Dynamic Challenge-Response Authentication Using Transaction Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online authentication systems rely on static and easily guessable challenge questions, making them vulnerable to hacking and repetitive for users.

Innovation Solution

A non-repeatable challenge-response authentication system that generates user-specific, dynamic challenges based on recent transaction data, ensuring that each authentication session uses unique questions and answers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static challenge questions are used for authentication, then the authentication process is simple and easy to implement, but the security is weak because the questions are easily guessable and repetitive

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static challenge questions into dynamic, time-varying challenges. The challenge questions are generated based on recent user transactions and change over time, making them non-repeatable. This dynamic approach enhances security while maintaining system simplicity through automated generation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of challenge questions from fixed, predetermined values to variable values derived from user transaction data. By using parameters such as recent purchases, locations, and timestamps, the system generates unique challenges that are difficult to guess but straightforward to verify.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If static challenge questions are stored in the system, then the authentication process is efficient, but the system becomes vulnerable to hacking and data breaches

Engineering Contradiction:
Improvesystem securityVSAvoidrisk of information exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements a challenge-response mechanism where the correct answer to each challenge is discarded after verification. Instead of storing challenge answers permanently, the system generates new challenges based on recent transactions, ensuring that even if one challenge is compromised, previous and future challenges remain secure.

Inventive Principle:
Principle #34Discarding and recovering

Solution Approach 2:

The patent extracts security-critical information from the stored user data by generating challenges based on recent transactions without storing the challenges themselves. This extraction approach allows the system to use existing user information for security purposes while minimizing the storage of sensitive authentication data.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If users answer static challenge questions repeatedly, then the authentication process is consistent, but users become frustrated when they cannot remember their answers

Engineering Contradiction:
Improveuser convenienceVSAvoidtime for password reset
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent enables users to answer challenges based on their own recent transaction history, which they naturally remember. By using real user behavior data as the basis for challenges, the system eliminates the need for users to memorize arbitrary answers, allowing them to authenticate based on their own knowledge of recent activities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by generating challenges based on recent user transactions that the user is likely to remember. This preliminary preparation of challenges using familiar information reduces the cognitive burden on users and eliminates the need for time-consuming password resets.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If the same challenge questions are used across multiple online systems, then the authentication process is standardized, but a single hack can compromise multiple systems

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidcross-system security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by generating challenge questions specific to each user's transaction history and each system's context. Instead of using universal, standardized challenges, the system creates localized challenges based on user-specific data, ensuring that a compromise at one system does not affect other systems.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250168153A1Non-repeatable challenge-response authentication
Publication Date: 2025.05.22 NCR VOYIX CORP
  • US20250168153A1 patent drawing
  • US20250168153A1 patent drawing
  • US20250168153A1 patent drawing

AI summary

User data is aggregated across a plurality of electronic communication channels and domains. An online system initially authenticates a user for access to the online system over a network. The online system provides a user identifier for the user to an authentication service. The authentication service generates a non-repeatable challenge from the aggregated user data for the user identifier and provides the non-repeatable challenge to the online system. The online system provides the challenge to the user and receives a response from the user. The online system provides the response to the authentication service and the authentication sends a success or failure back to the online system based on the response to the challenge, and based on the success or failure the online system makes a final determination for authenticating the user for accessing to the online system.