Dynamic User Prompts for Secure Transaction Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Authentication systems relying on static questions and answers are vulnerable to unauthorized access due to their static nature.

Innovation Solution

Dynamically generate authentication questions based on recent user activity data, such as location and purchase history, and compare user responses to these questions in real-time to authenticate users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static authentication questions are used, then the authentication process is simple and fast, but the system becomes vulnerable to unauthorized access

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication questions that change based on user behavior patterns, device information, and contextual factors. Instead of static questions, the system generates unique questions for each authentication attempt, making it difficult for unauthorized actors to predict or reuse answers. This dynamic approach directly addresses the security vulnerability while maintaining operational simplicity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple parameters including question content, question type, and authentication criteria based on user profile data, device characteristics, and transaction context. By dynamically adjusting these parameters, the system enhances security without requiring complex manual configuration, resolving the contradiction between security improvement and system complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If user data is stored long-term for authentication, then authentication accuracy is improved, but data storage risks increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoiddata storage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of user data to extract authentication features and patterns before the actual authentication event. User behavior patterns, device fingerprints, and contextual information are pre-processed and stored in a simplified format, enabling accurate authentication without retaining raw sensitive data long-term. This preliminary action reduces storage risks while maintaining authentication accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the necessary authentication-related information from user data, separating it from sensitive personal information. By taking out only the features needed for authentication (such as behavior patterns and device characteristics) and discarding or anonymizing the rest, the system achieves accurate authentication with minimal data retention, thereby reducing storage risks.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If dynamically generated questions are used, then security against unauthorized access is improved, but the authentication process becomes more complex

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs self-service by automatically generating authentication questions based on pre-analyzed user patterns and contextual information without requiring manual intervention. The question generation is automated through algorithms that process user behavior data and create relevant questions instantly, maintaining high speed while enhancing security through dynamic content generation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12423698B2Secure user authentication based on dynamically generated user prompts
Publication Date: 2025.09.23 BANK OF AMERICA CORP
  • US12423698B2 patent drawing
  • US12423698B2 patent drawing
  • US12423698B2 patent drawing

AI summary

Arrangements for providing dynamic user authentication are provided. In some aspects, a user may initiate a transaction at a merchant point-of-sale (POS) system, via a merchant website, or the like. In response, user data from one or more pre-registered user devices may be retrieved. The data may be analyzed to identify one or more data points for use as a correct answer to an authentication question. An authentication question may be dynamically generated and transmitted to the merchant system for display and the user may provide authentication response data. The authentication response data may be received and compared to the data points providing the basis for the authentication question. If the data matches, the user may be authenticated and the transaction may be processed. If not, additional user authentication data may be requested. The system may then delete the received user data.