security question or even a phone call based verification.  This helps to control or even eliminate the fraudulent access by a hacker, as it begins to happen.

How this prevents fraud?

During adaptive authentication, the key element to note is most of the factors that are used for authentication are instantly generated, so the hacker would not be knowing all the details of the authentication sequence and credentials in advance, for them to execute a phishing attack on the authenticated session of the user.  Even the user would not know these in advance for the hackers to target gullible users to get credentials from them, before the login.

What are the other adaptive authentication factors that can come into play?

MFA is normally performed by:

•    factors that the users know (passwords, security questions, pre-stored user-approved picture patterns and code numbers),

•    factors the users have (like OTP, mobile push authentication, google authentication) and 

•    factors that define who the users are (biometric authentications like retina scan, fingerprints, facial recognition).  

Out of these the first set of factors “the one the users know” are under severe attack by the hackers.  Hence banks will resort slowly to the second and third categories of authentications mentioned above.  These two categories of factors will be hard to pry out or reproduce like the passwords or security questions, for the reasons mentioned above.

What are the challenges in implementing Adaptive MFA?

The primary challenge is how to protect the user experience.  Users normally do not like too many restrictions just to get to their bank account.  Also, not all users are computer or mobile-savvy.  For example, the bank in the question above has instructed the users who do not have a mobile phone or do not have a valid phone number in the file, to call the bank to get authenticated.   

While this may work temporarily, this cannot be done by the user every time as the waiting times for such calls are high.  So, the banks have to arrive at the right mix of technology and user convenience to implement secure MFA login at the right cost to the user.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -
Raj Srinivas
Raj Srinivas
Primarily from a strong security and product engineering background, he has been the principal architect of MISP (Multi-Domain Identity Services Platform) & CIE (Cloud ID Exchange) – in-house IAM & Security products at 8K Miles.

More Latest Stories

More Articles

The IoT Platform Market Just Consolidated: Smart Integrators Are Looking Elsewhere

Three platforms changed owners in 15 months. Your stack didn't change. Your risk profile did.

How Home-Based Healthcare is Improving Medical Accessibility Across India

The Indian health care industry has seen considerable transformation in recent times, primarily due to changes in patient demand and an increasing need for convenient and cost-effective health care. India is a country where high-quality health care facilities were available only in urban areas,...

Meta Platforms, Broadcom Partners to Co-Develop Multi-Gen Silicon AI Chips

Facebook parent Meta Platforms (NASDAQ: META) has expanded its partnership with Broadcom to co-develop...

Practo Names Srijesh Kumar as Global CPTO

India-based online doctor consulting platform, Practo has announced the appointment of Srijesh Kumar as...

Matrix Geo Solutions Wins ₹5.14 Crore Narmada Survey Project from MPSEDC

Matrix Geo Solutions Limited has received a Letter of Acceptance (LoA) from Madhya Pradesh...

Why Reliability and Security Are the New Differentiators in Enterprise Tech

For years, enterprises competed on features, scale, and speed. Today, the real differentiator is...

Trump Accuses Iran of Breaching Ceasefire, Warns Over Strait of Hormuz Transit

The US President Donald Trump has accused Iran of failing to allow adequate oil...

India’s Foreign Secretary Vikram Misri Holds Talks with FBI Chief Kash Patel

India’s Foreign Secretary Vikram Misri met FBI Chief Kash Patel in Washington on Thursday...

Sawai Capital Executes ₹300 Crore Structured Credit Transactions in Q4

A Gurugram-based wealth and investment platform, Sawai Capital, has executed structured credit transactions in excess of ₹300 crore during the fourth quarter, with deal...

Cisco Appoints Pete Shimer to Board, Daniel Schulman to Step Down

Cisco Systems (NASDAQ:CSCO) has appointed Pete A. Shimer to its board of directors, while...

Cisco Director Pete Shimer Files Initial Ownership Disclosure with SEC

Cisco Systems (NASDAQ: CSCO) board member Pete A. Shimer has filed an initial statement...

Buy vs Build in the AI Era: Why Enterprises Are Rethinking Technology Strategy

Every decade or so, a shift arrives that forces enterprises to rethink how they...

Cisco Report: Cybersecurity Remains Top Challenge as Industrial AI Adoption Expands

Cisco Systems (NASDAQ:CSCO) has released its latest State of Industrial AI Report, highlighting how...

Motilal Oswal Alternates leads $280 Mn Series E Round for KreditBee

India based digital lending platform KreditBee (KrazyBee Services PVT Ltd) has raised $280 million in a Series E funding round at a post money...

Cisco Appoints Pete Shimer as its board of directors

American multinational technology conglomerate, Cisco Inc (NASDAQ: CSCO) on Tuesday announced the appointment of Pete Shimer to its board of directors with the immediate effects. Shimer currently serves on the boards of Alaska Airlines, Korn Ferry and Synopsys, and is Executive Chair of the Cancer...

Cambodia Installs Statue Honouring Mine Detection Rat Magawa

Magawa, a landmine detecting rat who was awarded a gold medal for his service,...

GPS Renewables’ GPSR Arya Raises ₹500 Million from Axis AMC to Scale CBG Projects Across India

GPSR Arya, the asset platform of GPS Renewables, has raised ₹500 million in mezzanine...

How Modern Technology Enhances Efficiency and Performance of Residential HVAC Systems

Modern technology has revolutionized many aspects of our daily lives, and residential HVAC systems...

CredResolve Secures Pre-Series A round funding from Merak Ventures & Others

CredResolve, an India-based AI-powered debt collections infrastructure company, has raised a pre-Series A funding...

How to Avoid Distracted Driving on the Road

Driving on today's roads requires utmost attention and care. As automobiles evolve with advanced...

Closing India’s Employability Gap with Tech-First Hiring Models

India’s employability challenge is often framed as a skill gap problem. But that’s only...

VES College of Architecture’s Dr. Prof. Anand Achari on Preparing Students for Real Urban Challenges with AI and Design Thinking

Speaking with TechGraph, Principal of VES College of Architecture (VESCOA), Dr. Prof. Anand Achari,...

The Future of Crypto Investing Is on Autopilot

When most people think about cryptocurrency investing, they envision charts fluctuating rapidly, traders responding...

NVIDIA CEO Jensen Huang Reports 437,908 Shares Disposal at $181.93 Each

Jensen Huang, President and CEO of Nvidia Corporation (NASDAQ:NVDA), has reported a series of...

Buy vs Build in the AI Era: Why Enterprises Are Rethinking Technology Strategy

Every decade or so, a shift arrives that forces enterprises to rethink how they...

ASLI Appoints Rajagopal G as Chairman for 2026–28 Term

Association of Senior Living India (ASLI) has announced the appointment of Rajagopal G as...

realme Launches realme 16 5G in India with Dual 50MP Cameras, 7000mAh Battery

With a bid to strengthen its position in the mid range segment, realme has...

SatLeo Labs Raises $2.2 Mn Seed Round Led by Unicorn India Ventures

SatLeo Labs, a Gujarat-based space tech startup focused on capturing high-resolution thermal and visible...

How Graphics on Cars Can Boost Your Business

In today's competitive market, businesses are constantly looking for innovative ways to stand out...

Cisco Report: Cybersecurity Remains Top Challenge as Industrial AI Adoption Expands

Cisco Systems (NASDAQ:CSCO) has released its latest State of Industrial AI Report, highlighting how...

The Future of Crypto Investing Is on Autopilot

When most people think about cryptocurrency investing, they envision charts fluctuating rapidly, traders responding...

How NBBL’s New Technology Stack Is Transforming the Future of Payments

India’s digital payments ecosystem has reached a scale that very few countries in the...

NVIDIA CEO Jensen Huang Reports 437,908 Shares Disposal at $181.93 Each

Jensen Huang, President and CEO of Nvidia Corporation (NASDAQ:NVDA), has reported a series of...