Authentication via Personal Interaction History Questions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing popularity of remote access to computer systems and applications has led to a convenience and security issue due to the need for multiple usernames and passwords, with Single Sign-On (SSO) solutions being a single point of failure and compromising security if compromised or forgotten.

Innovation Solution

A method and system for authenticating users by generating questions based on their personal historical interaction data with various applications, using an SSO system to access and retrieve relevant information, and evaluating answers to determine the likelihood of the user's legitimacy through a series of questions related to their interaction history.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manage multiple authentication credentials for different applications, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically collects interaction history data from multiple applications and generates authentication questions without requiring manual user setup. The user simply answers questions about their own interaction history, and the system handles data aggregation, question generation, and authentication evaluation automatically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The SSO system acts as an intermediary that collects interaction history data from multiple applications, processes this data into authentication questions, and uses the answers to authenticate the user across all connected applications. This mediator eliminates the need for users to manage separate credentials while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If Single Sign-On system is used to improve convenience, then ease of operation is improved, but reliability deteriorates due to single point of failure

Engineering Contradiction:
ImproveconvenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Instead of relying on a single password credential, the authentication is segmented into multiple independent interaction history questions. Each question represents a separate piece of authentication evidence, and the combination of answers provides robust security without creating a single point of failure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the authentication parameter from static passwords to dynamic interaction history questions. These questions are generated based on actual user behavior patterns collected from multiple applications, making the authentication both convenient and resistant to single-point failures.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If static passwords are used for authentication, then ease of operation is improved, but security deteriorates due to password reuse and weak passwords

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Instead of requiring users to remember complex passwords, the system inverts the approach by having users answer questions about their own interaction history. This leverages the user's natural knowledge of their own behavior patterns rather than relying on their ability to remember and create secure passwords.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP3241136B1User authentication based on personal access history
Publication Date: 2020.07.29 ONESPAN INT GMBH
  • EP3241136B1 patent drawingFigure 1
  • EP3241136B1 patent drawingFigure 2
  • EP3241136B1 patent drawingFigure 3

AI summary

Methods and systems are provided for authenticating a user using data related to the historical interactions of the user with computer based applications.