Activity-Based Identity Validation Using AI-Generated Questions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user validation methods, such as passwords and biometrics, are becoming increasingly vulnerable to unauthorized access, necessitating a more robust and dynamic approach to verify user identity.

Innovation Solution

A user identity validation system that generates questions based on a legitimate user's past activity, using Large Language Models (LLMs) to assess responses, providing a score-based authentication that can be combined with or used independently of credential-based or biometric validation, and isolating data interactions to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional password-based validation is used, then ease of operation is improved, but security reliability deteriorates due to password leakage vulnerabilities

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary validation mechanism that uses third-party data sources and AI models to verify user identity without relying on passwords. The system acts as a mediator between the user and the authentication system, using activity-based questions and AI-generated responses to validate identity securely without requiring traditional credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the authentication parameters from static credentials (passwords) to dynamic activity-based validation. Instead of verifying what the user knows (passwords), the system verifies what the user has done (activities) by generating questions based on user behavior patterns and comparing AI-generated responses with actual responses.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multi-factor authentication methods like one-time codes and biometrics are used, then security reliability is improved, but vulnerability to theft and unauthorized access increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidvulnerability to device theft and credential theft
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary validation by establishing a baseline of user activity patterns before the actual authentication event. The system continuously monitors and stores user behavior data, creating a predictive model of legitimate activity. During authentication, the system generates questions based on this pre-established activity pattern, making it difficult for thieves to predict or fabricate valid responses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces mechanical/biometric authentication systems with an AI-based cognitive validation system. Instead of relying on physical biometrics that can be copied or stolen, the system uses AI models to analyze and validate user behavior patterns, substituting the authentication mechanism from physical/biological traits to digital cognitive validation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If activity-based validation questions are generated using AI, then security reliability is improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial action by generating only the necessary number of validation questions based on the user's activity level and risk profile. The system doesn't always perform full AI validation - it selectively applies AI-generated questions only when needed, based on the authentication context and user behavior patterns, reducing unnecessary processing complexity.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent uses AI models to create synthetic validation questions and expected responses that copy the patterns of legitimate user behavior. The AI model learns from historical user activity data and generates fake-but-plausible questions that would be difficult for attackers to predict, effectively copying legitimate authentication patterns without requiring complex verification processes.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP4657801A1User identity validation
Publication Date: 2025.12.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4657801A1 patent drawingFigure 1a
  • EP4657801A1 patent drawingFigure 1b
  • EP4657801A1 patent drawingFigure 2

AI summary

A data item is obtained that is representative of an activity associated with a legitimate user. A fact is derived from the data item and a question about the activity associated with the legitimate user activity is generated from the fact. An expected answer to the question is also generated based on the fact, and compared with an end-user response to the question in an end-user authentication process. In certain implementations, Large Language Models (LLM) are used to aid the user authentication process.