Dynamic Knowledge-Based User Authentication via Extracted Resource Characteristics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user authentication techniques are inadequate when users lose or forget their credentials, as they often require readily available passwords or tokens, leading to inconvenience, privacy concerns, and high costs associated with out-of-band channels or biometric systems.
Innovation Solution
Dynamic knowledge-based user authentication methods that verify user knowledge of extracted characteristics from previous interactions with a protected resource, such as files, contacts, or multimedia objects, allowing access without requiring predetermined credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication techniques require predetermined credentials (passwords, tokens), then security is maintained, but user access becomes problematic when credentials are lost or forgotten
Solution Approach 1:
The system performs preliminary action by extracting and storing characteristics of previously accessed resources (files, contacts, multimedia objects) during normal authenticated operations. These pre-extracted characteristics serve as authentication credentials without requiring users to remember or carry predetermined passwords or tokens, resolving the contradiction between maintaining security and ensuring convenient access when credentials are lost.
2Ease of operation
If out-of-band channels (email, administrator contact) are used to provide missing credentials, then access can be restored, but cost and time requirements increase significantly
Solution Approach 1:
The system enables self-service by allowing users to authenticate using characteristics automatically extracted from their own previous resource access patterns stored in the system. Users can recover access independently without requiring administrator intervention or contacting support channels, eliminating the time and cost associated with traditional out-of-band credential recovery processes.
3Ease of operation
If biometric authentication is used as backup for lost credentials, then access can be provided, but system cost and complexity increase
Solution Approach 1:
The system uses copying by creating virtual copies of authentication credentials in the form of extracted characteristics (file identifiers, contact information, multimedia object metadata) that replicate the authentication function without requiring physical biometric sensors or complex hardware. These copied characteristics are stored in memory and can be used for authentication, providing backup capability at minimal cost and complexity.
4Ease of operation
If life questions or challenge questions are used for authentication, then access can be provided without credentials, but privacy concerns and security limitations arise
Solution Approach 1:
The system applies local quality by extracting and using characteristics specific to each user's local resource access patterns (particular files, contacts, or multimedia objects they have accessed) rather than using generic life questions or challenge questions. This localized approach to authentication provides stronger security and privacy protection while maintaining ease of access, as the characteristics are uniquely tied to the user's actual usage patterns rather than relying on potentially compromised general knowledge.
Data Source
AI summary
A personal computing device, server or other type of processing device authenticates a user attempting to access a protected resource by verifying user knowledge of one or more extracted characteristics of stored information indicative of an internal operating state of that resource. The one or more extracted characteristics are characteristics that would likely be known to the user if that user had made one or more previous authenticated accesses to the protected resource. For example, the extracted characteristics may be indicative of a manner in which the user had utilized the protected resource during the one or more previous authenticated accesses to the protected resource. The processing device receives input from the user regarding the one or more extracted characteristics, and grants or denies access to the protected resource based at least in part on the input received from the user.


