Enterprise Knowledge-Based Authentication Using Corporate Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional knowledge-based authentication systems rely on publicly available facts, making them insecure as this information can be accessed by imposters, and they lack control over the security of authentication questions, as the sources of these facts are not under the organization's control.

Innovation Solution

An enterprise knowledge-based authentication system generates challenge questions and responses based on corporate data sources, such as emails, meetings, and spreadsheets, stored on organizational information management servers, ensuring the security and control over the information used for authentication, and includes incorrect responses that are difficult for fraudsters to guess but easy for genuine users to distinguish.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If publicly available facts are used for generating authentication questions, then the system is easier to implement and operate, but the security of the authentication system deteriorates because imposters can access this information

Engineering Contradiction:
Improveease of implementationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts authentication questions from internal corporate data sources (emails, meetings, spreadsheets) rather than using publicly available facts. This separation removes the vulnerable public information from the authentication process while maintaining the knowledge-based authentication approach, thereby improving security without significantly complicating implementation

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces corporate data sources as an intermediary between the authentication system and the user knowledge. Instead of directly using public facts, the system uses corporate-specific data (emails, meetings, spreadsheets) that serve as a secure intermediary layer, making it harder for imposters to obtain authentication information while keeping the system manageable

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If corporate data sources are used for generating authentication questions, then the security and control over authentication information is improved, but the device complexity increases due to managing multiple data sources

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the authentication system multi-functional by integrating it with multiple existing corporate data sources (emails, meetings, spreadsheets). These data sources serve multiple purposes: they store business information and simultaneously provide secure authentication questions. This universality reduces overall system complexity by reusing existing infrastructure rather than building separate authentication data storage

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the authentication function with existing corporate data sources. Instead of creating a separate system for storing authentication questions, the system combines authentication question generation with existing corporate data (emails, meetings, spreadsheets), thereby reducing device complexity while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If challenge questions are made more specific to corporate data, then the difficulty for fraudsters to guess responses increases, but the ease of operation decreases as users must remember more specific information

Engineering Contradiction:
Improveauthentication securityVSAvoiduser memory burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments corporate data into distinct categories (emails, meetings, spreadsheets) and generates authentication questions from each segment. This segmentation allows the system to provide diverse question types that tap into different user experiences and memory areas, distributing the memory burden across multiple familiar contexts rather than requiring memorization of a single large set of facts

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes the authentication system dynamic by selecting questions from evolving corporate data sources. As new emails, meetings, and spreadsheets are created, new authentication questions become available. This dynamic nature allows the system to adapt to user roles and responsibilities over time, presenting questions that are relevant to the user's current work context, thereby reducing memory burden while maintaining security

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10255558B1Managing knowledge-based authentication systems
Publication Date: 2019.04.09 EMC IP HLDG CO LLC
  • US10255558B1 patent drawing
  • US10255558B1 patent drawing
  • US10255558B1 patent drawing

AI summary

A method is used in managing knowledge-based authentication systems. A set of factors is evaluated for gathering organization based information from a set of information sources for authenticating a user in a knowledge-based authentication system. The organization based information is collected based on the evaluation.