Dynamic Social Network Authentication Questions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users often forget the answers to security questions set up for authentication, leading to inconvenience and potential security issues when trying to access websites or applications.

Innovation Solution

A method and apparatus that generate authentication questions based on a user's records from social networking services, eliminating the need for users to set up and remember security questions, with each authentication process receiving a unique question and allowing answers within a time-limited period.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users set up security questions for authentication, then authentication capability is provided, but users may forget the answers causing authentication failure

Engineering Contradiction:
Improveauthentication capabilityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically generates security questions based on the user's own social networking data without requiring user setup. The user's social network profile, friends list, or activity history serves as the source material for generating authentication questions, eliminating the need for manual security question configuration while ensuring the user can answer based on their familiar information

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system transforms static security questions into dynamic, context-aware questions by changing the parameter source from user-defined to system-generated based on social networking parameters. The questions adapt to the user's specific social network profile, making them both secure and answerable by the user without memorization

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If security questions are generated from user's social networking records, then user convenience is improved, but authentication security may be compromised

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary analysis of the user's social networking data to generate authentication questions before the authentication event occurs. By pre-processing the social network information and selecting appropriate questions based on security criteria, the system ensures both user convenience and authentication security are maintained

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms to evaluate the security quality of generated questions. By analyzing the sensitivity and uniqueness of social networking data, the system can adjust question selection to maintain security standards while ensuring user answerability, creating a feedback loop that balances convenience and security

Inventive Principle:
Principle #23Feedback

3Device complexity

If the same security question is used for multiple authentication processes, then system complexity is reduced, but security effectiveness decreases

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system implements dynamic security questions that change based on the authentication context, user's current social networking state, and security requirements. Each authentication process can receive a different question drawn from the user's social network profile, ensuring security effectiveness without requiring complex manual configuration

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses a universal pool of social networking data that serves multiple authentication purposes. The same social network profile information can generate multiple different authentication questions across various authentication events, providing both security diversity and system simplicity through a single data source

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9985944B2Method and apparatus for user authentication
Publication Date: 2018.05.29 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US9985944B2 patent drawing
  • US9985944B2 patent drawing
  • US9985944B2 patent drawing

AI summary

A method and apparatus for authenticating a user is provided, the method includes: receiving an authentication request sent from a user device by a user; providing basic information in response to the authentication request, wherein the basic information comprises information related to a social networking service used by the user; generating authentication information based on the basic information, wherein the authentication information comprises a question and a corresponding answer; sending the question to the user device and receiving feedback information from the user device; and generating an authentication result by verifying whether the feedback information is consistent with the answer, and sending the authentication result to the user device. The method and apparatus address the issue of forgotten answers to security questions used in user authentication.