Dynamic Knowledge Authentication via Internet History

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional knowledge-based authentication systems are vulnerable to phishing attacks and do not provide adequate security, as information used for challenge questions can be easily obtained by third parties, including public records and online research.

Innovation Solution

A knowledge-based authentication system that utilizes recent user internet history information from online retailers and search engines to generate challenge questions, which are dynamic and not publicly available, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional knowledge-based authentication uses public records or static user information for challenge questions, then the authentication system is easy to implement, but the security is weak because third parties can obtain the same information through phishing or public records

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static challenge questions based on unchanging public records into dynamic challenge questions based on real-time or recently updated user data (e.g., current news articles, recent social media posts, latest search history). This ensures the challenge information evolves over time and cannot be easily obtained through static phishing attacks, directly addressing the security weakness while maintaining implementation feasibility through automated data retrieval

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system pre-collects and stores user activity data, browsing history, and interaction patterns before authentication events occur. This preliminary data gathering creates a rich repository of unique user-specific information that can be dynamically queried during authentication, enabling secure challenge questions to be generated without complex real-time data collection during the authentication moment itself

Inventive Principle:
Principle #10Preliminary action

2Reliability

If knowledge-based authentication uses information that changes over time (like recent web history), then phishing attacks are curtailed and security is enhanced, but the system requires access to dynamic data sources and more complex data processing

Engineering Contradiction:
Improveauthentication securityVSAvoidease of implementation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces intermediary components such as APIs and data aggregation services that bridge the authentication system with dynamic data sources like news outlets, social media platforms, and search engines. These intermediaries handle the complexity of data retrieval, formatting, and validation, allowing the core authentication logic to remain simple while still utilizing evolving user data for secure challenge question generation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system leverages user-generated content and self-tracked browsing behavior as the source of challenge information. Users effectively provide their own authentication data through their natural online activities, eliminating the need for manual setup or external configuration. The system automatically monitors and utilizes this self-service data stream, reducing implementation complexity while maintaining high security through dynamic, user-specific challenges

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8955066B1Knowledge based authentication using recent user internet activity
Publication Date: 2015.02.10 EMC IP HLDG CO LLC
  • US8955066B1 patent drawing
  • US8955066B1 patent drawing
  • US8955066B1 patent drawing

AI summary

A technique of knowledge-based authentication receives information from third parties as to a user's recent web history including purchase history at an on-line retailer or search engine queries to produce a challenge question to authenticate the user based on that recent web history.