Dynamic User Identity Verification System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user identity verification methods are vulnerable to unauthorized access as pre-configured security answers can be decrypted, leading to potential economic harm for genuine account holders.
Innovation Solution
A system and method for user identity verification where a server pre-configures verification information, including security challenges and answers, based on collected user information, and transmits these challenges to a client for verification, with the server comparing user-provided answers to determine identity authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-configured security answers are used for user verification, then verification process is simple and fast, but security is compromised as answers can be decrypted by unauthorized parties
Solution Approach 1:
The patent implements dynamic verification information that changes over time and context. Instead of static pre-configured answers, the system generates verification challenges and answers that are dynamically created based on user behavior patterns, device characteristics, and transaction context. This dynamic nature prevents unauthorized parties from using decrypted static answers, while the automated generation process manages the increased complexity without requiring manual intervention.
Solution Approach 2:
The system changes multiple parameters of the verification process including the content of verification challenges, the format of answers, the timing of verification requests, and the criteria for acceptance. By varying these parameters dynamically based on risk assessment and user behavior analysis, the system enhances security against decryption attacks while maintaining operational efficiency through automated parameter management.
2Ease of manufacture
If manual security answers are configured by users, then setup is straightforward, but security is weakened as configured answers can be easily decrypted
Solution Approach 1:
The system automatically generates and manages verification information without requiring manual user configuration. The server autonomously creates verification challenges, generates corresponding answers, and manages the verification process based on collected user information and behavior patterns. This self-service approach eliminates the security vulnerability of manually configured answers while maintaining ease of use through automated processes that require no user setup intervention.
Solution Approach 2:
The system performs preliminary actions by pre-configuring verification information on the server side before it is needed for actual verification. The server collects user information in advance, generates verification challenges and answers proactively, and stores them securely. This preliminary configuration eliminates the need for users to manually set up security answers while ensuring secure, automated verification readiness.
3Productivity
If static verification answers are stored, then verification process is efficient, but vulnerability to decryption attacks increases
Solution Approach 1:
The patent replaces static stored verification answers with dynamically generated verification information. The system creates verification challenges and answers that are unique to each verification event based on real-time user behavior analysis, device characteristics, and transaction context. This dynamic generation maintains verification efficiency through automated processes while eliminating the vulnerability to decryption attacks that plagues static stored answers.
Solution Approach 2:
The system substitutes the mechanical approach of storing and retrieving static verification answers with an information processing approach that generates verification data dynamically through algorithmic processes. Instead of mechanically storing fixed answers in databases, the system uses computational processes to generate verification information based on user behavior patterns and contextual data, thereby maintaining processing speed while eliminating decryption vulnerabilities.
Data Source
AI summary
A method of user identity verification by a server, where the server pre-configures, by use of collected user information, verification information corresponding to accounts of users in a user verification information data store, the verification information including a plurality of verification security challenges and a plurality of respective first verification answers. The method includes detecting a condition to whether initiate a user identity verification is satisfied, where an account ID of a user is obtained from the condition. The method also includes inquiring the pre-configured user verification information about verification information matching the account ID and transmitting security challenges of the inquired verification information to the client. The method further includes receiving from the client second verification answers corresponding to the security challenges and comparing the second verification answers with the first verification answers to determine whether the user's identity is verified.


