Location-Based Authentication Questions for Shared Account Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Authentication questions based on transaction data can confuse legitimate users, especially when multiple users share an account, as they may not remember transactions conducted by others, leading to denied access to their own accounts.
Innovation Solution
Analyze location data from a user's device to tag transactions based on user presence, generating authentication questions only for transactions where the user was physically present, distinguishing between in-person and online transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication questions are generated based on all transactions associated with a shared account, then account security is improved, but legitimate users experience confusion and denied access because they cannot recall transactions conducted by other account holders
Solution Approach 1:
The patent segments transactions into different categories based on user presence: transactions where the user was physically present and transactions where they were not. This segmentation allows the system to generate authentication questions selectively from only those transactions the user can actually recall, resolving the contradiction between security and usability.
Solution Approach 2:
The system performs preliminary analysis of transaction data using location information to determine user presence before generating authentication questions. By pre-tagging transactions with presence indicators, the system ensures that only relevant, user-knowable transactions are used in authentication, preventing access denial while maintaining security.
2Reliability
If authentication questions are generated based on synthetic transactions, then security against guessing is improved, but user confusion increases when users are asked about transactions they did not conduct
Solution Approach 1:
The patent applies different qualities to different types of transactions: real transactions tagged with user presence information and synthetic transactions. Authentication questions are selectively generated based on local characteristics of each transaction type, ensuring users are only asked about transactions they can actually verify, thus maintaining both security and user understanding.
3Measurement precision
If location data analysis is implemented to tag transactions with user presence, then authentication accuracy is improved, but system complexity increases
Solution Approach 1:
The patent introduces location data as an intermediary element that objectively determines user presence at transaction locations. This intermediary provides a reliable, automated method for tagging transactions without requiring complex user input or manual verification, improving authentication accuracy while managing system complexity through the use of readily available location information.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, systems, and apparatuses are described herein for improving computer authentication processes by generating authentication questions based on the location of a user. Transaction data indicating a plurality of transactions associated with a user account may be received. Location data indicating a plurality of locations of a user device might be received. At least a subset of the plurality of transactions may be tagged, based on the location data, with an indication that a user was present for a respective transaction. For example, a location of a merchant might be compared to a user device location indicated by the location data. A plurality of authentication questions might be generated based on the subset of the plurality of transactions. Access to the user account might be provided based on responses to the plurality of authentication questions.