Event-Based Security Challenges for Mobile Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of mobile computing devices face challenges in accessing password-protected resources due to the need to remember multiple login credentials and the difficulty in managing password lists, especially with the increasing number of resources and frequency of access.

Innovation Solution

A security application on mobile devices generates and uses event-based security challenges, collecting and storing event data such as location, transaction, and call information to create personalized challenge questions and responses, which are used for authentication, allowing users to access protected resources securely without relying on traditional password management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users rely on traditional password protection for accessing multiple web-based resources, then security is maintained, but user convenience deteriorates due to the need to remember multiple login credentials

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication mechanism from traditional password-based systems and replaces it with event-based challenge questions. The security application collects event data (location, transactions, calls) and generates challenges based on this data, removing the burden of password memorization while maintaining security through knowledge of recent personal events.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter of authentication from static passwords to dynamic event-based challenges. The challenge questions are generated based on recent events captured by the mobile device, such as location data, transaction history, and call logs, making authentication adaptive and context-aware rather than relying on fixed credentials.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If users maintain password lists on mobile devices, then access to multiple resources is enabled, but device complexity increases and security risks arise from storing sensitive information

Engineering Contradiction:
Improveaccess capabilityVSAvoidpassword management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security application serves itself by automatically collecting event data from the mobile device's existing sensors and applications. It generates challenge questions based on this self-collected data without requiring users to manually input or manage authentication credentials, eliminating the need for password lists while maintaining versatile access capability.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If the number of password-protected resources increases, then more services are accessible, but the difficulty of managing multiple passwords increases exponentially

Engineering Contradiction:
Improveservice accessibilityVSAvoidpassword management difficulty
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal authentication system where a single security application can generate event-based challenges for accessing multiple different web-based resources. The system collects comprehensive event data that can serve as the basis for challenges across various services, eliminating the need for separate password management for each resource while maintaining broad service accessibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10747857B2Event-based security challenges
Publication Date: 2020.08.18 AT&T INTELLECTUAL PROPERTY I L P
  • US10747857B2 patent drawing
  • US10747857B2 patent drawing
  • US10747857B2 patent drawing

AI summary

Concepts and technologies are disclosed herein for event-based security challenges. A computer can execute a security application. The computer can receive a request for authentication information associated with a user device. The computer can access event data corresponding to the user device. The computer can generate, based upon the event data, a challenge question and a response to the challenge question. The computer can provide data indicating the challenge question and the response to a requestor associated with the request.