Transaction-Based User Authentication Using Dynamic Challenge Questions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems rely on static security measures that are easily compromised, making them insecure and inconvenient for users, as they often require complex passwords and static user information that can be publicly accessible.

Innovation Solution

A method and system that leverage transaction data from payment transactions to dynamically authenticate users by generating challenge questions based on their past transactions, ensuring the user's knowledge of specific details from these transactions is verified.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static security measures (passwords, pin numbers) are used for authentication, then the authentication process is simple to implement, but the security is weak and easily compromised

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static authentication (fixed passwords) into dynamic authentication by using real-time transaction data to generate challenge questions. The authentication parameters change continuously based on user transaction history, making the system adaptive and resistant to static breaches while maintaining operational simplicity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameter from fixed strings (passwords) to dynamic questions derived from transaction data. Challenge questions are regenerated based on transaction amount, merchant, location, and time parameters, creating a moving target that adapts to each authentication attempt.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If complex passwords are required for strong security, then the authentication security is improved, but the ease of operation deteriorates as users find it difficult to remember

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses the user's own transaction data as the basis for authentication challenges. Users authenticate themselves by answering questions about their own spending habits, which they naturally remember, eliminating the need to memorize complex passwords while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Transaction data serves as an intermediary between the user and the authentication system. Instead of directly asking for passwords, the system uses transaction information (merchant names, amounts, locations) as a mediator to create challenges that are secure yet naturally recallable by the user.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the same security measure is used across multiple service providers, then the ease of operation is improved, but the security deteriorates as a single breach compromises all providers

Engineering Contradiction:
Improveauthentication consistencyVSAvoidoverall security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Each service provider implements authentication based on its own unique transaction data, creating locally-specific security parameters. A breach at one provider only affects that provider's transaction data, not others, as each system uses its own transaction history to generate challenges.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The authentication system is segmented to use provider-specific transaction data rather than universal credentials. Each service provider's authentication is independent, based on its own transaction records, isolating security breaches to individual providers while maintaining operational consistency through the same challenge-response mechanism.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If publicly accessible information (current address) is used for authentication, then the ease of operation is improved, but the security deteriorates as the information is easily accessible

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary analysis of transaction data to identify unique, non-public characteristics before generating authentication challenges. By pre-processing transaction history to extract distinctive patterns (specific merchants, unusual amounts, rare locations), the system creates challenges based on information that hasn't been exposed publicly yet.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12530688B2Methods and systems for leveraging transactions to dynamically authenticate a user
Publication Date: 2026.01.20 MASTERCARD INT INC
  • US12530688B2 patent drawing
  • US12530688B2 patent drawing
  • US12530688B2 patent drawing

AI summary

A system and method for authenticating a candidate user accessing a host computing device as an authentic user is provided. The host computing device is in communication with an authenticating computing device. The method includes receiving, by the authenticating computing device, a request to authenticate the candidate user as an authentic user. The authentication request includes a user identifier. The method also includes retrieving, by the authenticating computing device, transaction data including payment transactions performed by the authentic user based on the user identifier. The method also includes generating, by the authenticating computing device, a challenge question and a correct answer based on the transaction data associated with the authentic user, and transmitting the challenge question for display on a candidate user computing device used by the candidate user.