Dynamic Knowledge-Based Authentication System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems are vulnerable to fraudulent methods and man-in-the-middle attacks due to static authentication factors, easily hackable passwords, and brute-force login credentials, lacking sufficient security to ensure user identity validation.

Innovation Solution

A dynamic knowledge-based authentication system that utilizes private user information from third-party connected accounts to generate real-time authentication challenges, making it difficult for unauthorized users to access secured information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static authentication factors (OTP, static answers) are used, then authentication process is simple and fast, but security is insufficient and vulnerable to fraudulent methods

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static authentication factors into dynamic ones by continuously changing authentication challenges based on user behavior patterns, device characteristics, and contextual information. The authentication factors are no longer fixed but adapt in real-time, making them resistant to replay attacks and fraudulent methods while maintaining system feasibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple parameters simultaneously including authentication challenge content, validation criteria, and decision thresholds based on risk assessment. This dynamic parameter adjustment enhances security by adapting to different attack vectors and user contexts without requiring complete system redesign.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If constant authentication factors are used, then authentication is straightforward, but the system is vulnerable to man-in-the-middle attacks

Engineering Contradiction:
Improveresistance to man-in-the-middle attacksVSAvoidauthentication operation difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication factors become dynamic and context-dependent, changing with each authentication attempt based on user behavior analysis, device fingerprinting, and environmental context. This prevents man-in-the-middle attacks by ensuring that captured authentication data cannot be reused, while the system automatically manages the complexity through algorithmic generation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system automatically generates and manages dynamic authentication challenges without requiring user intervention to configure security parameters. The complexity of implementing dynamic factors is handled by the system itself through automated behavior analysis and challenge generation, keeping the user experience simple while enhancing security.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional authentication methods are used, then implementation is easy, but the system suffers from bad passwords, easily hackable credentials, and brute-force vulnerabilities

Engineering Contradiction:
Improveresistance to brute-force attacksVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic authentication challenges that adapt to detected attack patterns, making brute-force attacks ineffective. When multiple failed attempts or suspicious patterns are detected, the system automatically increases challenge complexity or switches authentication methods, creating a moving target that resists automated attacks while maintaining ease of use for legitimate users.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12107972B2System and method for dynamic knowledge-based authentication
Publication Date: 2024.10.01 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12107972B2 patent drawing
  • US12107972B2 patent drawing
  • US12107972B2 patent drawing

AI summary

The present disclosure relates to knowledge based authentication whereby a user is authenticated through third-party linked accounts. The method includes receiving an authentication request from a merchant computer, assessing one or more data fields to generate an authentication challenge for the user, connecting to one or more third-party account service provider to extract user-related data, generating the authentication challenge based on the extracted user-related data from the third-party account service provider, posing the authentication challenge to the user on a user device, receiving a response to the authentication challenge, and returning the authentication response to the merchant.