Activity Log-Based KBA Question Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional knowledge-based authentication (KBA) systems are vulnerable to security breaches when hackers access publicly available databases, leading to compromised security due to limited diversity in fact sources and the risk of repeating questions.

Innovation Solution

Generating KBA questions based on facts from user activity logs, such as web browsing history, to create a diverse set of questions that are less susceptible to being answered by hackers even if they breach a fact server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional KBA uses publicly available databases (LexisNexis, credit bureaus, motor vehicle registries) as fact sources, then the system can access user facts for authentication, but the security is compromised when hackers breach these servers and gain access to the information needed for generating KBA questions

Engineering Contradiction:
ImprovesecurityVSAvoidhacker access to fact sources
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary mechanism (activity log) between the user and the fact sources. Instead of directly accessing public databases, the system uses activity logs as a mediator to derive facts about the user from their digital footprint, thereby preventing direct hacker access to sensitive databases while maintaining authentication capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of user information through activity logs rather than using the original public databases directly. The activity log serves as a derived copy that contains sufficient information for authentication without exposing the sensitive underlying data sources to hackers

Inventive Principle:
Principle #26Copying

2Reliability

If conventional KBA uses limited publicly available databases as fact sources, then the system can maintain simple fact collection, but the number of original KBA questions becomes limited and repeat questions reduce security

Engineering Contradiction:
ImprovesecurityVSAvoiddiversity of fact sources
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the fact sources dynamic by using activity logs that continuously capture user behavior patterns. Instead of static public databases, the system dynamically derives facts from ongoing user activities, ensuring an ever-expanding and diverse question pool that adapts to changing user behaviors

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent transitions from one-dimensional fact sources (single public database) to multi-dimensional fact sources by aggregating data from multiple activity log entries, web pages, and digital footprints. This dimensional expansion provides diverse fact sources while maintaining system simplicity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9514407B1Question generation in knowledge-based authentication from activity logs
Publication Date: 2016.12.06 EMC IP HLDG CO LLC
  • US9514407B1 patent drawing
  • US9514407B1 patent drawing
  • US9514407B1 patent drawing

AI summary

An improved technique involves generating KBA questions based on facts from fact sources pointed to by an activity log. A KBA system obtains an activity log from a computer of a user in an organization. For example, the computer records the user's web browsing history. The KBA system then considers each entry in the activity log as a source of facts for deriving KBA questions. In the case of a web browsing history, the KBA system generates facts from web pages that the user visited. The KBA system then derives new KBA questions from the facts so derived.