Automated Knowledge-Based Authentication List Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing knowledge-based authentication (KBA) systems require manual and labor-intensive processes for creating and maintaining white lists and black lists, which are prone to inaccuracies due to data availability issues and context-dependent sensitivity challenges.

Innovation Solution

Automated techniques for discovering and generating white lists and black lists by analyzing entity-related information and querying entity agents for approval, using data analysis modules and feedback mechanisms to identify individuals and terms for exclusion from authentication processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual white list creation is used, then authentication security is maintained, but labor intensity and time consumption increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidlist creation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables automatic self-service for white list and black list management by analyzing entity-related information and automatically identifying individuals and terms for exclusion, eliminating the need for manual entry while maintaining security requirements

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of entity-related information before authentication operations to pre-identify white list individuals and black list terms, so that when authentication is needed, the lists are already prepared and approved

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual black list creation is used, then sensitive terms are excluded, but accuracy decreases due to context-dependent sensitivity challenges

Engineering Contradiction:
Improvesensitive term exclusionVSAvoidterm sensitivity accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system incorporates feedback mechanisms where entity agents review and approve the automatically identified black list terms, allowing correction and refinement of context-dependent sensitivity judgments to improve accuracy

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary analysis of entity-related information to pre-identify potentially sensitive terms before authentication operations, allowing for proactive review and approval to ensure accurate context-dependent sensitivity assessment

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If complete manual list creation is required, then data accuracy can be verified, but the process becomes vulnerable to inaccuracies due to data availability issues

Engineering Contradiction:
Improvelist data accuracyVSAvoidprocess robustness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system automatically analyzes entity-related information to self-generate white list and black list candidates, reducing human error in data entry while maintaining verification through agent approval processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback loops where entity agents review automatically generated list candidates, providing verification and correction opportunities that maintain data accuracy while reducing vulnerability to manual entry errors

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9356919B1Automated discovery of knowledge-based authentication components
Publication Date: 2016.05.31 EMC IP HLDG CO LLC
  • US9356919B1 patent drawing
  • US9356919B1 patent drawing
  • US9356919B1 patent drawing

AI summary

Methods, apparatus and articles of manufacture for automated discovery of knowledge-based authentication components are provided herein. A method includes analyzing entity-related information to identify one or more individuals within the entity for exclusion from one or more authentication requirements in connection with one or more operations associated with the entity, wherein said analyzing is based on one or more pre-defined parameters, and querying an agent of the entity to approve each of the one or more individuals identified within the entity for exclusion from the one or more authentication requirements.