Dynamic Question Subset Authentication for Phishing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Phishing attacks compromise online financial transactions by tricking users into providing sensitive information, as existing security measures often lack robust authentication methods, especially in simplified payment processes that avoid lengthy registration and login requirements.

Innovation Solution

A system that authenticates parties during transactions by asking a subset of randomly or pseudo-randomly selected questions, providing transitory information that uniquely identifies the provider, and issuing a customer identifier for future transactions, thereby reducing the risk of phishing by varying the questions and limiting access to content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If simplified payment processes avoid lengthy registration and login requirements, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of payment processVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication actions by asking and answering questions before the payment process begins. This preliminary verification ensures security without requiring lengthy registration or login procedures, as the authentication happens implicitly during the payment flow itself

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary authentication mechanism using questions and answers as a mediator between the customer and the payment processing. This intermediary layer verifies identity without requiring direct login credentials, maintaining both simplicity and security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If phishing attacks replicate legitimate websites, then ease of operation for users is maintained, but detection difficulty increases

Engineering Contradiction:
Improveuser interaction simplicityVSAvoidphishing detection difficulty
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system makes the authentication process dynamic by selecting questions randomly from a pool each time. This dynamic approach prevents phishing sites from statically replicating the authentication process, as the question sequence changes with each interaction, making detection more difficult for attackers

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system provides feedback through the question-answer interaction mechanism that verifies user identity in real-time. This feedback loop ensures that only authenticated users can proceed, making it difficult for phishing sites to successfully replicate the legitimate website's authentication flow

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7650310B2Technique for reducing phishing
Publication Date: 2010.01.19 INTUIT INC
  • US7650310B2 patent drawing
  • US7650310B2 patent drawing
  • US7650310B2 patent drawing

AI summary

Embodiments of a system that performs authentication during a financial transaction are described. During operation, this system asks a prospective customer a subset of questions from a set of questions, where the subset of questions has a probability of being different from those asked while previously or subsequently asking questions of the prospective customer or another prospective customer. Next, the system receives answers to the subset of questions from the prospective customer, thereby confirming that the prospective customer is a customer associated with a financial transaction. Then, the system provides transitory information associated with the financial transaction that, for the customer, uniquely identifies a provider of the financial transaction, thereby completing the authentication.