Combined OTP and KBA Identity Authentication System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Business entities and governmental agencies face challenges in authenticating identities effectively to prevent identity-related fraud, as existing authentication methods can be compromised by sophisticated deception schemes, balancing security with efficient service.

Innovation Solution

A combined authentication process utilizing One-Time Passcode (OTP) and Knowledge-Based Authentication (KBA), where OTP codes are provided as multiple-choice answers to KBA questions, leveraging 'possession' and 'knowledge' factors for enhanced security, with OTP codes and questions sent through different communication channels to increase security layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used, then service efficiency is maintained, but security against sophisticated fraud is compromised

Engineering Contradiction:
Improveauthentication securityVSAvoidservice efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines OTP (Something You Have) and KBA (Something You Know) authentication methods into a unified system. The authentication process integrates both factors by presenting KBA questions to the user and verifying their responses against pre-stored answers, while simultaneously managing OTP code generation and validation. This merging of multiple authentication factors strengthens security without significantly impacting service efficiency for legitimate users.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multiple authentication factors are combined, then security is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is designed to perform multiple functions through a unified process. It can authenticate users using either KBA, OTP, or both factors depending on the configuration and risk assessment. The system universally handles different authentication scenarios (new account registration, password reset, suspicious activity verification) through the same multi-factor framework, reducing the need for separate specialized systems for each authentication type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If KBA questions are used alone, then ease of operation is maintained, but vulnerability to fraud increases

Engineering Contradiction:
Improveauthentication convenienceVSAvoidfraud vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system preemptively counteracts fraud risks by implementing additional authentication layers before granting access. When fraud is detected or suspected, the system automatically requires both KBA and OTP verification instead of relying on KBA alone. This preliminary anti-action prevents fraudulent attempts before they can succeed, while maintaining ease of operation for legitimate users who can complete either factor quickly.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS9380057B2Systems and methods for combined OTP and KBA identity authentication
Publication Date: 2016.06.28 LEXISNEXIS RISK SOLUTIONS INC
  • US9380057B2 patent drawing
  • US9380057B2 patent drawing
  • US9380057B2 patent drawing

AI summary

Certain implementations include systems and methods for combined one-time-passcode (OTP) and knowledge-based-authentication (KBA) identity authentication. A method is provided that includes receiving a set of identity information associated with a subject; querying one or more databases; receiving personally identifiable information; producing at least one knowledge based authentication (KBA) identity proofing question having a personally identifiable correct answer; generating a unique correct one-time pass (OTP) code for the personally identifiable correct answer; generating one or more incorrect answers with corresponding incorrect codes; outputting, the at least one KBA identity proofing question; outputting the personally identifiable correct answer with the unique correct OTP code, and the one or more incorrect answers with corresponding incorrect codes; receiving a response code; comparing the response code and the unique correct OTP code; and responsive to a match between the response code and the unique correct OTP code, outputting a first indication of authentication.