Enterprise KBA Confounder Generation from Email Headers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional knowledge-based authentication (KBA) systems relying on publicly available databases are costly, inefficient, and insecure, particularly for organizations with diverse user populations, as they generate ineffective confounders based on ethnicity and require vast resources to manage large datasets, while also exposing sensitive information to potential imposters.
Innovation Solution
An enterprise KBA (eKBA) system generates confounders from personal information management (PIM) data within the organization, specifically from email data, forming multiple-choice questions that are secure and cost-effective by focusing on peer circles rather than ethnicity, using an eKBA server that extracts facts and confounders from email headers to create authenticating queries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If third-party software packages are used to generate confounders from publicly available databases, then authentication questions can be generated, but the cost becomes very high and the system becomes complex
Solution Approach 1:
The system generates its own confounders using internally available employee data such as directory information, HR records, and communication metadata. This eliminates the need for external third-party software packages and publicly available databases, making the system self-sufficient and reducing both cost and complexity while maintaining authentication effectiveness
Solution Approach 2:
The patent extracts only the necessary confounder data from internal sources that are already collected for legitimate business purposes. By taking out only the specific information needed for authentication (without requiring entire external databases), the system achieves effective confounder generation with minimal data processing and storage requirements
2Adaptability or versatility
If third-party software is used to generate confounders based on ethnicity from publicly available databases, then incorrect answers can be generated, but the confounders become ineffective for diverse organizational populations
Solution Approach 1:
The system generates confounders that are locally adapted to each organization's specific population characteristics by using that organization's own employee data. Instead of applying generic ethnicity-based confounders from external databases, the system creates confounders that reflect the actual demographic and professional composition of the specific organization, ensuring both applicability and authentication accuracy
Solution Approach 2:
The patent changes the parameters used for confounder generation from external demographic characteristics to internal organizational attributes such as department, location, tenure, and communication patterns. This parameter transformation ensures that confounders are both adaptable to diverse organizational structures and reliable for authenticating members of that specific organization
3Quantity of substance
If publicly available databases are used to store facts for KBA questions, then vast resources are required to manage the large datasets
Solution Approach 1:
The system segments the data requirements for confounder generation by using only specific fields from internal databases that are already maintained for business operations. Instead of managing entire external databases containing information on millions of people, the system segments and uses only the relevant portions of internal data (directory information, HR records, communication metadata) that pertain to the organization's own employees
Solution Approach 2:
The patent makes the collected employee data serve multiple functions: it is used for legitimate business operations (directory services, HR management, communication routing) and simultaneously for authentication confounder generation. This multi-functionality eliminates the need for separate dedicated databases for authentication purposes, reducing overall data management complexity while maintaining sufficient data volume for effective authentication
4Reliability
If facts are obtained from publicly available databases, then KBA questions can be generated, but the incorrect answers become insecure because imposters may have examined the facts
Solution Approach 1:
The system converts the potential harm of publicly available information being accessible to imposters into a benefit by using internal data that is inherently more secure. Information that would be exposed in public databases is instead kept within the organization's controlled environment, and the same data serves dual purposes for both operational efficiency and enhanced security
Solution Approach 2:
The patent prevents the security vulnerability before it can occur by never using publicly available databases in the first place. Instead, the system proactively uses only internally sourced data that is not publicly accessible, thereby preempting the possibility of imposters examining the facts and compromising authentication security
Data Source
AI summary
An improved technique generates confounders for KBA questions from personal information management (PIM) data created from within an organization. An enterprise KBA (eKBA) server collects PIM data such as email data for a particular member of the organization. For email data, the eKBA server extracts facts from the headers of emails and generates queries having a corresponding correct answer from a first subset of the facts. Moreover, the eKBA server extracts a set of confounders from a second subset of the facts. The eKBA server then forms a multiple-choice KBA question from the query, the corresponding correct answer, and selected confounders.


