IP Library Granted Patent US 11,062,014
Granted Patent B1
US 11,062,014 · App. 15/883,704 · Granted Jul 13, 2021

Dynamic challenge question-based authentication

Inventors: Haim Raman (Netanya, IL); Tamar Vardy (Tel Aviv, IL); Adi Peer (Petach Tikva, IL); Aviram Shterenbaum (Kiryat Bialik, IL); Karin Daches (Tel Aviv, IL); Itzik Sorani (Kadima, IL)
Assignee: RSA Security LLC
G06F21/36G06N7/023G06F2221/2103
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,062,014
App. No.
15/883,704
Granted
Jul 13, 2021
Kind
B1
Abstract

Techniques for generating dynamic challenge questions for use in an authentication process are provided herein. An example computer-implemented method can include outputting a first prompt to a user via a user device interface, wherein the first prompt comprises a first set of information-gathering questions; generating dynamic challenge questions for use in an authentication process, wherein the dynamic challenge questions are generated based on user responses to the first set of information-gathering questions; generating a second prompt in connection with an authentication request, wherein the second prompt is based at least in part on at least one of the dynamic challenge questions; processing a user response to the at least one dynamic challenge question, wherein said processing comprises determining a likelihood that the user response matches an automatically estimated response; and resolving the authentication request based on the processing.

Claims (50)

1. A computer-implemented method for generating one or more dynamic challenge questions for use in an authentication process, the method comprising:

outputting a first prompt to a user via at least one user device interface, wherein the first prompt comprises a first set of one or more information-gathering questions, wherein a correct answer to the one or more information-gathering questions is unknown before the first prompt is outputted, and user responses to the first set of the one or more information-gathering questions include a direct answer and an additional item of information to at least one information gathering question of the one or more information gathering questions;

generating one or more dynamic challenge questions for use in an authentication process involving the user, wherein the one or more dynamic challenge questions are generated based on one or more user responses to the first set of one or more information-gathering questions;

generating a second prompt via the at least one user device interface in connection with an authentication request by the user to access a protected resource associated with the user device, wherein the second prompt is based at least in part on (i) at least one of the one or more dynamic challenge questions and (ii) a second set of one or more information-gathering questions, wherein user responses to the second set of one or more information-gathering questions are unknown, and wherein the second set of one or more information-gathering questions is generated based on one or more user responses to the first set of one or more information-gathering questions including the one or more new items of information:

processing at least one user response entered via the user device interface in response to the at least one dynamic challenge question, wherein said processing comprises determining a likelihood that the at least one user response matches at least one automatically estimated response;

resolving the authentication request based on said processing;

subsequent to resolving the authentication request, generating one or more additional dynamic challenge questions for use in an additional authentication request by the user to access the protected resource, wherein the one or more additional dynamic challenge questions are generated based at least in part on deriving new user-related information from (i) the one or more user responses to the first set of one or more information-gathering questions (ii) the at least one user response to the at least one dynamic challenge question generated in connection with the resolved authentication request and (iii) one or more user responses to the second set of one or more information-gathering questions: and

outputting a third prompt via the at least one user device interface in connection with the additional authentication request by the user to access the protected resource, wherein the third prompt is based at least in part on at least one of the one or more additional dynamic challenge questions;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The computer-implemented method of claim 1 , wherein said processing comprises applying fuzzy logic to the at least one user response.

3. The computer-implemented method of claim 1 , further comprising:

storing one or more user responses to the second set of one or more information-gathering questions in a database.

4. The computer-implemented method of claim 1 , further comprising:

storing the one or more user responses to the first set of one or more information-gathering questions in a database.

5. The computer-implemented method of claim 1 , wherein said resolving comprises granting access to the protected resource associated with the user device if the determined likelihood exceeds a pre-established threshold value.

6. The computer-implemented method of claim 5 , further comprising:

subsequent to said granting access to the protected resource, storing the at least one user response to the at least one dynamic challenge question in a database.

7. The computer-implemented method of claim 1 , wherein the third prompt is further based at least in part on a third set of one or more information-gathering questions, wherein user responses to the third set of one or more information-gathering questions are unknown.

8. The computer-implemented method of claim 7 , further comprising:

storing one or more user responses to the third set of one or more information-gathering questions in a database.

9. The computer-implemented method of claim 1 , further comprising:

processing at least one user response entered via the user device interface in response to the at least one additional dynamic challenge question, wherein said processing comprises determining a likelihood that the at least one user response to the at least one additional dynamic challenge question matches at least one automatically estimated response.

10. The computer-implemented method of claim 9 , wherein said processing comprises applying fuzzy logic to the at least one user response to the at least one additional dynamic challenge question.

11. The computer-implemented method of claim 9 , further comprising:

resolving the additional authentication request based on said processing of the at least one user response to the at least one additional dynamic challenge question.

12. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes said at least one processing device:

to output a first prompt to a user via at least one user device interface, wherein the first prompt comprises a first set of one or more information-gathering questions, wherein a correct answer to the one or more information-gathering questions is unknown before the first prompt is outputted, and user responses to the first set of the one or more information-gathering questions include a direct answer and an additional item of information to at least one information gathering question of the one or more information gathering questions;

to generate one or more dynamic challenge questions for use in an authentication process involving the user, wherein the one or more dynamic challenge questions are generated based on one or more user responses to the first set of one or more information-gathering questions;

to generate a second prompt via the at least one user device interface in connection with an authentication request by the user to access a protected resource associated with the user device, wherein the second prompt is based at least in part on (i) at least one of the one or more dynamic challenge questions and (ii) a second set of one or more information-gathering questions, wherein user responses to the second set of one or more information-gathering questions are unknown, and wherein the second set of one or more information-gathering questions is generated based on one or more user responses to the first set of one or more information-gathering questions including the one or more new items of information:

to process at least one user response entered via the user device interface in response to the at least one dynamic challenge question, wherein said processing comprises determining a likelihood that the at least one user response matches at least one automatically estimated response;

to resolve the authentication request based on said processing;

subsequent to resolving the authentication request, to generate one or more additional dynamic challenge questions for use in an additional authentication request by the user to access the protected resource, wherein the one or more additional dynamic challenge questions are generated based at least in part on deriving new user-related information from (i) the one or more user responses to the first set of one or more information-gathering questions (ii) the at least one user response to the at least one dynamic challenge question generated in connection with the resolved authentication request and (iii) one or more user responses to the second set of one or more information-gathering questions: and;

to output a third prompt via the at least one user device interface in connection with the additional authentication request by the user to access the protected resource, wherein the third prompt is based at least in part on at least one of the one or more additional dynamic challenge questions.

13. The non-transitory processor-readable storage medium of claim 12 , wherein said processing comprises applying fuzzy logic to the at least one user response.

14. The non-transitory processor-readable storage medium of claim 12 , wherein said resolving comprises granting access to the protected resource associated with the user device if the determined likelihood exceeds a pre-established threshold value.

15. The non-transitory processor-readable storage medium of claim 12 , wherein the third prompt is further based at least in part on a third set of one or more information-gathering questions, wherein user responses to the third set of one or more information-gathering questions are unknown.

16. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

said at least one processing device being configured:

to output a first prompt to a user via at least one user device interface, wherein the first prompt comprises a first set of one or more information-gathering questions, wherein a correct answer to the one or more information-gathering questions is unknown before the first prompt is outputted, and user responses to the first set of the one or more information-gathering questions include a direct answer and an additional item of information to at least one information gathering question of the one or more information gathering questions;

to generate one or more dynamic challenge questions for use in an authentication process involving the user, wherein the one or more dynamic challenge questions are generated based on one or more user responses to the first set of one or more information-gathering questions;

to generate a second prompt via the at least one user device interface in connection with an authentication request by the user to access a protected resource associated with the user device, wherein the second prompt is based at least in part on (i) at least one of the one or more dynamic challenge questions and (ii) a second set of one or more information-gathering questions, wherein user responses to the second set of one or more information-gathering questions are unknown, and wherein the second set of one or more information-gathering questions is generated based on one or more user responses to the first set of one or more information-gathering questions including the one or more new items of information:

to process at least one user response entered via the user device interface in response to the at least one dynamic challenge question, wherein said processing comprises determining a likelihood that the at least one user response matches at least one automatically estimated response;

to resolve the authentication request based on said processing;

subsequent to resolving the authentication request, to generate one or more additional dynamic challenge questions for use in an additional authentication request by the user to access the protected resource, wherein the one or more additional dynamic challenge questions are generated based at least in part on deriving new user-related information from (i) the one or more user responses to the first set of one or more information-gathering questions, and (ii) the at least one user response to the at least one dynamic challenge question generated in connection with the resolved authentication request and (iii) one or more user responses to the second set of one or more information-gathering questions: and

to output a third prompt via the at least one user device interface in connection with the additional authentication request by the user to access the protected resource, wherein the third prompt is based at least in part on at least one of the one or more additional dynamic challenge questions.

17. The apparatus of claim 16 , wherein said processing comprises applying fuzzy logic to the at least one user response.

18. The apparatus of claim 16 , wherein said resolving comprises granting access to the protected resource associated with the user device if the determined likelihood exceeds a pre-established threshold value.

19. The apparatus of claim 16 , wherein the third prompt is further based at least in part on a third set of one or more information-gathering questions, wherein user responses to the third set of one or more information-gathering questions are unknown.

20. The apparatus of claim 16 , wherein said at least one processing device is further configured: to process at least one user response entered via the user device interface in response to the at least one additional dynamic challenge question, wherein said processing comprises determining a likelihood that the at least one user response to the at least one additional dynamic challenge question matches at least one automatically estimated response.

Assignments (18)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 70587/0885 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075031/0394 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 21, 2025
From: RSA SECURITY LLC; RSA SECURITY USA LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 070587/0885 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 9, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054362/0008 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 053701/0112 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2018
From: RAMAN, HAIM; VANDY, TAMAR; PEER, ADI; SHTERENBAUM, AVIRAM; DACHES, KARIN; SORANI, ITZIK
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 044773/0458 →
Cited By (2)
US 12,603,873 US 12,685,573