Enterprise KBA Confounder Generation from Email Headers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional knowledge-based authentication (KBA) systems relying on publicly available databases are costly, inefficient, and insecure, particularly for organizations with diverse user populations, as they generate ineffective confounders based on ethnicity and require vast resources to manage large datasets, while also exposing sensitive information to potential imposters.

Innovation Solution

An enterprise KBA (eKBA) system generates confounders from personal information management (PIM) data within the organization, specifically from email data, forming multiple-choice questions that are secure and cost-effective by focusing on peer circles rather than ethnicity, using an eKBA server that extracts facts and confounders from email headers to create authenticating queries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If third-party software packages are used to generate confounders from publicly available databases, then authentication questions can be generated, but the cost becomes very high and the system becomes complex

Engineering Contradiction:
Improveauthentication effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system generates its own confounders using internally available employee data such as directory information, HR records, and communication metadata. This eliminates the need for external third-party software packages and publicly available databases, making the system self-sufficient and reducing both cost and complexity while maintaining authentication effectiveness

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts only the necessary confounder data from internal sources that are already collected for legitimate business purposes. By taking out only the specific information needed for authentication (without requiring entire external databases), the system achieves effective confounder generation with minimal data processing and storage requirements

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If third-party software is used to generate confounders based on ethnicity from publicly available databases, then incorrect answers can be generated, but the confounders become ineffective for diverse organizational populations

Engineering Contradiction:
Improveconfounder applicabilityVSAvoidauthentication accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system generates confounders that are locally adapted to each organization's specific population characteristics by using that organization's own employee data. Instead of applying generic ethnicity-based confounders from external databases, the system creates confounders that reflect the actual demographic and professional composition of the specific organization, ensuring both applicability and authentication accuracy

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameters used for confounder generation from external demographic characteristics to internal organizational attributes such as department, location, tenure, and communication patterns. This parameter transformation ensures that confounders are both adaptable to diverse organizational structures and reliable for authenticating members of that specific organization

Inventive Principle:
Principle #35Parameter changes

3Quantity of substance

If publicly available databases are used to store facts for KBA questions, then vast resources are required to manage the large datasets

Engineering Contradiction:
Improvedata volumeVSAvoiddata management complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The system segments the data requirements for confounder generation by using only specific fields from internal databases that are already maintained for business operations. Instead of managing entire external databases containing information on millions of people, the system segments and uses only the relevant portions of internal data (directory information, HR records, communication metadata) that pertain to the organization's own employees

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes the collected employee data serve multiple functions: it is used for legitimate business operations (directory services, HR management, communication routing) and simultaneously for authentication confounder generation. This multi-functionality eliminates the need for separate dedicated databases for authentication purposes, reducing overall data management complexity while maintaining sufficient data volume for effective authentication

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If facts are obtained from publicly available databases, then KBA questions can be generated, but the incorrect answers become insecure because imposters may have examined the facts

Engineering Contradiction:
Improveauthentication securityVSAvoidinformation exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system converts the potential harm of publicly available information being accessible to imposters into a benefit by using internal data that is inherently more secure. Information that would be exposed in public databases is instead kept within the organization's controlled environment, and the same data serves dual purposes for both operational efficiency and enhanced security

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent prevents the security vulnerability before it can occur by never using publicly available databases in the first place. Instead, the system proactively uses only internally sourced data that is not publicly accessible, thereby preempting the possibility of imposters examining the facts and compromising authentication security

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS9177127B1Confounder generation in knowledge-based authentication for an enterprise
Publication Date: 2015.11.03 EMC IP HLDG CO LLC
  • US9177127B1 patent drawing
  • US9177127B1 patent drawing
  • US9177127B1 patent drawing

AI summary

An improved technique generates confounders for KBA questions from personal information management (PIM) data created from within an organization. An enterprise KBA (eKBA) server collects PIM data such as email data for a particular member of the organization. For email data, the eKBA server extracts facts from the headers of emails and generates queries having a corresponding correct answer from a first subset of the facts. Moreover, the eKBA server extracts a set of confounders from a second subset of the facts. The eKBA server then forms a multiple-choice KBA question from the query, the corresponding correct answer, and selected confounders.