Experience-Based MFA Using Dynamic Security Questions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication (MFA) methods for accessing sensitive data repositories are vulnerable to unauthorized access due to compromised credentials and static, generic security questions, which can be easily predicted by malicious parties.
Innovation Solution
Implement dynamic security questions based on personalized and relevant experiences of authorized users, derived from their medical data, continuously updated as new information is collected, to enhance MFA.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static, generic security questions are used in MFA, then the authentication process is simple to implement, but the security is weak because they can be easily predicted by malicious parties
Solution Approach 1:
The patent transforms static security questions into dynamic ones by continuously updating them based on new user experiences and interactions with the system. The security questions evolve over time, drawing from recent user activities, making them unpredictable for attackers while remaining relevant to the user's actual experience with the system.
Solution Approach 2:
The system automatically generates security questions based on user-generated data and interactions without requiring manual configuration. The system monitors user behavior, extracts meaningful experiences, and autonomously creates updated security questions, reducing administrative overhead while improving security.
2Reliability
If dynamic security questions based on user experiences are implemented, then security is enhanced and questions are difficult to predict, but the system complexity increases
Solution Approach 1:
The system automatically generates security questions based on user-generated data and interactions without requiring manual configuration. The system monitors user behavior, extracts meaningful experiences, and autonomously creates updated security questions, reducing administrative overhead while improving security.
Solution Approach 2:
The system continuously monitors user interactions and experiences, using this feedback to dynamically update security questions. The feedback loop ensures that security questions remain relevant to current user experiences while adapting to changing threat landscapes.
3Reliability
If security questions are based on personalized user experiences, then unauthorized access is reduced, but the ease of operation may be affected by the need to remember personal experiences
Solution Approach 1:
The system automatically generates security questions based on user-generated data and interactions without requiring manual configuration. The system monitors user behavior, extracts meaningful experiences, and autonomously creates updated security questions, reducing administrative overhead while improving security.
Solution Approach 2:
The system changes the parameters of security questions over time by incorporating new user experiences and interactions. This dynamic parameter change ensures that questions remain both secure (unpredictable to attackers) and convenient (based on user's actual recent experiences that they naturally remember).
Data Source
AI summary
Methods and systems for managing requests for functionalities of a data repository are disclosed. The data repository may store sensitive data (e.g., personal data), and may offer functionality (e.g., data access) in order to facilitate computer-implemented services. To prevent unauthorized access to and/or use of the sensitive data, an access control system may be implemented. For example, in order to gain access to data stored in the data repository, the access control system may prompt a requesting user to provide responses to security questions during authentication. The security questions may be based on details of personal experiences of the authorized user (e.g., identified from the personal data of the authorized user) and may be updated automatically when new data is introduced to the data repository. Therefore, the responses to the security questions required for authentication may be memorable to the authorized user and/or difficult to predict for unauthorized users.


