Location-Based Authentication Questions for Shared Account Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Authentication questions based on transaction data can confuse legitimate users, especially when multiple users share an account, as they may not remember transactions conducted by others, leading to denied access to their own accounts.

Innovation Solution

Analyze location data from a user's device to tag transactions based on user presence, generating authentication questions only for transactions where the user was physically present, distinguishing between in-person and online transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication questions are generated based on all transactions associated with a shared account, then account security is improved, but legitimate users experience confusion and denied access because they cannot recall transactions conducted by other account holders

Engineering Contradiction:
Improveaccount securityVSAvoiduser access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments transactions into different categories based on user presence: transactions where the user was physically present and transactions where they were not. This segmentation allows the system to generate authentication questions selectively from only those transactions the user can actually recall, resolving the contradiction between security and usability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary analysis of transaction data using location information to determine user presence before generating authentication questions. By pre-tagging transactions with presence indicators, the system ensures that only relevant, user-knowable transactions are used in authentication, preventing access denial while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication questions are generated based on synthetic transactions, then security against guessing is improved, but user confusion increases when users are asked about transactions they did not conduct

Engineering Contradiction:
Improvesecurity against guessingVSAvoiduser understanding
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different qualities to different types of transactions: real transactions tagged with user presence information and synthetic transactions. Authentication questions are selectively generated based on local characteristics of each transaction type, ensuring users are only asked about transactions they can actually verify, thus maintaining both security and user understanding.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If location data analysis is implemented to tag transactions with user presence, then authentication accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces location data as an intermediary element that objectively determines user presence at transaction locations. This intermediary provides a reliable, automated method for tagging transactions without requiring complex user input or manual verification, improving authentication accuracy while managing system complexity through the use of readily available location information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4367590B1User presence detection for authentication question generation
Publication Date: 2025.12.10 CAPITAL ONE SERVICES LLC
  • EP4367590B1 patent drawingFigure 1
  • EP4367590B1 patent drawingFigure 2
  • EP4367590B1 patent drawingFigure 3

AI summary

Methods, systems, and apparatuses are described herein for improving computer authentication processes by generating authentication questions based on the location of a user. Transaction data indicating a plurality of transactions associated with a user account may be received. Location data indicating a plurality of locations of a user device might be received. At least a subset of the plurality of transactions may be tagged, based on the location data, with an indication that a user was present for a respective transaction. For example, a location of a merchant might be compared to a user device location indicated by the location data. A plurality of authentication questions might be generated based on the subset of the plurality of transactions. Access to the user account might be provided based on responses to the plurality of authentication questions.