Dynamic Authentication Challenges via Social Network Activity Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods are ineffective in distinguishing fraudulent login attempts, as they rely on static information that can be easily compromised by malicious users.

Innovation Solution

A system and method that generates user authentication challenges based on social network activity information and patterns, analyzing the account owner's social network activity to create dynamic challenges that are specific to their behavior, thereby enhancing security against fraudulent attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static authentication information (favorite restaurant, first pet name) is used for challenges, then the authentication system is simple to implement, but fraudulent users can easily obtain this information and successfully bypass authentication

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static authentication information into dynamic challenges by analyzing social network activity patterns. Instead of using fixed data like favorite restaurants, the system generates challenges based on real-time or recent social network behavior, making the authentication data dynamic and difficult for fraudsters to obtain in advance

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary analysis of social network activity patterns before generating authentication challenges. By pre-analyzing user behavior patterns, the system prepares authentication data that reflects actual user behavior, enabling more effective challenges before the authentication moment arrives

Inventive Principle:
Principle #10Preliminary action

2Reliability

If social network activity information is analyzed to create personalized challenges, then authentication security is significantly improved, but the system complexity and computational resources increase

Engineering Contradiction:
Improveauthentication securityVSAvoidanalysis engine complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential and relevant features from social network activity data to create authentication challenges. Instead of analyzing all social network data, the system identifies and extracts key behavioral patterns that are sufficient for authentication, reducing computational complexity while maintaining security effectiveness

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The social network activity analysis engine serves multiple functions: it monitors user behavior for security purposes, generates authentication challenges, and potentially informs other security decisions. This multi-functionality justifies the added complexity by providing multiple benefits from a single analytical system

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9037864B1Generating authentication challenges based on social network activity information
Publication Date: 2015.05.19 GOOGLE LLC
  • US9037864B1 patent drawing
  • US9037864B1 patent drawing
  • US9037864B1 patent drawing

AI summary

A system and method for generating user authentication challenges based at least in part on an account owner's social network activity information. A login request including an account owner's correct username and password as well as additional login information is received from a user. The login attempt is detected as a potentially fraudulent based on the additional login information from the user. The account owner's social network activity information is analyzed. An authentication challenge based at least in part on the account owner's social network activity information is generated and sent for display. The login request is allowed or denied based on the completion on the authentication challenge.