Identity Verification via User-Specific Exam Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity verification systems for accessing confidential information over networks, such as credit files, are inadequate as they rely heavily on passwords and security questions, which can be insecure and cumbersome, especially when users forget passwords or lack sufficient information for question-based authentication, and require complex programming for evolving security questions.

Innovation Solution

A system that uses a server to create and administer exams based on user-specific data, allowing access to confidential information only after successful completion of the exam, which can be answered through a client interface or an IVR system, providing a secure and efficient alternative authentication method that can be managed by non-technical personnel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password-based authentication is used, then security is provided, but user convenience deteriorates when passwords are forgotten or compromised

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces security questions as an intermediary authentication mechanism between the user and the password system. When passwords are forgotten or compromised, the security questions serve as a mediator to verify user identity without requiring the original password, thus maintaining security while improving user convenience during recovery scenarios

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the authentication process through security questions that are separate from the password mechanism. Instead of relying solely on the password copy, the system uses knowledge-based questions that replicate the authentication function through a different pathway, providing redundancy and user convenience

Inventive Principle:
Principle #26Copying

2Ease of operation

If security questions are used for authentication, then user convenience is improved, but system complexity increases due to programming requirements for evolving questions

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements dynamic security questions that can be updated and evolved without requiring complex system reprogramming. The system allows security questions to change over time based on user profiles and security requirements, with the ability to adapt the question set dynamically while maintaining a manageable underlying structure

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication system is segmented into modular components where security questions are separated from the core authentication logic. This segmentation allows the question bank to be independently managed and updated without affecting the overall system complexity, enabling non-technical personnel to maintain the question set

Inventive Principle:
Principle #1Segmentation

3Reliability

If manual credit file checking is required, then data security is maintained, but time consumption increases significantly

Engineering Contradiction:
Improvedata securityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication through security questions before granting access to confidential information. This preliminary verification step ensures data security is maintained while automating the process, eliminating the need for time-consuming manual credit file checking by users

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system enables users to verify their own identities and access their credit files through self-service authentication using security questions. This eliminates the need for manual intervention by support staff while maintaining security, allowing users to quickly access their information without time-consuming manual processes

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9843582B2Identity verification systems and methods
Publication Date: 2017.12.12 TRANS UNION LLC
  • US9843582B2 patent drawing
  • US9843582B2 patent drawing
  • US9843582B2 patent drawing

AI summary

Systems and methods for authenticating the identity of a user prior to giving access to confidential data at a user interface via a network are described. In an exemplary implementation in an Internet environment, a server hosts an application providing selective access by the user to confidential data related to the user. The user provides initial data to the application as part of a request to access the confidential data. At least one database having the confidential data stored therein is accessed by the server to retrieve confidential data relating to the user located in the database based on the initial data received from the client interface. An exam creation function causes the server to create an exam comprising at least one question based at least in part on a portion of the confidential data relating to the user. This function creates the exam based on at least one exam definition. An exam administration function causes the server to transmit the exam to the client interface for presentation to the user. The user is granted access to the confidential data subsequent to determination that the user successfully passed the exam.