Targeted Authentication Queries Based on User Actions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods, including two-factor authentication, are vulnerable to security attacks such as key-loggers, phishing, malware, and other malicious technologies, compromising user identity and account security.

Innovation Solution

The implementation of targeted authentication queries based on detected user actions and historical events, where a service provider generates authentication queries tailored to a user's specific experiences and actions, enhancing security by requiring only the user to know the answers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (username/password, two-factor authentication) are used, then authentication security is improved, but the system becomes vulnerable to key-loggers, phishing, malware, and other malicious technologies

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to security attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional mechanical authentication systems (username/password, tokens) with a knowledge-based authentication system that uses targeted authentication queries. The system substitutes the mechanical verification process with an intelligent query generation mechanism that leverages user-specific information stored in a database, making it resistant to automated attacks like key-loggers and phishing since the queries are dynamically generated based on user behavior patterns and historical data.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication system performs self-service by automatically generating targeted authentication queries based on stored user information and behavior patterns. The system serves itself by maintaining a database of user-specific data and automatically creating personalized queries without requiring manual intervention, thereby improving security while reducing the need for complex user input.

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If targeted authentication queries based on user actions are implemented, then vulnerability to security attacks is reduced, but device complexity increases due to the need for user action detection and query generation systems

Engineering Contradiction:
Improvevulnerability to security attacksVSAvoidauthentication system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-storing user-specific information, actions, and events in a database before authentication is needed. This pre-processing of data allows the authentication system to quickly generate targeted queries without complex real-time analysis, thereby reducing the computational complexity during the actual authentication process while maintaining high security through personalized queries.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary component - a database that stores user information, actions, and events - which mediates between the user and the authentication system. This intermediary simplifies the overall system architecture by centralizing data storage and retrieval operations, making the complex authentication process more manageable and scalable while maintaining security through personalized query generation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If authentication queries are tailored to user's specific experiences and actions, then authentication accuracy is improved, but the time required for authentication increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidauthentication time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial action by selecting only the most relevant user actions and events to create authentication queries, rather than requiring users to answer questions about all their historical activities. This selective approach maintains high authentication accuracy by focusing on the most distinguishing user-specific information while minimizing the time required for authentication by limiting the scope of queries to essential elements only.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250158998A1Targeted authentication queries based on detected user actions
Publication Date: 2025.05.15 PAYPAL INC
  • US20250158998A1 patent drawing
  • US20250158998A1 patent drawing
  • US20250158998A1 patent drawing

AI summary

There are provided systems and methods for targeted authentication queries based on detected user actions. A user may perform various actions during a day, including online, electronic, or digital actions, such as social networking, messaging, and media consumption, as well as real-life actions, such as exercise, travel, and purchases. The actions may be used to determine a user history for the user by a service provider. When the user wishes to login to an account or otherwise authenticate the identity of the user, the user may provide login or authentication credentials. The credentials may be used to look up the user history and cause the service provider to generate an authentication-query for the user based on events associated with the user in the user history. The query may be utilized to further authenticate the user by requiring the user to respond with the event associated with the user.