Social Network Activity Authentication Challenge Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication technologies do not effectively utilize social network activity information to generate challenges that are secure against fraudulent login attempts while minimizing burden on legitimate users.

Innovation Solution

A system and method that analyzes an account owner's social network activity information to generate authentication challenges, comprising a login receiver, fraudulent login detection engine, social network activity information analysis engine, and challenge generation engine, which creates challenges based on this information to verify user identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing authentication technologies (secret questions, CAPTCHA, calendar activities) are used to guard against fraudulent login attempts, then security against bots and automated devices is improved, but the burden on legitimate users increases and social network activity information is not utilized

Engineering Contradiction:
Improvesecurity against fraudulent loginVSAvoiduser burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically analyzes the user's social network activity information and generates authentication challenges without requiring manual setup by the user. The challenge is derived from the user's own social graph data, making the system self-configuring and reducing user burden while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameter basis for authentication from static information (secret questions, calendar events) to dynamic social network activity parameters. By utilizing the user's social graph connections and activity patterns, the system creates challenges that are both secure and naturally familiar to the user, reducing burden

Inventive Principle:
Principle #35Parameter changes

2Reliability

If social network activity information is utilized to generate authentication challenges, then security is improved and user burden is reduced, but the system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses a multi-functional architecture where the social network activity information serves multiple purposes: it provides the basis for generating authentication challenges, establishes security thresholds, and defines user profiles. This universal use of social graph data reduces overall system complexity by eliminating the need for separate authentication data collection systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces a fraud detection engine as an intermediary component that mediates between the login attempt and the authentication challenge generation. This intermediary analyzes social network activity patterns and determines whether to trigger a challenge, simplifying the overall control flow and making the system more manageable despite increased functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8997240B1Generating user authentication challenges based on social network activity information
Publication Date: 2015.03.31 GOOGLE LLC
  • US8997240B1 patent drawing
  • US8997240B1 patent drawing
  • US8997240B1 patent drawing

AI summary

A system and method for generating user authentication challenges based at least in part on an account owner's social network activity information. A login request including an account owner's correct username and password as well as additional login information is received from a user. The login attempt is detected as a potentially fraudulent based on the additional login information from the user. The account owner's social network activity information is analyzed. An authentication challenge based at least in part on the account owner's social network activity information is generated and sent for display. The login request is allowed or denied based on the completion on the authentication challenge.