Dynamic Knowledge-Based User Authentication via Extracted Resource Characteristics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user authentication techniques are inadequate when users lose or forget their credentials, as they often require readily available passwords or tokens, leading to inconvenience, privacy concerns, and high costs associated with out-of-band channels or biometric systems.

Innovation Solution

Dynamic knowledge-based user authentication methods that verify user knowledge of extracted characteristics from previous interactions with a protected resource, such as files, contacts, or multimedia objects, allowing access without requiring predetermined credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication techniques require predetermined credentials (passwords, tokens), then security is maintained, but user access becomes problematic when credentials are lost or forgotten

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary action by extracting and storing characteristics of previously accessed resources (files, contacts, multimedia objects) during normal authenticated operations. These pre-extracted characteristics serve as authentication credentials without requiring users to remember or carry predetermined passwords or tokens, resolving the contradiction between maintaining security and ensuring convenient access when credentials are lost.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If out-of-band channels (email, administrator contact) are used to provide missing credentials, then access can be restored, but cost and time requirements increase significantly

Engineering Contradiction:
Improveaccess restoration capabilityVSAvoidtime and cost for credential recovery
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables self-service by allowing users to authenticate using characteristics automatically extracted from their own previous resource access patterns stored in the system. Users can recover access independently without requiring administrator intervention or contacting support channels, eliminating the time and cost associated with traditional out-of-band credential recovery processes.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If biometric authentication is used as backup for lost credentials, then access can be provided, but system cost and complexity increase

Engineering Contradiction:
Improvebackup authentication capabilityVSAvoidsystem cost and setup requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system uses copying by creating virtual copies of authentication credentials in the form of extracted characteristics (file identifiers, contact information, multimedia object metadata) that replicate the authentication function without requiring physical biometric sensors or complex hardware. These copied characteristics are stored in memory and can be used for authentication, providing backup capability at minimal cost and complexity.

Inventive Principle:
Principle #26Copying

4Ease of operation

If life questions or challenge questions are used for authentication, then access can be provided without credentials, but privacy concerns and security limitations arise

Engineering Contradiction:
Improvecredential-free access capabilityVSAvoidsecurity and privacy protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies local quality by extracting and using characteristics specific to each user's local resource access patterns (particular files, contacts, or multimedia objects they have accessed) rather than using generic life questions or challenge questions. This localized approach to authentication provides stronger security and privacy protection while maintaining ease of access, as the characteristics are uniquely tied to the user's actual usage patterns rather than relying on potentially compromised general knowledge.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9674177B1Dynamic knowledge-based user authentication without need for presentation of predetermined credential
Publication Date: 2017.06.06 RSA SECURITY USA LLC
  • US9674177B1 patent drawing
  • US9674177B1 patent drawing
  • US9674177B1 patent drawing

AI summary

A personal computing device, server or other type of processing device authenticates a user attempting to access a protected resource by verifying user knowledge of one or more extracted characteristics of stored information indicative of an internal operating state of that resource. The one or more extracted characteristics are characteristics that would likely be known to the user if that user had made one or more previous authenticated accesses to the protected resource. For example, the extracted characteristics may be indicative of a manner in which the user had utilized the protected resource during the one or more previous authenticated accesses to the protected resource. The processing device receives input from the user regarding the one or more extracted characteristics, and grants or denies access to the protected resource based at least in part on the input received from the user.