Dynamic Challenge-Response Authentication Using Transaction Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online authentication systems rely on static and easily guessable challenge questions, making them vulnerable to hacking and repetitive for users.
Innovation Solution
A non-repeatable challenge-response authentication system that generates user-specific, dynamic challenges based on recent transaction data, ensuring that each authentication session uses unique questions and answers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static challenge questions are used for authentication, then the authentication process is simple and easy to implement, but the security is weak because the questions are easily guessable and repetitive
Solution Approach 1:
The patent transforms static challenge questions into dynamic, time-varying challenges. The challenge questions are generated based on recent user transactions and change over time, making them non-repeatable. This dynamic approach enhances security while maintaining system simplicity through automated generation.
Solution Approach 2:
The patent changes the parameters of challenge questions from fixed, predetermined values to variable values derived from user transaction data. By using parameters such as recent purchases, locations, and timestamps, the system generates unique challenges that are difficult to guess but straightforward to verify.
2Reliability
If static challenge questions are stored in the system, then the authentication process is efficient, but the system becomes vulnerable to hacking and data breaches
Solution Approach 1:
The patent implements a challenge-response mechanism where the correct answer to each challenge is discarded after verification. Instead of storing challenge answers permanently, the system generates new challenges based on recent transactions, ensuring that even if one challenge is compromised, previous and future challenges remain secure.
Solution Approach 2:
The patent extracts security-critical information from the stored user data by generating challenges based on recent transactions without storing the challenges themselves. This extraction approach allows the system to use existing user information for security purposes while minimizing the storage of sensitive authentication data.
3Ease of operation
If users answer static challenge questions repeatedly, then the authentication process is consistent, but users become frustrated when they cannot remember their answers
Solution Approach 1:
The patent enables users to answer challenges based on their own recent transaction history, which they naturally remember. By using real user behavior data as the basis for challenges, the system eliminates the need for users to memorize arbitrary answers, allowing them to authenticate based on their own knowledge of recent activities.
Solution Approach 2:
The system performs preliminary actions by generating challenges based on recent user transactions that the user is likely to remember. This preliminary preparation of challenges using familiar information reduces the cognitive burden on users and eliminates the need for time-consuming password resets.
4Adaptability or versatility
If the same challenge questions are used across multiple online systems, then the authentication process is standardized, but a single hack can compromise multiple systems
Solution Approach 1:
The patent applies local quality by generating challenge questions specific to each user's transaction history and each system's context. Instead of using universal, standardized challenges, the system creates localized challenges based on user-specific data, ensuring that a compromise at one system does not affect other systems.
Data Source
AI summary
User data is aggregated across a plurality of electronic communication channels and domains. An online system initially authenticates a user for access to the online system over a network. The online system provides a user identifier for the user to an authentication service. The authentication service generates a non-repeatable challenge from the aggregated user data for the user identifier and provides the non-repeatable challenge to the online system. The online system provides the challenge to the user and receives a response from the user. The online system provides the response to the authentication service and the authentication sends a success or failure back to the online system based on the response to the challenge, and based on the success or failure the online system makes a final determination for authenticating the user for accessing to the online system.


