Dynamic Device-Specific Question Authentication for Script Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures are inadequate in preventing unauthorized access and modification by automated scripts and spiders, as they can bypass traditional security methods such as confirmation dialogs and CAPTCHAs, and user-specific passwords are not viable due to multiple authorized users.

Innovation Solution

Implementing a question-and-answer system via a graphical user interface that presents system-specific questions answerable by human users but not by automated scripts, allowing access only when the correct answer is provided, and denying access if the answer is incorrect.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (passwords, CAPTCHAs, confirmation dialogs) are used, then basic access control is provided, but automated scripts and spiders can still bypass these measures and cause unauthorized access or system disruptions

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidunauthorized access by automated scripts
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the security parameter from static (passwords, CAPTCHAs) to dynamic system-specific questions about device characteristics. The security challenge adapts to the specific device being accessed, requiring knowledge of device-specific parameters such as hardware identifiers, configuration details, or operational characteristics that automated scripts cannot easily obtain or guess.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary verification layer between the user and the protected resource. Instead of directly checking passwords or CAPTCHAs, the system mediates access by presenting device-specific knowledge questions that act as an intermediate verification step, confirming the user's legitimate knowledge about the device before allowing access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user-specific passwords are implemented, then individual user authentication is achieved, but this becomes unviable when multiple authorized users need access to the same system

Engineering Contradiction:
Improveauthentication securityVSAvoidmulti-user access capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal security mechanism that works for all authorized users without requiring user-specific credentials. The device-specific knowledge questions serve all users equally, verifying that whoever accesses the device has legitimate knowledge about it, regardless of which authorized user it is. This multi-functional approach replaces multiple user-specific authentication mechanisms with a single universal verification method.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automated security verification is used, then access control speed is improved, but security against sophisticated automated attacks deteriorates

Engineering Contradiction:
Improveaccess verification speedVSAvoidprotection against automated attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces dynamic elements into the security verification process. Instead of static passwords or predictable CAPTCHAs, the system uses dynamic device-specific questions that change based on the target device's characteristics. This dynamic approach maintains fast automated verification while preventing sophisticated automated attacks, because the questions adapt to each specific device context rather than following predictable patterns.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10108789B2Increasing security of a device and/or system via questioning about a characteristic of the device and/or system
Publication Date: 2018.10.23 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10108789B2 patent drawing
  • US10108789B2 patent drawing
  • US10108789B2 patent drawing

AI summary

A method for preventing unauthorized access to and/or modification of a page of a device and/or system according to one embodiment includes presenting a question via a graphical user interface; receiving a response to the question; allowing access to and/or modification of the page when the response to the question includes the answer; and not allowing access to and/or modification of the page when the response to the question does not include the answer. An answer to the question includes a characteristic of the device and/or system.