Experience-Based MFA Using Dynamic Security Questions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication (MFA) methods for accessing sensitive data repositories are vulnerable to unauthorized access due to compromised credentials and static, generic security questions, which can be easily predicted by malicious parties.

Innovation Solution

Implement dynamic security questions based on personalized and relevant experiences of authorized users, derived from their medical data, continuously updated as new information is collected, to enhance MFA.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static, generic security questions are used in MFA, then the authentication process is simple to implement, but the security is weak because they can be easily predicted by malicious parties

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static security questions into dynamic ones by continuously updating them based on new user experiences and interactions with the system. The security questions evolve over time, drawing from recent user activities, making them unpredictable for attackers while remaining relevant to the user's actual experience with the system.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system automatically generates security questions based on user-generated data and interactions without requiring manual configuration. The system monitors user behavior, extracts meaningful experiences, and autonomously creates updated security questions, reducing administrative overhead while improving security.

Inventive Principle:
Principle #25Self-service

2Reliability

If dynamic security questions based on user experiences are implemented, then security is enhanced and questions are difficult to predict, but the system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically generates security questions based on user-generated data and interactions without requiring manual configuration. The system monitors user behavior, extracts meaningful experiences, and autonomously creates updated security questions, reducing administrative overhead while improving security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors user interactions and experiences, using this feedback to dynamically update security questions. The feedback loop ensures that security questions remain relevant to current user experiences while adapting to changing threat landscapes.

Inventive Principle:
Principle #23Feedback

3Reliability

If security questions are based on personalized user experiences, then unauthorized access is reduced, but the ease of operation may be affected by the need to remember personal experiences

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically generates security questions based on user-generated data and interactions without requiring manual configuration. The system monitors user behavior, extracts meaningful experiences, and autonomously creates updated security questions, reducing administrative overhead while improving security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameters of security questions over time by incorporating new user experiences and interactions. This dynamic parameter change ensures that questions remain both secure (unpredictable to attackers) and convenient (based on user's actual recent experiences that they naturally remember).

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12524560B2Multifactor authentication based on user experiences
Publication Date: 2026.01.13 DELL PROD LP
  • US12524560B2 patent drawing
  • US12524560B2 patent drawing
  • US12524560B2 patent drawing

AI summary

Methods and systems for managing requests for functionalities of a data repository are disclosed. The data repository may store sensitive data (e.g., personal data), and may offer functionality (e.g., data access) in order to facilitate computer-implemented services. To prevent unauthorized access to and/or use of the sensitive data, an access control system may be implemented. For example, in order to gain access to data stored in the data repository, the access control system may prompt a requesting user to provide responses to security questions during authentication. The security questions may be based on details of personal experiences of the authorized user (e.g., identified from the personal data of the authorized user) and may be updated automatically when new data is introduced to the data repository. Therefore, the responses to the security questions required for authentication may be memorable to the authorized user and/or difficult to predict for unauthorized users.