Dynamic Challenge Question Generation for User Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user authentication methods, such as username and password combinations, are prone to forgetfulness and vulnerability to security system hackers, especially when predefined security questions can be easily answered by others due to publicly available user profile information.

Innovation Solution

A system that generates personalized challenge questions based on user history data and location information, dynamically changing these questions to prevent hackers from guessing the answers, and allowing multiple-choice or natural language responses to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If username and password authentication is used, then user authentication can be performed, but the system is vulnerable to security breaches and user forgetfulness

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic challenge questions that change over time and are generated based on user behavior patterns. The authentication system transitions from static passwords to dynamic, context-aware challenges that adapt to user interactions, making the authentication process both more secure and more convenient for legitimate users.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system automatically generates challenge questions based on user profile data and behavior patterns without requiring manual setup by security administrators. The authentication mechanism serves itself by leveraging existing user interaction data to create personalized security challenges.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If predefined security questions are used, then password recovery is enabled, but hackers can easily answer them using publicly available user profile information

Engineering Contradiction:
Improvepassword recovery capabilityVSAvoidsecurity against hackers
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system pre-collects user profile data and behavior patterns during normal usage, storing this information for future authentication challenges. By preparing authentication challenges in advance based on accumulated user data, the system ensures that security questions are always relevant and difficult for hackers to guess.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The challenge questions dynamically change based on multiple parameters including user behavior patterns, profile information, and interaction history. This parameter-driven approach ensures that security questions remain adaptive and resistant to hacking while maintaining password recovery functionality.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If complex authentication mechanisms are implemented, then security is enhanced, but the cognitive load on users increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system leverages user-generated data from normal platform interactions to automatically create personalized challenge questions. This self-service approach eliminates the need for users to manually set up complex security measures while maintaining high security standards through behavior-based authentication.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8955058B2Automatically generating challenge questions inferred from user history data for user authentication
Publication Date: 2015.02.10 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8955058B2 patent drawing
  • US8955058B2 patent drawing
  • US8955058B2 patent drawing

AI summary

User authentication is provided. At least one of a social network and a business network of each user in a plurality of users is accessed. User history data of each user in the plurality of users is monitored in the at least one of the social network and the business network. Challenge questions requiring a user response are generated based on monitoring the user history data of the users. The user response to a generated challenge question is evaluated. A set of events is triggered based on evaluating the user response.