Dynamic User Identity Verification System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user identity verification methods are vulnerable to unauthorized access as pre-configured security answers can be decrypted, leading to potential economic harm for genuine account holders.

Innovation Solution

A system and method for user identity verification where a server pre-configures verification information, including security challenges and answers, based on collected user information, and transmits these challenges to a client for verification, with the server comparing user-provided answers to determine identity authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-configured security answers are used for user verification, then verification process is simple and fast, but security is compromised as answers can be decrypted by unauthorized parties

Engineering Contradiction:
Improveuser account securityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic verification information that changes over time and context. Instead of static pre-configured answers, the system generates verification challenges and answers that are dynamically created based on user behavior patterns, device characteristics, and transaction context. This dynamic nature prevents unauthorized parties from using decrypted static answers, while the automated generation process manages the increased complexity without requiring manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple parameters of the verification process including the content of verification challenges, the format of answers, the timing of verification requests, and the criteria for acceptance. By varying these parameters dynamically based on risk assessment and user behavior analysis, the system enhances security against decryption attacks while maintaining operational efficiency through automated parameter management.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If manual security answers are configured by users, then setup is straightforward, but security is weakened as configured answers can be easily decrypted

Engineering Contradiction:
Improveverification setup easeVSAvoidverification security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system automatically generates and manages verification information without requiring manual user configuration. The server autonomously creates verification challenges, generates corresponding answers, and manages the verification process based on collected user information and behavior patterns. This self-service approach eliminates the security vulnerability of manually configured answers while maintaining ease of use through automated processes that require no user setup intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring verification information on the server side before it is needed for actual verification. The server collects user information in advance, generates verification challenges and answers proactively, and stores them securely. This preliminary configuration eliminates the need for users to manually set up security answers while ensuring secure, automated verification readiness.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If static verification answers are stored, then verification process is efficient, but vulnerability to decryption attacks increases

Engineering Contradiction:
Improveverification processing speedVSAvoiddecryption attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces static stored verification answers with dynamically generated verification information. The system creates verification challenges and answers that are unique to each verification event based on real-time user behavior analysis, device characteristics, and transaction context. This dynamic generation maintains verification efficiency through automated processes while eliminating the vulnerability to decryption attacks that plagues static stored answers.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system substitutes the mechanical approach of storing and retrieving static verification answers with an information processing approach that generates verification data dynamically through algorithmic processes. Instead of mechanically storing fixed answers in databases, the system uses computational processes to generate verification information based on user behavior patterns and contextual data, thereby maintaining processing speed while eliminating decryption vulnerabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10528710B2System and method for user identity verification, and client and server by use thereof
Publication Date: 2020.01.07 ADVANCED NEW TECHNOLOGIES CO LTD
  • US10528710B2 patent drawing
  • US10528710B2 patent drawing
  • US10528710B2 patent drawing

AI summary

A method of user identity verification by a server, where the server pre-configures, by use of collected user information, verification information corresponding to accounts of users in a user verification information data store, the verification information including a plurality of verification security challenges and a plurality of respective first verification answers. The method includes detecting a condition to whether initiate a user identity verification is satisfied, where an account ID of a user is obtained from the condition. The method also includes inquiring the pre-configured user verification information about verification information matching the account ID and transmitting security challenges of the inquired verification information to the client. The method further includes receiving from the client second verification answers corresponding to the security challenges and comparing the second verification answers with the first verification answers to determine whether the user's identity is verified.