Recognition-Based Log-In Verification Using Extracted Device Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security verification methods, such as security questions, are inadequate due to easily duplicable answers and reliance on human recall, which can be challenging and insecure, especially when the user's device is unavailable.
Innovation Solution
An automated data-extractor module extracts personalized data from a user's device and presents it for recognition-based verification, using a combination generator to confirm identity through multiple cycles of verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security questions are used for verification, then the system provides security verification capability, but the answers are easily duplicable and can be researched by third parties
Solution Approach 1:
The patent extracts personal data directly from the user's device (photos, contacts, messages, files) and uses this extracted data as the basis for verification questions. This removes the vulnerability of traditional static security questions by dynamically generating questions from unique device-specific data that cannot be easily researched or duplicated by third parties.
Solution Approach 2:
The system performs preliminary data extraction and analysis from the user's device before the verification process. It pre-processes the personal data to create a pool of verification candidates, so that when verification is needed, the system can quickly generate appropriate questions without requiring real-time analysis during the verification moment.
2Reliability
If recall-based security questions are used, then the system verifies user identity, but it challenges users who have difficulty with unassisted memory recall
Solution Approach 1:
The patent introduces an intermediary system that acts as a bridge between the user's memory and the verification process. Instead of directly asking users to recall information, the system presents extracted personal data (photos, contacts, messages) as visual or contextual cues that facilitate recognition and recall, making the verification process more accessible to users with memory challenges.
Solution Approach 2:
The patent replaces the mechanical process of unassisted human recall with an automated data extraction and presentation system. The system automatically extracts relevant personal data from the device, processes it into appropriate verification formats, and presents it to the user, substituting the manual recall effort with an automated assistance system.
3Adaptability or versatility
If subjective security questions are used, then the system allows flexible answer choices, but the answers can change over time reducing security consistency
Solution Approach 1:
The system uses data that the user has already stored and organized in their own device, such as photos, contacts, and messages. This self-service approach leverages the user's existing digital footprint to create verification questions, ensuring that the data is both personally meaningful (providing flexibility) and stable (since it's already stored in the device). The user's own device serves as the source of truth for verification data.
4Ease of operation
If automated data extraction is implemented, then the system reduces reliance on human recall, but it requires access to the user's personal device data
Solution Approach 1:
The patent implements a universal data extraction framework that can handle multiple types of personal data (photos, contacts, messages, files) through a single integrated system. This multi-functional approach allows the system to extract various data types using common extraction mechanisms, reducing overall system complexity compared to implementing separate extraction systems for each data type.
Data Source
AI summary
The present invention is an automated data-extractor which is pre-set to extract specified data from a user's personal device (such as but not limited to a smart phone), and then to present that extracted data to the user for verification by recognition, not by recall, as part of a security log-in protocol. Recognition is much easier, for a user, than outright recall, and therefore the present technology provides a user-friendly way to verify an individual during a log-in procedure. The invention thus embraces at least a two modules containing (a) a data extractor module and (b) a combination generator module which presents the extracted data to the user in a question-and-answer mode to prompt “yes” or “no” verification of the data extracted, but requiring only recognition as to the user's own data, not completely unprompted recall.
