Dynamic Knowledge Authentication via Internet History
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional knowledge-based authentication systems are vulnerable to phishing attacks and do not provide adequate security, as information used for challenge questions can be easily obtained by third parties, including public records and online research.
Innovation Solution
A knowledge-based authentication system that utilizes recent user internet history information from online retailers and search engines to generate challenge questions, which are dynamic and not publicly available, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional knowledge-based authentication uses public records or static user information for challenge questions, then the authentication system is easy to implement, but the security is weak because third parties can obtain the same information through phishing or public records
Solution Approach 1:
The patent transforms static challenge questions based on unchanging public records into dynamic challenge questions based on real-time or recently updated user data (e.g., current news articles, recent social media posts, latest search history). This ensures the challenge information evolves over time and cannot be easily obtained through static phishing attacks, directly addressing the security weakness while maintaining implementation feasibility through automated data retrieval
Solution Approach 2:
The system pre-collects and stores user activity data, browsing history, and interaction patterns before authentication events occur. This preliminary data gathering creates a rich repository of unique user-specific information that can be dynamically queried during authentication, enabling secure challenge questions to be generated without complex real-time data collection during the authentication moment itself
2Reliability
If knowledge-based authentication uses information that changes over time (like recent web history), then phishing attacks are curtailed and security is enhanced, but the system requires access to dynamic data sources and more complex data processing
Solution Approach 1:
The patent introduces intermediary components such as APIs and data aggregation services that bridge the authentication system with dynamic data sources like news outlets, social media platforms, and search engines. These intermediaries handle the complexity of data retrieval, formatting, and validation, allowing the core authentication logic to remain simple while still utilizing evolving user data for secure challenge question generation
Solution Approach 2:
The system leverages user-generated content and self-tracked browsing behavior as the source of challenge information. Users effectively provide their own authentication data through their natural online activities, eliminating the need for manual setup or external configuration. The system automatically monitors and utilizes this self-service data stream, reducing implementation complexity while maintaining high security through dynamic, user-specific challenges
Data Source
AI summary
A technique of knowledge-based authentication receives information from third parties as to a user's recent web history including purchase history at an on-line retailer or search engine queries to produce a challenge question to authenticate the user based on that recent web history.


