Chat robot authentication system and method
By using large language models and natural language processing technology in the chatbot authentication system, explaining and evaluating users' open answers, the accuracy and security issues of traditional authentication methods are solved, and a more accurate and secure authentication process is achieved.
Patent Information
- Application Number
- CN202411594050.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-10-11
- Filing Date
- 2024-11-08
- Publication Date
- 2025-05-09
AI Technical Summary
Traditional user authentication methods have problems such as insufficient accuracy, inability to conduct natural conversations, not supporting user memory loss or partial answers, and being susceptible to fraudulent activities.
Using chatbot authentication systems, leverage large language models and state-of-the-art generative natural language processing technology, interpret open answers based on user known data, generate and propose iterative and/or subsequent questions to achieve a more accurate and secure authentication process.
A more accurate, user-friendly and secure authentication process is achieved, which enhances the accuracy of verification of user identities and provides an additional layer of fraud protection, which improves users' confidence in the security of personal information.
Smart Images

Figure CN119961916A_ABST
Abstract
Description
Technical Field
[0001] The disclosed technology generally relates to secure communications and, more particularly, to chatbot authentication systems and methods for verifying user identities. Background Art
[0002] Communications between individuals, organizations, and devices increasingly rely on electronic communications and data storage, which brings with it the associated risks of unauthorized access and data / identity theft. Therefore, it is necessary to implement strong security measures to protect sensitive data from unauthorized access.
[0003] A common way to ensure secure communication and data exchange is to authenticate by verifying the identity of a user or entity before granting access to a resource or system. There are many traditional technologies for user authentication, including passwords, biometrics, tokens, certificates, knowledge-based authentication (KBA), etc. However, this traditional approach has certain vulnerabilities and limitations.
[0004] In a traditional KBA process during registration, a user may be presented with (or the user may select from) a series of security questions, and the user may enter custom answers to the security questions. Then, during the authentication phase, the user may be presented with one or more previous security questions, and the user may be asked to enter the same text (spelling, punctuation, content, etc.) that the user entered when answering questions previously during registration. Existing implementations of this traditional process may have significant flaws. For example, a user may forget the specific format in which they provided their answer, such as spelling or abbreviations, which may make it difficult for them to provide the same answer in the future. In addition, it is well known that many users do not provide truthful answers, but instead choose irrelevant or even profane answers that are not ideal for authentication purposes.
[0005] Traditional KBA methods also typically require users to answer pre-configured quizzes with multiple-choice questions. This multiple-choice quiz-based authentication method has vulnerabilities that fraudsters can exploit to access victims' accounts. For example, KBA may display the victim's correct answers to fraudsters, who may compile information about the victim's identity through repeated quiz attempts and use this information to pass authentication. Based on guesswork alone, unauthorized users can choose the correct answer with a probability of 20%-25% per question. In addition, fraudsters can research certain questions related to data in public records, such as previous addresses, vehicles, etc., to increase their success rate in overcoming the authentication steps.
[0006] The above-mentioned traditional authentication methods lack accuracy in determining the identity of the user, do not have the ability to conduct natural conversations, do not have the ability to provide assistance for user memory lapses or partial answers, and may be susceptible to fraudulent activities. Therefore, an improved authentication technology is needed to address the shortcomings of traditional solutions. Summary of the invention
[0007] Some or all of the above needs can be solved by certain implementations of the disclosed technology. Disclosed herein are systems and methods for implementing a chatbot authentication process that can utilize a large language model (LLM) and state-of-the-art generative natural language processing (NLP) to interpret open-ended answers based on known data about the user. The provided answers can be evaluated for accuracy and completeness, and iterative and / or follow-up questions can be generated and asked to allow the user to provide clarification or other details. The systems and methods disclosed herein can understand the semantic meaning of the answers provided by the user, which can enable a more accurate, user-friendly, and secure authentication process.
[0008] In an example implementation, a computer-implemented method for user authentication for access to a service using a chatbot is disclosed. The method may include receiving user information corresponding to a user; parsing the received user information into a unique identifier (UID) of the user; obtaining comprehensive data about the user that matches the UID from one or more data sources; generating multiple open authentication questions based on the comprehensive data; outputting one or more of the multiple open authentication questions for display on a user device associated with the user; receiving one or more user answers corresponding to one or more of the multiple open authentication questions in natural language; evaluating one or more user answers based on known ground truth using a large language model (LLM) based on the comprehensive data; and authenticating the user to access the service in response to determining that a success count matches a predefined threshold number of matches, the success count corresponding to the number of factually correct user answers corresponding to one or more of the multiple open authentication questions.
[0009] In another example implementation, a computer-implemented method for user authentication for access to a service using a chatbot is disclosed. The method may include receiving user information corresponding to a user; parsing the received user information into a unique identifier (UID) of the user; obtaining skill-based or knowledge-based integrated data about the user that matches the UID from one or more data sources; generating a plurality of skill-based or knowledge-based authentication questions based on the skill-based or knowledge-based integrated data; outputting one or more of the plurality of skill-based or knowledge-based authentication questions for display on a user device; receiving one or more user answers corresponding to one or more of the plurality of skill-based or knowledge-based authentication questions in natural language; evaluating one or more user answers based on known ground truth using a large language model (LLM) based on the skill-based or knowledge-based integrated data; and authenticating the user to access the service in response to determining that a success count matches a predefined threshold number of matches, the success count corresponding to the number of factually correct user answers corresponding to one or more of the plurality of skill-based or knowledge-based authentication questions.
[0010] In another example implementation, a system for user authentication via a chatbot is disclosed. The system may include a data repository, a user interface, at least one memory, and at least one processor, the data repository being configured to store user identification information; the user interface being configured to display authentication questions and receive user answers from the user; at least one memory being used to store data and computer executable instructions; at least one processor being configured to access at least one memory and further configured to execute computer executable instructions, the instructions causing at least one processor to: receive user information corresponding to a user; resolve the received user information into a unique identifier (UID) of the user; obtain comprehensive data about the user matching the UID from one or more data sources; generate multiple authentication questions based on the comprehensive data; output one or more of the multiple authentication questions for display on a user device; receive one or more user answers corresponding to one or more of the multiple authentication questions in natural language; evaluate the user answers based on known ground truth using a large language model (LLM) based on the comprehensive data; output an indication corresponding to the evaluation for display on the user device; and in response to determining that a success count matches a predefined threshold number of matches, authenticate the user to access a service, the success count corresponding to the number of factually correct user answers corresponding to one or more of the multiple authentication questions.
[0011] Other implementations, features, and aspects of the disclosed technology are described in detail herein and are considered a part of the disclosed technology that is claimed for protection. Other implementations, features, and aspects may be understood with reference to the following detailed description, drawings, and claims.
[0012] CROSS-REFERENCE TO RELATED APPLICATIONS
[0013] This application claims the benefit of priority under 35 U.S.C. § 119 to U.S. Provisional Patent Application No. 63 / 596,986, filed on November 8, 2023, entitled “System and Method for Chatbot Authentication.” This application also claims the benefit of priority under 35 U.S.C. § 119 to U.S. Provisional Patent Application No. 63 / 653,337, filed on May 30, 2024, entitled “System and Method for Chatbot Authentication.” The contents of each of the above applications are incorporated herein by reference in their entirety as if fully set forth herein. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Reference will now be made to the accompanying drawings and flow charts, which are not necessarily drawn to scale, in which:
[0015] Figure 1A A user interface with example questions 102 and user free answers 104 is shown.
[0016] Figure 1B A user interface with feedback 106 and updated user free answers 108 is shown.
[0017] Figure 1C A user interface of a user free answer with feedback and updates is shown.
[0018] Figure 1D A user interface of a user free answer with feedback and updates is shown.
[0019] Figure 1E A user interface with feedback and user free answers is shown.
[0020] Figure 1F A user interface with feedback and user free answers is shown.
[0021] Figure 1G A user interface with feedback and user free answers is shown.
[0022] Figure 1H A user interface with example questions and user-generated answers is shown.
[0023] Fig. 1I A user interface is shown with example questions and user abbreviated answers.
[0024] Figure 1J A user interface is shown with example questions and user free answers in Hebrew.
[0025] Figure 1KA user interface is shown with example questions and user free answers in French.
[0026] Figure 1L A user interface is shown with an indication of successful authentication.
[0027] Figure 1M A user interface is shown with an authentication failure indication.
[0028] Figure 1N A user interface is shown indicating authentication failure due to detection of a pasted answer, remote access, etc.
[0029] Figure 2 is a block diagram of an authentication system according to an example implementation of the disclosed technology.
[0030] Figure 3 is another block diagram of an authentication system according to an example implementation of the disclosed technology.
[0031] Figure 4 Depicted are analytical evaluation results associated with an authentication attempt according to an example implementation of the disclosed technology.
[0032] Figure 5A Another analytical evaluation result related to a user device associated with an authentication attempt according to an example implementation of the disclosed technology is depicted.
[0033] Figure 5B Another analytical evaluation result related to a user's detected IP address according to an example implementation of the disclosed technology is depicted.
[0034] Figure 6 is a block diagram depiction of a computing device according to certain exemplary implementations of the disclosed technology.
[0035] Figure 7 An example photograph of an aircraft cockpit is shown with some controls identified with corresponding questions to test the skills-based knowledge of an individual with a commercial pilot's license in accordance with an example implementation of the disclosed technology.
[0036] Figure 8 An example photograph of an aircraft cockpit is shown with portions of the controls blacked out and with corresponding questions to test the skills-based knowledge of an individual with a commercial pilot's license in accordance with an example implementation of the disclosed technology.
[0037] Fig. 9 An example question pane for querying individuals having skills or knowledge acquired through higher education is shown in accordance with certain example implementations of the disclosed technology.
[0038] Fig.10 is a flow chart of a method according to an example implementation of the disclosed technology.
[0039] Fig.11 is a flow chart of a method according to an example implementation of the disclosed technology. DETAILED DESCRIPTION
[0040] The disclosed technology provides a novel authentication technology that enhances security and provides a more reliable and user-friendly authentication mechanism. Exemplary implementations of the disclosed technology can provide certain improvements over traditional authentication methods that are typically used to authenticate users and prevent fraud.
[0041] The disclosed technology includes a chatbot authentication system and process that can leverage a large language model (LLM) and state-of-the-art generative natural language processing (NLP) to interpret open-ended answers based on known data about the user. The provided answers can be evaluated for accuracy and completeness, and in certain implementations, iterative and / or follow-up questions can be generated and asked to allow the user to provide clarification or additional details. With the help of LLM and NLP, the systems and methods disclosed herein can understand the semantic meaning of the answers provided by the user, which can enable a more accurate, user-friendly, and secure authentication process.
[0042] Certain implementations of the disclosed technology can be used in conjunction with advanced digital proprietary tools, such as LexisNexis ThreatMetrix and LexisNexis BehavioSec solutions, to detect and prevent fraud attempts. These tools can identify suspicious activities, such as pasting, off-paging, use of Virtual Private Networks (VPNs) or remote desktops, or bot / script attacks, to ensure a secure authentication environment. Certain implementations of the disclosed technology can compare behavioral biometric patterns to a broad base of users to detect suspicious attempts to answer questions.
[0043] The term "User Information" is defined herein as any information that can be directly or indirectly associated with a user's identity. User Information may include, but is not limited to, personally identifiable information (PII). For example, an email address may be considered PII because it can be used to uniquely identify a specific user. However, a username such as "msmith4149" may not be sufficient to be considered PII, but may be considered User Information.
[0044] According to some exemplary implementations of the disclosed technology, the authentication workflow may include one or more of the following steps to ensure that the user's identity is authenticated before continuing to access or use certain services:
[0045] (1) Users or customers of an enterprise (e.g., bank, e-commerce enterprise, online retailer, etc.) can provide user information to LexisNexis Risk Solutions (LNRS) as a precursor to the authentication process;
[0046] (2) LNRS can resolve the received user information into a unique identifier of the user (such as LexID);
[0047] (3) Collecting comprehensive data about the user that matches the LexID from LNRS data sources and / or other comprehensive data sources;
[0048] (4) Digital analytics scripts can collect device and behavioral data in response to a user loading / accessing an authentication page;
[0049] (5) The system can generate authentication questions based on predefined configurations;
[0050] (6) Users can iteratively get prompts for multiple open-ended questions (based on predefined configurations);
[0051] (7) Users can enter answers in natural language, without size, style, or language restrictions (as opposed to closed traditional certification tests);
[0052] (8) A large language model (LLM) may be used to evaluate the user input based on known ground truth. In some implementations, the LLM may output an indication or value corresponding to the evaluation, such as correct, incorrect, or incomplete.
[0053] (8a) if the answer is evaluated as factually correct, the user may be prompted with the next question and a success count may be incremented;
[0054] (8b) if the answer is evaluated as factually incorrect, the user may be prompted with the next question and the success count may not be incremented;
[0055] (8c) if the answer is in fact correct but incomplete, the user may be prompted with additional instructions that indicate the missing information (e.g., the color of the car when the user only specified the model), and the success count may not be incremented until the correct missing information is provided;
[0056] (8d) In some implementations, if the answer is incorrect and incomplete, the user can be prompted as to what information is missing;
[0057] (9) After all questions are answered, authentication may succeed or fail based on the number of correct answers that match a predefined threshold or due to detection of digital risk signals (such as pasted text, user leaving the page, remote access, detection of VPN, robot or script behavior). In response to the evaluation of the answers to the questions, an indication of success or failure may be presented to the user. In some implementations, the indication may provide the user with information about why they passed or failed authentication.
[0058] The disclosed technology provides several advantages over traditional quiz-based approaches. In a first aspect, LLM can enable a more natural and engaging interaction with the user. In a second aspect, the disclosed technology provides a more thorough and accurate authentication process. For example, open-ended questions allow for a more in-depth assessment of the user's knowledge of the questions asked, eliminating the opportunity to guess the correct answer, which is a common problem with multiple-choice quizzes. In a third aspect, the disclosed technology can limit or completely avoid revealing facts about the user. In a fourth aspect, the disclosed technology can provide support for many languages. In a fifth aspect, the disclosed technology can be used in conjunction with advanced digital security tools.
[0059] Certain implementations of the disclosed technology can provide an additional layer of protection against fraud that traditional authentication methods cannot provide. This not only ensures a secure authentication process, but also increases the user's confidence in the security of their personal information. The disclosed technology can achieve more accurate, secure and user-friendly authentication methods, making it a significant advance in the field of digital security.
[0060] Additional details and implementations of the disclosed technology will now be further described with reference to the accompanying drawings.
[0061] Figure 1A A user interface with example questions 102 and user free answers 104 is shown.
[0062] Figure 1B A user interface with feedback 106 and updated user free answers 108 is shown.
[0063] Figure 1C A user interface of a user free answer with feedback and updates is shown.
[0064] Figure 1D A user interface of a user free answer with feedback and updates is shown.
[0065] Figure 1E A user interface with feedback and user free answers is shown.
[0066] Figure 1F A user interface with feedback and user free answers is shown.
[0067] Figure 1G A user interface with feedback and user free answers is shown.
[0068] Figure 1H A user interface with example questions and user-generated answers is shown.
[0069] Fig. 1I A user interface is shown with example questions and user abbreviated answers.
[0070] Figure 1J A user interface is shown with example questions and user free answers in Hebrew.
[0071] Figure 1K A user interface is shown with example questions and user free answers in French.
[0072] Figure 1L A user interface is shown with an indication of successful authentication.
[0073] Figure 1M A user interface is shown with an authentication failure indication.
[0074] Figure 1N A user interface is shown indicating authentication failure due to detection of a pasted answer, remote access, etc.
[0075] Figure 2 200 is a high-level block diagram of an authentication system 200 implemented according to an example of the disclosed technology. The system 200 can be configured to distinguish between an unknown user 202 and a legitimate user 204 requesting access to an online service of an enterprise server 206. For example, the enterprise server 206 can be associated with an enterprise such as an enterprise, a government agency, an online retailer, etc. The system 200 can also include a security server 210 (or communicate with the security server 210 via a network 208), which can work in conjunction with the enterprise server 206, for example, by generating security questions and interpreting corresponding answers through a chatbot, which can be verified to authenticate the legitimate user 204 to access the online service of the enterprise server 206, as will be discussed further below.
[0076] Figure 3 is a block diagram of an authentication system 300 according to an example implementation of the disclosed technology, which may correspond to the above reference Figure 2Advanced authentication system 200 discussed. According to certain exemplary implementations of the disclosed technology, a user (legitimate or otherwise) can utilize a user device 302 (e.g., a computer, tablet, mobile phone, smartphone, etc.) to communicate with an enterprise server 306 to register and / or authenticate access to an online service. In certain exemplary implementations, certain device information 304 and / or user information 305 stored on the user device 302 can be used in conjunction with the disclosed technology as an additional layer of security, for example, to confirm that the associated user is authenticating using an identified device. Examples of device information 304 include a unique device identifier (UDID), an identifier for advertiser (IDFA), an internet protocol (IP) address, a media access control (MAC) address, and the like.
[0077] In certain exemplary implementations, the enterprise server 306 may communicate with a secure server 310 via a network 308, such as the Internet, a wide area network, a local area network, etc. The secure server 310 may include a data repository 314 for generating, storing, and / or retrieving authentication questions, answers, etc. In certain exemplary implementations, the secure server 310 may include one or more large language models (LLMs) 316 and natural language processors (NLPs) 318 that may be used to interact with users, generate questions, interpret answers, etc.
[0078] According to certain exemplary implementations of the disclosed technology, the enterprise server 306 may provide a user interface (UI) 312a for communicating with the user device 302. In certain exemplary implementations, the enterprise server 306 may coordinate the control, formatting, presentation, display, capture, etc. of user responses through the UI 312a in communication with the security server 310. In an optional example implementation, for example, the security server 310 may "host" the enterprise UI 312b so that user registration and / or authentication may be handled by the security server 310. In certain exemplary implementations, the user device 312 may connect to the security server 310 (via the network 308). In certain exemplary implementations, the enterprise server 306 may redirect the user device 302 to the security server 310 to perform the registration and / or authentication.
[0079] Figure 4Depicted are example analytical evaluation results associated with authentication attempts according to example implementations of the disclosed technology. In certain implementations, various behavioral metric signals and / or data can be monitored and analyzed to determine the likelihood that a robot or fraudster is impersonating a user. In certain implementations, the scores can be used to help identify potential fraud situations. In certain implementations, the determined behavioral metric profiles can indicate a certain type of fraud, such as possible social engineering. In certain implementations, the profile evaluation results can be used in conjunction with other authentication processes disclosed herein to provide enhanced authentication security.
[0080] Figure 5A Another exemplary analysis evaluation result related to a user device associated with an authentication attempt according to an example implementation of the disclosed technology is depicted. In some implementations, the user device ID can be checked against historical usage to determine whether a new device is being used to attempt authentication. In some implementations, additional authentication steps may be required if an unrecognized user device is detected.
[0081] Figure 5B Another example analysis evaluation result related to a user's detected IP address according to an example implementation of the disclosed technology is depicted. In some implementations, the detected IP address can be checked against historical usage to determine whether an unidentified or suspicious communication channel is being utilized to attempt authentication. In some implementations, additional authentication steps may be required if it is detected that unidentified or suspicious communications are being used.
[0082] As mentioned above Figure 4 , 5A and 5B, as disclosed herein, additional authentication assessments can be used in conjunction with the LLM's evaluation of the user's natural language answers to provide enhanced authentication security. The following U.S. patents and U.S. patent application publications are incorporated herein by reference as if fully presented and may be used to describe various systems and / or processes that may be used herein to analyze assessments, for example, to provide enhanced authentication security: U.S. Patent Nos. 11,860,985; 11,329,975; 10,505,932; 10,142,369; 10,116,667; 10,764,297; 10,841,324; 9,444,835; and U.S. Patent Application Publication Nos. 20240037541; 20240259394; 20240256120; 20240297898.
[0083] Figure 66 is a block diagram of an illustrative computing device 600 that can be used for identity registration and / or authentication processes according to an example implementation of the disclosed technology. The computing device 600 can handle various aspects of the process, including communicating with various entities and / or external systems involved in the authentication process. For example, the computing device 600 can communicate via one or more clouds, the Internet, or other network channels to send and / or receive information. For example, the computing device 600 can receive identity information related to a user, and can receive independent information in response to querying one or more public or private databases.
[0084] Figure 6 The computing device 600 includes a central processing unit (CPU) 602, where computer instructions are processed; a display interface 604, which acts as a communication interface and provides functions for presenting video, graphics, images, and text on a display. In some example implementations of the disclosed technology, the display interface 604 can be directly connected to a local display, such as a touch screen display associated with a mobile computing device. In another example implementation, the display interface 604 can be configured to provide data, images, and other information to an external / remote display that is not necessarily physically connected to the computing device. For example, a desktop monitor can be used to mirror graphics and other information presented on the computing device 600. In some example implementations, the display interface 604 can be wirelessly connected to the external / remote display, for example, via a Wi-Fi channel or other network connection interface 612.
[0085] In an example implementation, the network connection interface 412 can be configured as a communication interface, for example, providing functionality for presenting video, graphics, images, text, other information, or any combination thereof on a display. In one example, the communication interface can include a serial port, a parallel port, a general-purpose input and output (GPIO) port, a game port, a universal serial bus (USB), a micro USB port, a high-definition multimedia (HDMI) port, a video port, an audio port, a Bluetooth port, a near-field communication (NFC) port, other similar communication interfaces, or any combination thereof.
[0086] The computing device 600 may include a keyboard interface 606 that provides a communication interface to a keyboard. In one example implementation, the computing device 600 may include a presence sensor interface 608 for interfacing with a pointing device and / or a touch screen. According to certain example implementations of the disclosed technology, the presence sensor interface 608 may provide a communication interface to various devices, such as a pointing device, a touch screen, a depth camera, etc., which may or may not be associated with a display.
[0087] The computing device 600 may be configured to use input devices via one or more input / output interfaces (e.g., keyboard interface 606, display interface 604, presence sensor interface 608, network connection interface 612, camera interface 614, sound interface 616, etc.) to allow a user to capture information into the computing device 600. The input device may include a mouse, a trackball, a directional pad, a trackpad, a touch-authentication trackpad, a presence-sensitive trackpad, a presentation-sensitive display, a scroll wheel, a digital camera, a digital video camera, a webcam, a microphone, a sensor such as an accelerometer or a gyroscope, a smart card, an iris reader, a fingerprint reader, a voiceprint reader, etc. In addition, the input device may be integrated with the computing device 600 or may be a separate device.
[0088] An example implementation of the computing device 600 may include an antenna interface 610 that provides a communication interface to an antenna; a network connection interface 612 that provides a communication interface to a network. In some implementations, a camera interface 614 is provided for capturing digital images, such as from a camera. In some implementations, a sound interface 616 is provided as a communication interface for converting sound into electrical signals using a microphone and converting electrical signals into sound using a speaker. According to an example implementation, a random-access memory (RAM) 618 is provided, where computer instructions and data can be stored in a volatile storage device for processing by the CPU 602.
[0089] According to an example implementation, the computing device 600 includes a read-only memory (ROM) 620, where unchanging low-level system code or data used for basic system functions (such as basic input and output (I / O), booting, or receiving keystrokes from a keyboard) is stored in a non-volatile storage device. According to an example implementation, the computing device 600 includes a storage medium 622 or another suitable type of memory (e.g., RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disk, optical disk, floppy disk, hard disk, removable ink cartridge, flash drive), where stored files include an operating system 624, application programs 626 (including, for example, a web browser application, a manifest extraction module, etc.) and data files 628. According to an example implementation, the computing device 600 includes a power supply 630 that provides appropriate alternating current (AC) or direct current (DC) to power the components. According to an example implementation, the computing device 600 may include a telephone subsystem 632 that allows the device 600 to send and receive sound over a telephone network. The component devices and the CPU 602 communicate with each other via a bus 634.
[0090] According to an example implementation, the CPU 602 has a suitable structure as a computer processor. In one arrangement, the computer CPU 602 may include more than one processing unit. The RAM 618 is connected to the computer bus 634 to provide fast RAM storage to the CPU 602 during the execution of software programs such as operating system applications and device drivers. More specifically, the CPU 602 loads computer executable processing steps from the storage medium 622 or other media into the fields of the RAM 618 in order to execute the software programs. Data can be stored in the RAM 618, where the data can be accessed by the computer CPU 602 during execution. In one example configuration, the device 600 includes at least 128MB of RAM and 256MB of flash memory.
[0091] The storage medium 622 itself may include multiple physical drive units, such as a redundant array of independent disks (RAID), a floppy disk drive, a flash memory, a USB flash drive, an external hard drive, a thumb drive, a pen drive, a key drive, a High-Density Digital Versatile Disc (HD-DVD) optical drive, an internal hard drive, a Blu-ray optical drive or a Holographic Digital Data Storage (HDDS) optical drive, an external micro dual in-line memory module (DIMM) synchronous dynamic random access memory (SDRAM) or an external micro DIMM SDRAM. Such a computer-readable storage medium allows the device 600 to access computer-executable process steps, applications, and to download data from the device 600 or upload data to the device 600. A computer program product such as a computer program product utilizing a communication system may be tangibly embodied in the storage medium 622, which may include a machine-readable storage medium.
[0092] Figure 7 An example photograph of an aircraft cockpit 700 is shown in accordance with an example implementation of the disclosed technology, wherein portions 702, 704 of controls or displays are identified with accompanying questions to test the skills-based knowledge of an individual having, for example, a commercial pilot's license.
[0093] Can be generated and attached Figure 7 Example questions for the photo shown (or similar photos) could include:
[0094] -What is highlighted?
[0095] - Lists the 4 telemeters available in these displays.
[0096] Figure 8 An example photograph of an aircraft cockpit 800 is shown in accordance with an example implementation of the disclosed technology, wherein portions 802, 804 of controls or displays are grayed out and identified with accompanying corresponding questions to test the skills-based knowledge of an individual holding a commercial pilot's license, for example.
[0097] Can be generated and attached Fig. 9 Example questions for the photo shown (or similar photos) could include:
[0098] -What is a gray display called?
[0099] - Lists the 4 telemeters that are usually available on the grey display.
[0100] Certain implementations of the disclosed technology can analyze the provided answers, for example, by using a large language model (LLM) to evaluate the user answer based on known ground truth. In certain implementations, the LLM can be used to generate questions based on a person's specific skills or knowledge.
[0101] According to certain exemplary implementations of the disclosed technology, questions may be generated and posed to an individual based on topics in higher education that the individual is known to possess.
[0102] Fig. 9 An example question pane 900 is shown for querying individuals with skill sets acquired through higher education, such as a Ph.D. in the field of quantum computing. According to certain exemplary implementations of the disclosed technology, the question pane 900 may pose an open-ended question 902 to the user, such as "Explain what your Ph.D. is about." Fig. 9 An example (test mode) answer is shown in dashed portion 904 of the question pane 900, which is not displayed in question pane 900 but is included to illustrate the type of data related to a particular (doctoral dissertation) topic that may be obtained from one or more comprehensive data sources related to the user's skills or knowledge. The user may answer open-ended question 902 by typing a natural language user answer 906 in the appropriate pane, and the user may press a "Submit Answer" button 910 to send the user answer to a system, such as enterprise server 306 (206) and / or secure server 310 (210), as described above with reference to Figure 2 and Figure 3 As described. For example, the security server can receive user answers corresponding to open-ended and / or skill-based and / or knowledge-based questions, and can evaluate one or more user answers based on comprehensive skill-based or knowledge-based data (as shown in dashed portion 904), using a large language model (LLM) based on known basic facts. As shown in feedback response 912, in this example, the predefined configuration may require a level of detail that the initial user answer does not meet. In this case, feedback response 912 can indicate that the answer is incomplete, and in some implementations, feedback on what information is missing in user answer 906 can also be provided. The user can then supplement their initial answer 906 with the missing information.
[0103] In some implementations, the predefined configuration may specify one or more of the following: (a) the number of open authentication questions to be generated; (b) the threshold number of matches required for authentication; (c) the complexity of the open authentication questions to be generated; and / or (d) the level of detail required in one or more user answers. In some implementations, the required level of complexity may include the number of contextual variables related to the user and / or his or her area of expertise. Therefore, in some implementations, when the predefined configuration requires multiple correct answers for authentication, additional open and / or skill- or knowledge-based questions may be asked of the user. When a question is answered correctly, the number of successes may be counted in advance. In response to determining that a success count matches a predefined threshold number of matches, the disclosed technology can authenticate the user, such as to access a service, wherein the success count corresponds to the number of factually correct user answers corresponding to one or more of the multiple skill- or knowledge-based authentication questions.
[0104] In some implementations, questions may be generated about known occupations of the person, such as software engineer, lawyer, etc. In some implementations, the questions may be text-based. In other implementations, the questions may include, for example, Figure 7 and Figure 8 Accompanying video or images shown.
[0105] In some implementations, skill-based questions may be used in conjunction with knowledge-based questions to improve the accuracy of verification. Although some of these skill-based questions may be researchable, certain form monitoring features such as time limits, monitoring of other open windows, etc., may be used to prevent acceptance of answers that are researched in real time.
[0106] Fig.101 is a flowchart of a method 1000 for user authentication of accessing services using a chatbot according to an example implementation of the disclosed technology. In some implementations, the method 1000 may cover the user's registration process and the user's access and / or related authentication process of utilizing services. The method 1000 starts at box 1002 and includes receiving user information corresponding to the user. In box 1004, the method 1000 includes parsing the received user information into a unique identifier (UID). In box 1006, the method 1000 includes obtaining comprehensive data about the user that matches the UID from one or more data sources. In box 1008, the method 1000 includes generating multiple open authentication questions based on the comprehensive data. In box 1010, the method 1000 includes outputting one or more of the multiple open authentication questions to be displayed on a user device associated with the user. In box 1012, the method 1000 includes receiving one or more user answers corresponding to one or more of the multiple open authentication questions in natural language. In block 1014, method 1000 includes evaluating one or more user answers based on known ground facts using a large language model (LLM) based on the comprehensive data. In block 1016, method 1000 includes authenticating the user to access the service in response to determining that a success count matches a predefined threshold number of matches, the success count corresponding to a number of factually correct user answers corresponding to one or more of the plurality of open authentication questions.
[0107] In some implementations, the method may also include collecting user device data and behavioral data in response to the user accessing the authentication page. In some implementations, the method may include generating a digital profile associated with the user.
[0108] In some implementations, generating multiple open authentication questions can be based on a predefined configuration. For example, the predefined configuration can include one or more of the following: (a) the number of open authentication questions to be generated; (b) a threshold number of matches required for authentication, where the threshold number is less than or equal to the number of open authentication questions; (c) the complexity of generating the open authentication questions and / or (d) the level of detail required in one or more user answers. In some implementations, the level of complexity can include the number of context variables associated with the user. As described above with reference to Fig. 9 As described, for example, the level of detail required in one or more user answers may include one or more of observations, experiments, contributions, specific details, specific knowledge, etc.
[0109] In some implementations, the LLM may be used to generate multiple open-ended certification questions.
[0110] In some implementations, if the user answer is evaluated as factually correct, the method may include outputting the next question for display on the user device and incrementing the success count. In some implementations, if the user answer is evaluated as factually incorrect, the method may include outputting the next question for display on the user device without incrementing the success count. In some implementations, if the user answer is factually correct but incomplete, the method may include outputting additional instructions for display on the user device to indicate the missing information without incrementing the success count. In some implementations, if the user answer is incorrect and incomplete, the method may include outputting additional instructions for display on the user device to indicate the missing information without incrementing the success count.
[0111] In some implementations, the method may include outputting an indication corresponding to the assessment, such as correct, incorrect, or incomplete, for display on a user device.
[0112] According to certain exemplary implementations of the disclosed technology, the one or more data sources may include one or more of the following: court records, birth certificate records, Census Bureau records, county records, property records, real estate records, court records, business records, school records, education records, web pages, professional license records, historical records, social media records, marketing records, publications, private records, media records, background records, proprietary data, and derived data records.
[0113] In some exemplary implementations, a list of multiple choice answers may be presented to the user for selection. In some implementations, the multiple choice answers may be associated with indexes or pointers so that comparisons (between the answers selected during registration and authentication) only require matching indexes.
[0114] In addition to knowledge-based certification improvements, the disclosed technology can be further extended to ask questions about specific skills that an individual may have. For example, the system can generate questions based on professional skills, specific knowledge, and / or licenses that an individual may have obtained (e.g., a commercial pilot license, a doctorate in a certain field, etc.), as described above with respect to Figure 7 , 8 and / or as discussed in 9.
[0115] Fig.111 is a flowchart of another method 1100 for user authentication for accessing services according to an example implementation of the disclosed technology. The method 1100 may cover a user's registration process and a user's related authentication process. The method 1100 starts at box 1102 and includes receiving user information corresponding to a user. In some implementations, the user information may be obtained directly from the user via a user device. In some implementations, some or all of the user information may be retrieved from a data repository, for example, based on a user name and / or password associated with a user by a known user device and / or a successful two-factor authorization, etc. In box 1104, the method 1100 includes parsing the received user information into a unique identifier (UID) of the user. In box 1106, the method 1100 includes obtaining comprehensive data about the user based on skills or knowledge that matches the UID from one or more data sources. In box 1108, the method 1100 includes generating multiple skill-based or knowledge-based authentication questions based on the comprehensive data based on skills or knowledge. In box 1110, method 1100 includes outputting one or more of a plurality of skill-based or knowledge-based authentication questions for display on a user device. In box 1112, method 1100 includes receiving one or more user answers corresponding to one or more of the plurality of skill-based or knowledge-based authentication questions in natural language. In box 1114, method 1100 includes evaluating one or more user answers based on known ground truth using a large language model (LLM) based on the skill-based or knowledge-based synthetic data. In box 1116, method 1100 includes authenticating the user to access the service in response to determining that a success count matches a predefined threshold number of matches, the success count corresponding to the number of factually correct user answers corresponding to one or more of the plurality of skill-based or knowledge-based authentication questions.
[0116] Certain implementations of the disclosed technology may include outputting an indication corresponding to the evaluation (e.g., Fig. 9 Instructions for discussion 912).
[0117] Certain implementations of the disclosed technology may include collecting user device and / or behavior data in response to the user accessing an authentication page. Certain implementations of the disclosed technology include generating a digital profile associated with the user.
[0118] In some implementations, generating multiple skills-based or knowledge-based authentication questions can be based on a predefined configuration. For example, the predefined configuration can include one or more of the following: (a) the number of open authentication questions to be generated; (b) a threshold number of matches required for authentication, where the threshold number is less than or equal to the number of open authentication questions; (c) the complexity of generating the open authentication questions and / or (d) the level of detail required in one or more user answers. In some implementations, the level of complexity can include the number of context variables associated with the user. As described above with reference to Fig. 9 As described, for example, the level of detail required in one or more user answers may include one or more of observations, experiments, contributions, specific details, specific knowledge, etc.
[0119] In some implementations, one or more of the multiple skill- or knowledge-based authentication questions output for display on a user device may include an accompanying photo or video of a device associated with the comprehensive skill- or knowledge-based data about the user that matches the UID.
[0120] In some implementations, one or more skills- or knowledge-based certification questions may include one or more open-ended questions.
[0121] In some implementations, the LLM may be used to generate one or more skills- or knowledge-based certification questions.
[0122] In some implementations, the method may include outputting an indication corresponding to the assessment, such as correct, incorrect, or incomplete, for display on a user device.
[0123] In some implementations, if the user answer is evaluated as factually correct, the method may include outputting the next question for display on the user device and incrementing the success count. In some implementations, if the user answer is evaluated as factually incorrect, the method may include outputting the next question for display on the user device without incrementing the success count. In some implementations, if the user answer is factually correct but incomplete, the method may include outputting additional instructions for display on the user device to indicate the missing information without incrementing the success count. In some implementations, if the user answer is incorrect and incomplete, the method may include outputting additional instructions for display on the user device to indicate the missing information without incrementing the success count.
[0124] In certain implementations, in response to determining that the success count matches the predefined threshold, the method may include authenticating the user to access the service.
[0125] Certain implementations of the disclosed technology may include collecting user device and / or behavior data in response to a user accessing an authentication page to generate a digital profile associated with the user. In certain implementations, the digital profile may be used as an additional security layer for authentication.
[0126] According to certain exemplary implementations of the disclosed technology, authentication questions may be presented during the authentication phase based on how the user answered one or more questions during the registration phase. Thus, certain weighting and / or logic may be applied to determine which questions are displayed for the user to answer during the authentication phase. For example, the user's preferred answers to authentication questions during registration may be tabulated in a user population to rank the answer choices for that population from the most common (or most frequently selected) to the most unique (or least frequently selected). If the user answers a first authentication question that has a higher popularity among its relevant population during the registration phase, and if the user answers a second authentication question that has a lower popularity (i.e., more unique among the relevant population) during login, the authentication topic presented during authentication may be automatically selected for presentation based on the popularity / uniqueness ranking or weight (from the authentication questions previously answered by the user) so that the authentication question topic corresponding to the most unique answer may be automatically selected for presentation to the user. In certain exemplary implementations, the above-mentioned population may include all users or a subgroup of users. In certain exemplary implementations, the subgroups of users may be divided by geographic region, etc. In certain exemplary implementations, one or more questions may be randomly selected.
[0127] A legitimate user as defined herein is a person who represents his or her true identity during the authentication process (as opposed to a fraudster who may misrepresent his or her identity as someone else). In certain exemplary implementations, the legitimacy of a user may be determined based on answers to questions. Authentication of a user may be provided based on the user's correct responses to the questions presented.
[0128] In an example implementation, the received set of identity information may also include information that may directly or indirectly identify certain characteristics about the communication channel used by the user (202, 204) and / or the user device 302, such as a phone number, IP address, MAC address, location, signal-to-noise ratio, unique browser configuration, operating system, installed fonts, installed plug-ins, etc. In an example implementation, the characteristics of the communication channel 308 or the device 302 may be utilized in conjunction with the received selection to determine one or more of the following:
[0129] Whether the received telephone number associated with the communication channel or device 302 is different from the originating device telephone number or has been altered in some way (i.e., spoofed);
[0130] Whether the user's device 302 is located in the expected location (i.e., within the user's hometown or state);
[0131] Whether the user's device 302 is located in an area associated with a high crime rate;
[0132] Whether the user's device 302 is located abroad;
[0133] Detailed information about the user device 302 that can be verified by independent information (ie, device fingerprinting).
[0134] Based on analysis of the responses, or other factors that determine the risk is above an acceptable level, the user may be presented with additional options or instructions to further verify the user's identity. For example, certain embodiments may include online or offline capture of an ID document (e.g., driver's license, social security card, credit card, bank card, utility bill, tax return, etc.) for further identity verification.
[0135] The identity authentication process disclosed herein can utilize all or part of previously collected, compared, analyzed and / or scored information to determine a fraud risk score. In certain example implementations, the fraud risk score can provide additional confidence for accepting or rejecting authentication.
[0136] If it is determined that the response received from the user corresponds to a correct answer, some implementations may also include initiating biometric capture of the user. For example, in some example implementations, biometric capture may be used to associate user identity information with some type of physically verifiable (biometric) information, such as a fingerprint, voiceprint, iris image, facial image, etc.
[0137] If the user does not provide the correct answer, some implementations may prevent or block additional authentication steps and may output a failure indication. For example, in the event that the risk is determined to be above an acceptable level, the user may be provided with other options or instructions to verify his or her identity.
[0138] In some implementations, the initial and / or additional authentication process steps may be controlled based on corporate or government oversight policies. For example, to comply with certain state laws, an authentication challenge method for verifying identity may need to be based on commercially reasonable tools. In other cases, certain transactions may require specific types of authentication based on business policy. For example, certain banks may require authentication for balance transfers over $10,000.
[0139] In some implementations, if the user provides an incorrect answer, the system may generate and present additional question panes to the user. If the user correctly answers a predetermined number or percentage of question panes within a limited or allotted time, the system may authenticate the user.
[0140] One purpose of the disclosed technology is to increase the strength and security of the authentication process by forcing users (who may or may not be legitimate) to provide proof of their skills or knowledge by answering open-ended questions. Certain implementations of the disclosed technology may also provide additional security by requiring a "possession" factor. In some implementations, a pane with selected answers may be sent to a user using various so-called "out-of-band" communication channels or channel combinations (such as through messaging, uniform resource locator (URL) access, etc.). For example, in one implementation, the question pane may be sent or presented to the user using one communication channel or device (e.g., through a browser on a desktop computer), while the user answer may be submitted using another communication channel or device (e.g., through a text message on a smartphone). This multi-channel / device communication may provide a "possession" factor for security in the authentication process.
[0141] In certain example implementations, the techniques disclosed herein can provide increased confidence that an individual is who they claim to be based on the individual's ability to provide correct answers to authentication questions. Certain example implementations can help minimize the likelihood that a fraudster will obtain the information needed to correctly answer the questions.
[0142] Some implementations may also impose a time limit on receiving an acknowledgement response. In some implementations, the time limit is less than one minute.
[0143] In some implementations, in response to an incorrect or incomplete answer, an indication of authentication failure or additional feedback may be sent to the user's computing device for display.
[0144] Certain example implementations of the disclosed technology can effectively determine and manage identity fraud risks. Certain implementations can be used to detect suspicious and / or fraudulent activities associated with the process of establishing a new account and / or requesting goods and services. For example, a user seeking to establish a new account (such as a credit account, a bank account, a utility account, etc.) or apply for benefits or services (such as a tax refund, etc.) can provide a basic set of user information, which can include personally identifiable information (PII), such as name, address, telephone number, social security number, etc. In some implementations, the user information provided can include information such as a username, for example, which may not be technically considered PII, but some systems can use this information to identify the user. In an example implementation, all or part of the user information set can be used to query one or more public and / or private databases to obtain independent information. In some example implementations, the independent information can be processed to determine / detect / score risk indicators. According to an example implementation of the disclosed technology, an account applicant who fails authentication may not be allowed to proceed.
[0145] When user authentication fails, certain example embodiments of the disclosed technology may allow for offline, manual, and / or custom verification of the user's identity. For example, some legitimate users may fail due to various factors. In these cases, appropriate authentication may be obtained through offline, manual, and / or custom verification. For example, in one implementation, a user who fails authentication may be asked to provide additional proof of identity. In another example implementation, a user who fails one of the stages may be asked to appear in person at the supplier's location for further questioning and / or record keeping.
[0146] For example, certain embodiments utilize a non-fair credit reporting act (non-FCRA) implementation so that if a user fails at one or more stages, that information will not be used to deny employment, credit, etc. In this case, the vendor that the user is seeking authentication from can offer other offline, manual, and / or custom verification options. However, if the user passes the open question authentication, additional processes can be utilized to initiate authentication, such as biometric authentication. Furthermore, if the user passes the open question authentication process, certain implementations of the disclosed technology can provide an effective means of identity authentication.
[0147] According to example implementations, certain technical effects may be provided, such as creating certain systems and methods that can reduce fraud losses and improve operational efficiency. Example implementations of the disclosed technology may provide further technical effects by providing systems and methods for detecting identity fraud. Certain implementations of the disclosed technology may also provide the technical effect of authenticating user identities through natural language processing.
[0148] In some example implementations of the disclosed technology, the identity authentication process can be implemented using any number of hardware and / or software applications, which are executed to facilitate any operation. In an example implementation, one or more I / O interfaces can facilitate the communication between the identity authentication system and one or more input / output devices. For example, a universal serial bus port, a serial port, a disk drive, a compact disc read-only memory (Compact Disc Read-Only Memory, CD-ROM) drive and / or one or more user interface devices such as a display, a keyboard, a keypad, a mouse, a control panel, a touch screen display, a microphone, etc. can facilitate the interaction of the user with the authentication system. One or more I / O interfaces can be used to receive or collect data and / or user instructions from various input devices. In various implementations of the disclosed technology, the received data can be processed and / or stored in one or more memory devices by one or more computer processors as needed.
[0149] One or more network interfaces may facilitate connection of the authentication system input and output to one or more suitable networks and / or connections; for example, connections to facilitate communication with any number of sensors associated with the system. One or more network interfaces may also facilitate connection to one or more suitable networks; for example, a local area network, a wide area network, the Internet, a cellular network, a radio frequency network, a Bluetooth enabled network, or a wireless network for communicating with external devices and / or systems. TM (owned by Telefonaktiebolaget LM Ericsson) network, Wi-Fi enabled TM (owned by the Wi-Fi Alliance), satellite-based networks, any wired network, any wireless network, etc.
[0150] As required, the implementation of the disclosed technology may include Figure 2 , 3 Or an authentication system with more or less the components shown in 6.
[0151] The above text describes certain implementations of the disclosed technology with reference to block diagrams and flow charts of systems and methods and / or computer program products according to example implementations of the disclosed technology. It should be understood that one or more boxes in the block diagrams and flow charts, as well as combinations of boxes in the block diagrams and flows, can be implemented by computer executable program instructions, respectively. Similarly, according to some implementations of the disclosed technology, some boxes of the block diagrams and flow charts may not necessarily need to be executed in the order presented, or may not need to be executed at all.
[0152] These computer executable program instructions can be loaded onto a general-purpose computer, a special-purpose computer, a processor or other programmable data processing device to produce a specific machine, so that the instructions executed on the computer, processor, or other programmable data processing device create a tool (means) for realizing one or more functions specified in a flowchart box or multiple flowchart boxes. These computer program instructions can also be stored in a computer-readable memory, which can instruct a computer or other programmable data processing device to operate in a particular manner, so that the instructions stored in the computer programmable memory produce a product including an instruction tool for realizing one or more functions specified in the flowchart box. For example, the implementation of the disclosed technology can provide a computer program product, including a computer-usable medium containing a computer-readable program code or program instructions, and the computer-readable program code is suitable for being executed to realize one or more functions specified in the flowchart box. The computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating elements or steps are executed on a computer or other programmable device, thereby generating a computer-implemented process, so that the instructions executed on a computer or other programmable device provide elements or steps for realizing the functions specified in the flowchart box.
[0153] Therefore, the blocks of the block diagrams and flow charts support a combination of tools for performing specified functions, a combination of elements or steps for performing specified functions, and program instruction tools for performing specific functions. It will also be understood that each block of the block diagrams and flow charts and the combination of blocks in the block diagrams and flows can be implemented by a dedicated, hardware-based computer system or a combination of dedicated hardware and computer instructions that performs the specified functions, elements or steps.
[0154] Although certain implementations of the disclosed technology have been described in conjunction with various implementations that are currently considered to be most practical, it should be understood that the disclosed technology is not limited to the disclosed implementations, but is intended to cover various modifications and equivalent arrangements within the scope of the appended claims. Although specific terms are used herein, they are used only in a generic and descriptive sense and not for purposes of limitation.
[0155] The written description herein uses examples to disclose certain implementations that enable those skilled in the art to practice the disclosed technology, including making and using any device or system and performing any combined method. The patentable scope of the disclosed technology is defined in the claims and can include other examples that occur to those skilled in the art. Such other examples should be within the scope of the claims if they have structural elements that do not differ from the literal language of the claims, or if they include equivalent structural elements that do not differ substantially from the literal language of the claims.
Claims
1. A computer-implemented method for user authentication for accessing a service using a chatbot, the method comprising: receiving user information corresponding to the user; Parsing the received user information into a unique identifier UID of the user; Obtaining comprehensive data about the user that matches the UID from one or more data sources; generating a plurality of open-ended authentication questions based on the comprehensive data; outputting one or more of the plurality of open authentication questions for display on a user device associated with the user; receiving, in natural language, one or more user answers corresponding to one or more of the plurality of open authentication questions; Based on the comprehensive data, using a large language model (LLM) to evaluate the one or more user answers according to known ground truths; as well as In response to determining that a success count matches a predefined threshold number of matches, authenticating the user to access the service, the success count corresponding to the number of factually correct user answers corresponding to one or more of the plurality of open authentication questions.
2. The computer-implemented method of claim 1 , further comprising: In response to the user accessing the authentication page, collecting user device data and behavior data; as well as A digital profile associated with the user is generated.
3. The computer-implemented method of claim 1 , wherein: Generating the plurality of open authentication questions is also according to a predefined configuration.
4. The computer-implemented method of claim 3, wherein: The predefined configurations include one or more of the following: The number of open certification questions to generate; a threshold number of matches required for authentication, wherein the threshold number is less than or equal to the number of open authentication questions; a level of complexity of the open authentication questions to be generated, wherein the level of complexity includes a number of context variables associated with the user; as well as The level of detail desired in the one or more user answers.
5. The computer-implemented method of claim 1 , wherein: The LLM is used to generate the plurality of open certification questions.
6. The computer-implemented method of claim 1 , wherein: If the user answer is evaluated as factually correct, outputting a next question for display on the user device and incrementing the success count; If the user answer is evaluated to be factually incorrect, outputting a next question for display on the user device without incrementing the success count; If the user answer is in fact correct but incomplete, outputting additional instructions for display on the user device to indicate the missing information without incrementing the success count; as well as If the user answer is incorrect and incomplete, additional instructions are output for display on the user device to indicate the missing information without incrementing the success count.
7. The computer-implemented method of claim 1 , wherein: The one or more data sources include one or more of: court records, birth certificate records, Census Bureau records, county records, property records, real estate records, court records, business records, school records, education records, web pages, professional license records, historical records, social media records, marketing records, publications, private records, media records, background records, proprietary data, and derived data records.
8. A computer-implemented method for user authentication for accessing a service using a chatbot, the method comprising: receiving user information corresponding to the user; Parsing the received user information into a unique identifier UID of the user; Obtaining comprehensive skill- or knowledge-based data about the user that matches the UID from one or more data sources; generating a plurality of skill-based or knowledge-based certification questions based on the comprehensive skill-based or knowledge-based data; outputting one or more of the plurality of skills- or knowledge-based certification questions for display on a user device; receiving, in natural language, one or more user answers corresponding to one or more of the plurality of skill- or knowledge-based certification questions; According to the skill-based or knowledge-based comprehensive data, using a large language model (LLM) to evaluate the one or more user answers according to known basic facts; as well as In response to determining that a success count matches a predefined threshold number of matches, authenticating the user to access the service, the success count corresponding to the number of factually correct user answers corresponding to one or more of the multiple skill-based or knowledge-based authentication questions.
9. The computer-implemented method of claim 8, further comprising: In response to the user accessing the authentication page, collecting user device data and behavior data; as well as A digital profile associated with the user is generated.
10. The computer-implemented method of claim 8, wherein: Generating the plurality of skills- or knowledge-based certification questions is also according to a predefined configuration.
11. The computer-implemented method of claim 8, wherein: If the user answer is evaluated as factually correct, outputting a next question for display on the user device and incrementing the success count; If the user answer is evaluated to be factually incorrect, outputting a next question for display on the user device without incrementing the success count; If the user answer is in fact correct but incomplete, outputting additional instructions for display on the user device to indicate the missing information without incrementing the success count; as well as If the user answer is incorrect and incomplete, additional instructions are output for display on the user device to indicate the missing information without incrementing the success count.
12. The computer-implemented method of claim 8, wherein: The one or more data sources include one or more of: court records, birth certificate records, Census Bureau records, county records, property records, real estate records, court records, business records, school records, education records, web pages, professional license records, historical records, social media records, marketing records, publications, private records, media records, background records, proprietary data, and derived data records.
13. The computer-implemented method of claim 8, further comprising, in response to the user accessing an authentication page, collecting user device and behavioral data to generate a digital profile associated with the user.
14. The computer-implemented method of claim 8, wherein: The one or more skill- or knowledge-based authentication questions include a photo of a device associated with the comprehensive skill- or knowledge-based data about the user that matches the UID.
15. The computer-implemented method of claim 8, wherein: One or more of the plurality of skills- or knowledge-based certification questions includes one or more open-ended questions.
16. A system for user authentication via a chatbot, the system comprising: a data repository configured to store user identification information; a user interface configured to display authentication questions and receive user answers from a user; at least one memory for storing data and computer executable instructions; and at least one processor configured to access the at least one memory and further configured to execute the computer executable instructions, such that the at least one processor: receiving user information corresponding to the user; Parsing the received user information into a unique identifier UID of the user; Obtaining comprehensive data about the user that matches the UID from one or more data sources; generating a plurality of authentication questions based on the comprehensive data; outputting one or more of the plurality of authentication questions for display on a user device; receiving, in natural language, one or more user answers corresponding to one or more of the plurality of authentication questions; Based on the comprehensive data, using a large language model (LLM) to evaluate the user answer according to known basic facts; outputting an indication corresponding to the evaluation for display on a user device; as well as In response to determining that a success count matches a predefined threshold number of matches, the user is authenticated to access the service, the success count corresponding to the number of factually correct user answers corresponding to one or more of the plurality of authentication questions.
17. The system of claim 16, wherein: The plurality of certification questions include one or more of open-ended questions, skill-based questions, and knowledge-based questions.
18. The system of claim 16, wherein: The system is also configured to: In response to the user accessing the authentication page, collecting user device data and behavior data; and A digital profile associated with the user is generated.
19. The system of claim 16, wherein: The authentication questions are also generated according to a predefined configuration.
20. The system of claim 16, wherein: The system is also configured to When the user answer is evaluated as factually correct, outputting a next question for display on the user device and incrementing the success count; When a user answer is evaluated as factually incorrect, outputting a next question for display on the user device without incrementing the success count; When the user answer is in fact correct but incomplete, outputting additional instructions for display on the user device to indicate the missing information without incrementing the success count; as well as When the user answer is incorrect and incomplete, additional instructions are output for display on the user device to indicate the missing information without incrementing the success count.
Citation Information
Patent Citations
Adjusting biometric detection thresholds based on recorded behavior
US11860985B2
Detection of use of a remote access tool for secure transactions
US20240037541A1
Systems and methods for detecting hand usage in keyboard interaction
US20240256120A1
Systems and methods for detecting browser mode
US20240259394A1
Systems and methods for detecting advanced users by detection of the use of multiple windows or tabs
US20240297898A1