Recognition-Based Log-In Verification Using Extracted Device Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security verification methods, such as security questions, are inadequate due to easily duplicable answers and reliance on human recall, which can be challenging and insecure, especially when the user's device is unavailable.

Innovation Solution

An automated data-extractor module extracts personalized data from a user's device and presents it for recognition-based verification, using a combination generator to confirm identity through multiple cycles of verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security questions are used for verification, then the system provides security verification capability, but the answers are easily duplicable and can be researched by third parties

Engineering Contradiction:
Improvesecurity verification reliabilityVSAvoidease of answer duplication
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts personal data directly from the user's device (photos, contacts, messages, files) and uses this extracted data as the basis for verification questions. This removes the vulnerability of traditional static security questions by dynamically generating questions from unique device-specific data that cannot be easily researched or duplicated by third parties.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary data extraction and analysis from the user's device before the verification process. It pre-processes the personal data to create a pool of verification candidates, so that when verification is needed, the system can quickly generate appropriate questions without requiring real-time analysis during the verification moment.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If recall-based security questions are used, then the system verifies user identity, but it challenges users who have difficulty with unassisted memory recall

Engineering Contradiction:
Improveidentity verification accuracyVSAvoiduser recall difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system that acts as a bridge between the user's memory and the verification process. Instead of directly asking users to recall information, the system presents extracted personal data (photos, contacts, messages) as visual or contextual cues that facilitate recognition and recall, making the verification process more accessible to users with memory challenges.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical process of unassisted human recall with an automated data extraction and presentation system. The system automatically extracts relevant personal data from the device, processes it into appropriate verification formats, and presents it to the user, substituting the manual recall effort with an automated assistance system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If subjective security questions are used, then the system allows flexible answer choices, but the answers can change over time reducing security consistency

Engineering Contradiction:
Improveanswer flexibilityVSAvoidanswer consistency over time
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The system uses data that the user has already stored and organized in their own device, such as photos, contacts, and messages. This self-service approach leverages the user's existing digital footprint to create verification questions, ensuring that the data is both personally meaningful (providing flexibility) and stable (since it's already stored in the device). The user's own device serves as the source of truth for verification data.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If automated data extraction is implemented, then the system reduces reliance on human recall, but it requires access to the user's personal device data

Engineering Contradiction:
Improveverification automation levelVSAvoiddata extraction system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal data extraction framework that can handle multiple types of personal data (photos, contacts, messages, files) through a single integrated system. This multi-functional approach allows the system to extract various data types using common extraction mechanisms, reducing overall system complexity compared to implementing separate extraction systems for each data type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250385902A1Automatic Extraction of Log-In Security Questions and Answers from Personal Devices
Publication Date: 2025.12.18 DUQUESNE UNIVERSITY
  • US20250385902A1 patent drawing

AI summary

The present invention is an automated data-extractor which is pre-set to extract specified data from a user's personal device (such as but not limited to a smart phone), and then to present that extracted data to the user for verification by recognition, not by recall, as part of a security log-in protocol. Recognition is much easier, for a user, than outright recall, and therefore the present technology provides a user-friendly way to verify an individual during a log-in procedure. The invention thus embraces at least a two modules containing (a) a data extractor module and (b) a combination generator module which presents the extracted data to the user in a question-and-answer mode to prompt “yes” or “no” verification of the data extracted, but requiring only recognition as to the user's own data, not completely unprompted recall.