Transaction-Based User Authentication Using Dynamic Challenge Questions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems rely on static security measures that are easily compromised, making them insecure and inconvenient for users, as they often require complex passwords and static user information that can be publicly accessible.
Innovation Solution
A method and system that leverage transaction data from payment transactions to dynamically authenticate users by generating challenge questions based on their past transactions, ensuring the user's knowledge of specific details from these transactions is verified.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static security measures (passwords, pin numbers) are used for authentication, then the authentication process is simple to implement, but the security is weak and easily compromised
Solution Approach 1:
The patent transforms static authentication (fixed passwords) into dynamic authentication by using real-time transaction data to generate challenge questions. The authentication parameters change continuously based on user transaction history, making the system adaptive and resistant to static breaches while maintaining operational simplicity.
Solution Approach 2:
The system changes the authentication parameter from fixed strings (passwords) to dynamic questions derived from transaction data. Challenge questions are regenerated based on transaction amount, merchant, location, and time parameters, creating a moving target that adapts to each authentication attempt.
2Reliability
If complex passwords are required for strong security, then the authentication security is improved, but the ease of operation deteriorates as users find it difficult to remember
Solution Approach 1:
The system uses the user's own transaction data as the basis for authentication challenges. Users authenticate themselves by answering questions about their own spending habits, which they naturally remember, eliminating the need to memorize complex passwords while maintaining security.
Solution Approach 2:
Transaction data serves as an intermediary between the user and the authentication system. Instead of directly asking for passwords, the system uses transaction information (merchant names, amounts, locations) as a mediator to create challenges that are secure yet naturally recallable by the user.
3Ease of operation
If the same security measure is used across multiple service providers, then the ease of operation is improved, but the security deteriorates as a single breach compromises all providers
Solution Approach 1:
Each service provider implements authentication based on its own unique transaction data, creating locally-specific security parameters. A breach at one provider only affects that provider's transaction data, not others, as each system uses its own transaction history to generate challenges.
Solution Approach 2:
The authentication system is segmented to use provider-specific transaction data rather than universal credentials. Each service provider's authentication is independent, based on its own transaction records, isolating security breaches to individual providers while maintaining operational consistency through the same challenge-response mechanism.
4Ease of operation
If publicly accessible information (current address) is used for authentication, then the ease of operation is improved, but the security deteriorates as the information is easily accessible
Solution Approach 1:
The system performs preliminary analysis of transaction data to identify unique, non-public characteristics before generating authentication challenges. By pre-processing transaction history to extract distinctive patterns (specific merchants, unusual amounts, rare locations), the system creates challenges based on information that hasn't been exposed publicly yet.
Data Source
AI summary
A system and method for authenticating a candidate user accessing a host computing device as an authentic user is provided. The host computing device is in communication with an authenticating computing device. The method includes receiving, by the authenticating computing device, a request to authenticate the candidate user as an authentic user. The authentication request includes a user identifier. The method also includes retrieving, by the authenticating computing device, transaction data including payment transactions performed by the authentic user based on the user identifier. The method also includes generating, by the authenticating computing device, a challenge question and a correct answer based on the transaction data associated with the authentic user, and transmitting the challenge question for display on a candidate user computing device used by the candidate user.


