Adaptive Secondary Authentication Using Personalized Questions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online authentication systems rely on single-factor authentication, which can be compromised if primary credentials such as passwords are stolen, leading to potential fraudulent activities.

Innovation Solution

Implementing a multi-factor authentication system that uses a question generation engine to create personalized questions based on user account history, a confidence engine to assess the legitimacy of user identity, and a quality engine to adjust and improve question difficulty, providing an additional layer of security beyond traditional password-based authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single-factor authentication is used, then ease of operation is improved, but reliability deteriorates

Engineering Contradiction:
Improveease of authenticationVSAvoidaccount security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple independent factors: something the user knows (password), something the user has (device identifier), and something about the user's behavior (biometric patterns, typing rhythm). This segmentation ensures that compromising one factor does not lead to complete system failure, thus improving reliability while maintaining operational ease through automated multi-factor verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-collecting and analyzing user behavior data during normal authentication interactions. Biometric templates, typing patterns, and device usage characteristics are established beforehand, enabling the system to automatically verify identity without requiring additional user effort during critical authentication moments, thus maintaining ease of operation while enhancing security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multi-factor authentication is implemented, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improveaccount securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple authentication factors are merged into a unified verification process. The password check, device identifier validation, and biometric pattern recognition are combined into a single authentication flow that the user experiences as one seamless operation. This merging reduces the perceived complexity for users while maintaining the enhanced security benefits of multi-factor authentication.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs self-service by automatically collecting, analyzing, and verifying authentication factors without requiring manual intervention. Device identifiers are automatically retrieved, biometric data is captured and processed, and verification decisions are made algorithmically. This self-service approach handles the complexity internally while presenting a simple interface to users, thus improving reliability without increasing operational complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If personalized questions are generated, then reliability is improved, but loss of information increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system applies local quality by selectively using different types of personal information for different authentication purposes. Generic demographic data is used for creating baseline profiles, while sensitive personal information is reserved for verification questions only when authentication is suspected. This localized use of information maintains authentication accuracy while minimizing unnecessary privacy intrusion.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes parameters of information usage based on risk assessment. During low-risk transactions, minimal personal information is accessed. When suspicious activity is detected, the system adjusts parameters to access additional verification data. This parameter-based control ensures authentication accuracy is maintained only when necessary, thereby reducing overall information loss and privacy intrusion.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9530133B2Adaptive secondary authentication criteria based on account data
Publication Date: 2016.12.27 APPLE INC
  • US9530133B2 patent drawing
  • US9530133B2 patent drawing
  • US9530133B2 patent drawing

AI summary

An authentication challenge system for performing secondary authentication for an account associated with an online store is described. In one embodiment, the authentication challenge system includes a question generation engine, which can derive a series of questions based upon activity associated with a user account of an online store; a network interface, which can transport the series of one or more questions derived by the question generation engine to authenticate the user to the online store; a confidence engine, which can determine a required confidence level for a successful authentication, and can compute a confidence score of the user identity; and a quality engine, which can adjust the question generation engine and the confidence engine based upon an analysis of question and answer metrics across multiple accounts of the online store. The online store can include digital media, such as music, movies, books or applications for electronic computing devices.