LLM Caller Authentication Using Personalized User Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies for identifying and addressing the challenges of malicious third-party access to user accounts are not foolproof and are often exploited by malicious third parties, leading to unauthorized access and information theft.
Innovation Solution
Utilizing a personalized large language model (LLM) trained on user-specific data and a general-purpose LLM to generate tailored identification questions, which are answered and compared against user data to authenticate the caller's identity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If generic predetermined questions are used for authentication, then the system is simple to operate, but the authentication effectiveness deteriorates because the questions are easily found online and are not personalized to the user
Solution Approach 1:
The patent applies local quality by transitioning from generic questions to personalized questions that are specifically tailored to each user based on their unique data, behaviors, and context. The system generates authentication questions that are locally relevant to the specific user being authenticated, making the questions difficult for attackers to predict while maintaining ease of use through automated question generation and administration.
2Ease of operation
If a list of predetermined questions and answers is maintained, then the authentication process is simple, but the system becomes complex to maintain and update regularly to remain effective
Solution Approach 1:
The system implements self-service by automatically generating and updating authentication questions based on user data, behaviors, and context without requiring manual intervention to maintain the question list. The automated question generation system continuously adapts to changing user patterns and eliminates the need for human administrators to manually update questions, thereby reducing maintenance complexity while maintaining high authentication effectiveness.
Solution Approach 2:
The patent applies parameter changes by dynamically adjusting authentication questions based on changing user behaviors, data patterns, and contextual information. Instead of using a static list of predetermined questions, the system continuously evolves the questions based on real-time analysis of user activity, making the authentication mechanism adaptable to new threats and user patterns without manual reconfiguration.
3Ease of manufacture
If publicly available information is used for verification questions, then the questions are easy to generate, but the authentication security deteriorates because malicious third parties can easily find and exploit this information
Solution Approach 1:
The system extracts authentication questions away from publicly available information sources and generates them from private, proprietary data about the user's behaviors, patterns, and context. By taking out the question generation process from public data and grounding it in private user-specific information, the system eliminates the vulnerability where attackers can easily find verification answers online while maintaining ease of automated question generation.
4Reliability
If automated voice assistants ask identification questions to callers, then the system can prevent some malicious access, but the authentication remains not foolproof and can be deceived
Solution Approach 1:
The patent applies mechanics substitution by replacing traditional mechanical authentication methods (fixed question lists, simple secrets) with an intelligent system that uses AI-generated questions based on user behavior patterns, contextual analysis, and proprietary data. This substitution of the authentication mechanism from static to dynamic, intelligent question generation significantly improves reliability while making deception by malicious third parties much more difficult.
Data Source
AI summary
A third-party attempting to call a user is identified and authenticated by collecting multi-dimensional user data and user activity into a personalized large language model (LLM) residing on a user device. A general-purpose LLM generates third-party authentication questions based on an initial intent of the caller and the questions are provided to the personalized LLM with the answers from the personalized LLM ranked based on relevancy and accuracy. One or more of the highest ranked questions are prompted to the caller and the answers provided by the caller are compared to the answers provided by the personalized LLM to determine if the caller is a trusted contact or a likely malicious third-party.


