Dynamic Knowledge-Based Authentication via Mobile Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems, particularly those using Knowledge Based Authentication (KBA) questions, are vulnerable to unauthorized access due to easily guessable answers, and possession factors like smartphones can be lost or stolen, disrupting access to secure accounts.

Innovation Solution

Dynamic, personalized knowledge-based authentication questions are generated from ongoing analytics streams from mobile devices, incorporating data on user interactions, locations, purchases, and device usage, which are used to authenticate users and reset possession factor credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional KBA questions are used for authentication, then users can reset possession factor credentials, but the questions are vulnerable to guessing and learning by fraudulent parties

Engineering Contradiction:
Improvecredential reset capabilityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms static KBA questions into dynamic questions that change over time based on user behavior analytics. The system continuously collects analytics data from mobile devices and generates new authentication questions based on recent user activities, making the authentication mechanism adaptive and difficult to compromise through static analysis or guessing.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of authentication questions by deriving them from multiple varying data sources including location history, communication patterns, application usage, and sensor data. These parameters are dynamically adjusted based on the analytics stream, ensuring that authentication challenges evolve with user behavior patterns.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If strong passwords are used to improve security, then authentication becomes harder to crack, but users cannot remember them and may write them down in accessible locations

Engineering Contradiction:
Improvepassword securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces mobile device analytics as an intermediary layer between the user and the authentication system. Instead of relying solely on user memory or written passwords, the system uses analytics data from the user's mobile device as a mediator to generate authentication questions that are both secure and naturally answerable by the user through their device usage patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service authentication by leveraging data that users already generate through their normal mobile device usage. The analytics stream captures location, communications, applications, and sensor data that users naturally produce, allowing the authentication system to draw from this self-generated information without requiring users to consciously remember or manage complex credentials.

Inventive Principle:
Principle #25Self-service

3Reliability

If possession factors are used for multifactor authentication, then security is enhanced, but users lose access to accounts when the possession factor is lost or stolen

Engineering Contradiction:
Improveauthentication securityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by continuously collecting and analyzing user behavior data before authentication is needed. The analytics stream is ongoing and pre-processes user activity data, so when authentication is required, the system already has a rich dataset ready to generate authentication questions, enabling rapid credential reset without requiring the original possession factor.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements beforehand cushioning by maintaining a continuous analytics stream that buffers user behavior data over time. This creates a safety cushion of historical data that can be used for authentication even when the current possession factor is unavailable, protecting users from complete access loss while maintaining security through verified behavioral patterns.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS9888377B1Using personal computing device analytics as a knowledge based authentication source
Publication Date: 2018.02.06 GEN DIGITAL INC
  • US9888377B1 patent drawing
  • US9888377B1 patent drawing
  • US9888377B1 patent drawing

AI summary

Ongoing analytics streams are received over time from mobile computing devices. An analytics stream comprises data corresponding to monitored activity that occurred on the originating mobile computing device. Dynamic, personalized knowledge based authentication questions are generated from analytics stream data. In response to an authentication request from a user, the user is prompted to answer a given number of current dynamic, personalized knowledge based authentication questions.