Historically-Aware Questionnaires for Knowledge-Based Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Knowledge-based authentication (KBA) systems are vulnerable to brute-force and dictionary attacks due to the use of secrets with low entropy, making them susceptible to fraud, especially with the increasing availability of personal information through social engineering and data mining.
Innovation Solution
The implementation of silent-alarm knowledge-based authentication (SA-KBA) that uses historically-aware questionnaires to assess a user's credibility by embedding a silent alarm in their responses, allowing the server to differentiate between legitimate and fraudulent authentication attempts through a confidence score, without requiring modifications to existing applications or communication protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If KBA uses secrets with low entropy for easy recall, then user convenience is improved, but security is worsened making the system vulnerable to brute-force and dictionary attacks
Solution Approach 1:
The system pre-generates multiple possible answers for each KBA question and stores them with metadata indicating their temporal validity. During authentication, the system selects an answer from the pre-generated set that is currently valid, rather than relying on a single static secret. This preliminary preparation allows the system to maintain security while preserving user convenience.
Solution Approach 2:
The KBA secrets are transformed from static to dynamic by implementing time-dependent validity periods for different answers. The system dynamically selects which answer is currently valid based on the challenge time, making the secret space adaptive and temporally varying. This dynamic approach prevents attackers from using static dictionary attacks while maintaining ease of recall for legitimate users.
2Device complexity
If KBA uses static secrets shared between user and server, then authentication simplicity is improved, but fraud detection capability is worsened
Solution Approach 1:
The system incorporates feedback mechanisms by analyzing patterns in authentication attempts and using confidence scores to assess the likelihood of fraud. The server compares the provided answer against multiple pre-generated possible answers and their associated metadata, generating a confidence score that reflects the probability of legitimate authentication. This feedback loop enables fraud detection while maintaining simple authentication for legitimate users.
Solution Approach 2:
The patent introduces an intermediary confidence score mechanism that mediates between the simple answer verification and complex fraud detection. Rather than directly comparing static secrets, the system uses confidence scores derived from multiple factors including temporal validity, answer patterns, and metadata analysis. This intermediary layer adds fraud detection capability without significantly increasing the complexity perceived by users.
3Loss of information
If personal information is made available through social networking and public records, then data accessibility is improved, but KBA vulnerability is worsened enabling sophisticated data-mining attacks
Solution Approach 1:
The system takes preliminary anti-action by pre-generating multiple possible answers and storing them with temporal validity metadata before any attack occurs. This preparation creates a defensive layer that makes data-mining attacks less effective, as attackers cannot simply retrieve one correct answer from public records. The temporal validity mechanism ensures that even if attackers obtain current information, the system can invalidate those answers over time.
Solution Approach 2:
The system changes the parameters of KBA secrets by introducing temporal validity periods and generating multiple possible answers with different metadata characteristics. This parameter transformation makes static data-mining approaches ineffective, as the correct answer changes over time and is embedded within a set of plausible alternatives. The system dynamically adjusts which answer is valid based on temporal parameters, rendering publicly available static information less useful to attackers.
Data Source
AI summary
Knowledge-based authentication (KBA) is provided using historically-aware questionnaires. The KBA can obtain a plurality of historically different answers from the user to at least one question; challenge the user with the question for a given period of time; receive a response from the user to the question; and grant access to the restricted resource if the response is accurate for the given period of time based on the historically different answers. Alternatively, the KBA can be based on historically aware answers to a set of inter-related questions. The user is challenged with the inter-related questions for a given period of time. Historically different answers can comprise answers with applicable dates, or correct answers to the question over time. Historically aware answers can comprise an answer that is accurate for an indicated date or period of time. An accurate response demonstrates knowledge of multiple related personal events.


