Password-Free Identity Validation via Personalized Challenge Questions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online identity validation methods are either cumbersome and hardware-reliant, or vulnerable due to the use of PINs and passwords, failing to effectively prevent identity theft and requiring high user compliance.

Innovation Solution

Implementing a system that validates user identity through Knowledge Based Authentication (KBA) questions and personalized challenge questions, eliminating the need for PINs or passwords, and providing an additional layer of security by using credit reporting data to generate questions based on the user's credit profile and personal experiences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware devices such as fingerprint readers or USB keys are used for identity validation, then security is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security validation function from hardware devices and relocates it to the server-side system. Instead of requiring fingerprint readers or USB keys at the client端, the system uses server-based validation of personal data and credit information to achieve the same security objective, thereby eliminating the need for complex hardware devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces credit reporting agencies and personal data as intermediary elements in the validation process. These intermediaries provide verification of user identity through credit checks and personal information validation, replacing the need for direct hardware-based authentication while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware devices are used for identity validation, then security is improved, but ease of operation worsens due to higher user compliance requirements

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs automated validation of user identity through server-based credit checks and personal data verification. This self-service approach eliminates the need for users to manually interact with hardware devices or comply with complex authentication procedures, while still maintaining high security standards.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If PINs and passwords are used for access control, then ease of operation is improved, but security deteriorates due to vulnerabilities to identity theft

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent fundamentally changes the validation parameter from user-created credentials (PINs and passwords) to objective personal data parameters such as credit history, personal information, and identity verification data. This parameter change maintains ease of operation while significantly improving security by using data that is difficult for fraudsters to replicate.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If manual review and call center validation are used, then security is improved, but productivity and loss of time worsen

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual review processes and call center validation with automated electronic systems that perform credit checks, validate personal data, and verify user identity through server-based algorithms. This substitution eliminates the need for human intervention while maintaining security, thereby improving productivity and reducing time loss.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements automated feedback loops where user-provided personal data is immediately validated against credit reporting agencies and stored validation results. This real-time feedback mechanism provides security verification without requiring manual review, thus maintaining productivity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8515847B2System and method for password-free access for validated users
Publication Date: 2013.08.20 E2E SYSTEMS LLC
  • US8515847B2 patent drawing
  • US8515847B2 patent drawing
  • US8515847B2 patent drawing

AI summary

A new approach is proposed that first validates identity of a user/individual who is initiating a request for a web service for the first time. Once validated, the user is allowed to access the web service, to register securely with the provider of the web service, and to create a series of personalized questions to be used for future validation purposes. During the user's subsequent request for the web service, the user will be asked, in addition to his/her user name, one or more of the personalized questions he/she created on rotation basis in place of a PIN or password.