Historically-Aware Questionnaires for Knowledge-Based Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Knowledge-based authentication (KBA) systems are vulnerable to brute-force and dictionary attacks due to the use of secrets with low entropy, making them susceptible to fraud, especially with the increasing availability of personal information through social engineering and data mining.

Innovation Solution

The implementation of silent-alarm knowledge-based authentication (SA-KBA) that uses historically-aware questionnaires to assess a user's credibility by embedding a silent alarm in their responses, allowing the server to differentiate between legitimate and fraudulent authentication attempts through a confidence score, without requiring modifications to existing applications or communication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If KBA uses secrets with low entropy for easy recall, then user convenience is improved, but security is worsened making the system vulnerable to brute-force and dictionary attacks

Engineering Contradiction:
Improveuser recall easeVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system pre-generates multiple possible answers for each KBA question and stores them with metadata indicating their temporal validity. During authentication, the system selects an answer from the pre-generated set that is currently valid, rather than relying on a single static secret. This preliminary preparation allows the system to maintain security while preserving user convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The KBA secrets are transformed from static to dynamic by implementing time-dependent validity periods for different answers. The system dynamically selects which answer is currently valid based on the challenge time, making the secret space adaptive and temporally varying. This dynamic approach prevents attackers from using static dictionary attacks while maintaining ease of recall for legitimate users.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If KBA uses static secrets shared between user and server, then authentication simplicity is improved, but fraud detection capability is worsened

Engineering Contradiction:
Improveauthentication process complexityVSAvoidfraud detection capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system incorporates feedback mechanisms by analyzing patterns in authentication attempts and using confidence scores to assess the likelihood of fraud. The server compares the provided answer against multiple pre-generated possible answers and their associated metadata, generating a confidence score that reflects the probability of legitimate authentication. This feedback loop enables fraud detection while maintaining simple authentication for legitimate users.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary confidence score mechanism that mediates between the simple answer verification and complex fraud detection. Rather than directly comparing static secrets, the system uses confidence scores derived from multiple factors including temporal validity, answer patterns, and metadata analysis. This intermediary layer adds fraud detection capability without significantly increasing the complexity perceived by users.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If personal information is made available through social networking and public records, then data accessibility is improved, but KBA vulnerability is worsened enabling sophisticated data-mining attacks

Engineering Contradiction:
Improvepersonal information accessibilityVSAvoiddata-mining attack risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system takes preliminary anti-action by pre-generating multiple possible answers and storing them with temporal validity metadata before any attack occurs. This preparation creates a defensive layer that makes data-mining attacks less effective, as attackers cannot simply retrieve one correct answer from public records. The temporal validity mechanism ensures that even if attackers obtain current information, the system can invalidate those answers over time.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system changes the parameters of KBA secrets by introducing temporal validity periods and generating multiple possible answers with different metadata characteristics. This parameter transformation makes static data-mining approaches ineffective, as the correct answer changes over time and is embedded within a set of plausible alternatives. The system dynamically adjusts which answer is valid based on temporal parameters, rendering publicly available static information less useful to attackers.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9009844B1Methods and apparatus for knowledge-based authentication using historically-aware questionnaires
Publication Date: 2015.04.14 EMC IP HLDG CO LLC
  • US9009844B1 patent drawing
  • US9009844B1 patent drawing
  • US9009844B1 patent drawing

AI summary

Knowledge-based authentication (KBA) is provided using historically-aware questionnaires. The KBA can obtain a plurality of historically different answers from the user to at least one question; challenge the user with the question for a given period of time; receive a response from the user to the question; and grant access to the restricted resource if the response is accurate for the given period of time based on the historically different answers. Alternatively, the KBA can be based on historically aware answers to a set of inter-related questions. The user is challenged with the inter-related questions for a given period of time. Historically different answers can comprise answers with applicable dates, or correct answers to the question over time. Historically aware answers can comprise an answer that is accurate for an indicated date or period of time. An accurate response demonstrates knowledge of multiple related personal events.