Password-Free Identity Validation via Personalized Challenge Questions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online identity validation methods are either cumbersome and hardware-reliant, or vulnerable due to the use of PINs and passwords, failing to effectively prevent identity theft and requiring high user compliance.
Innovation Solution
Implementing a system that validates user identity through Knowledge Based Authentication (KBA) questions and personalized challenge questions, eliminating the need for PINs or passwords, and providing an additional layer of security by using credit reporting data to generate questions based on the user's credit profile and personal experiences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware devices such as fingerprint readers or USB keys are used for identity validation, then security is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent extracts the security validation function from hardware devices and relocates it to the server-side system. Instead of requiring fingerprint readers or USB keys at the client端, the system uses server-based validation of personal data and credit information to achieve the same security objective, thereby eliminating the need for complex hardware devices.
Solution Approach 2:
The patent introduces credit reporting agencies and personal data as intermediary elements in the validation process. These intermediaries provide verification of user identity through credit checks and personal information validation, replacing the need for direct hardware-based authentication while maintaining security.
2Reliability
If hardware devices are used for identity validation, then security is improved, but ease of operation worsens due to higher user compliance requirements
Solution Approach 1:
The system performs automated validation of user identity through server-based credit checks and personal data verification. This self-service approach eliminates the need for users to manually interact with hardware devices or comply with complex authentication procedures, while still maintaining high security standards.
3Ease of operation
If PINs and passwords are used for access control, then ease of operation is improved, but security deteriorates due to vulnerabilities to identity theft
Solution Approach 1:
The patent fundamentally changes the validation parameter from user-created credentials (PINs and passwords) to objective personal data parameters such as credit history, personal information, and identity verification data. This parameter change maintains ease of operation while significantly improving security by using data that is difficult for fraudsters to replicate.
4Reliability
If manual review and call center validation are used, then security is improved, but productivity and loss of time worsen
Solution Approach 1:
The patent replaces manual review processes and call center validation with automated electronic systems that perform credit checks, validate personal data, and verify user identity through server-based algorithms. This substitution eliminates the need for human intervention while maintaining security, thereby improving productivity and reducing time loss.
Solution Approach 2:
The system implements automated feedback loops where user-provided personal data is immediately validated against credit reporting agencies and stored validation results. This real-time feedback mechanism provides security verification without requiring manual review, thus maintaining productivity.
Data Source
AI summary
A new approach is proposed that first validates identity of a user/individual who is initiating a request for a web service for the first time. Once validated, the user is allowed to access the web service, to register securely with the provider of the web service, and to create a series of personalized questions to be used for future validation purposes. During the user's subsequent request for the web service, the user will be asked, in addition to his/her user name, one or more of the personalized questions he/she created on rotation basis in place of a PIN or password.


