Behavioral Biometric Authentication System and Method
Patent Information
- Application Number
- TR202612598
- Authority / Receiving Office
- TR · TR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-07-27
- Publication Date
- 2026-08-21
Smart Images

Figure 00000010_0000 
Figure 00000011_0000
Abstract
Description
1 TARIFF Behavioral Biometric Authentication System and Method Technical Area This invention is used in mobile devices, computers, banking applications, e-government platforms, User ID 5 in corporate networks and all computing infrastructures requiring secure access authentication processes used and continuous authentication during the session It is related to a system and method of implementation. State of the Art Current authentication methods used today include: Password / PIN, SMS verification. - OTP, fingerprint, and facial recognition can be listed as examples. Some of these methods have shortcomings. 10 These methods include obtaining passwords through techniques such as phishing and keyloggers. It can be bypassed. SMS verification can be bypassed by SIM cloning. Fingerprint and facial recognition. Verification done via this method can be misleading with photos / videos. Also, in these methods, the user... They have to perform verification constantly. Current systems only verify upon login. After the user logs in, 15... The system does not detect it if someone else approaches the device. Patent application number TR2026 / 011328, which is included in the prior art. The document describes an AI-powered digital identity management system. (Related) The system, elements used, and solution method described in the application document. It has a different structure. 20 In conclusion, solutions that address the needs described above are relevant to the subject. Due to its shortcomings, it has become necessary to make improvements in the relevant technical field. Brief Description of the Invention The invention was created by drawing inspiration from existing situations and overcoming the aforementioned drawbacks. It aims to solve. 25 The purpose of this invention is to improve mobile devices, computers, banking applications, and e-government services. platforms, corporate networks and all computing infrastructures requiring secure access 2 User authentication processes are used and persistent identity verification is maintained throughout the session. It involves establishing a system and method for carrying out verification. The subject of the invention is a behavioral biometric authentication system, specifically using passwords, PINs, and It is implemented as an alternative to SMS verification processes or as an additional layer of security. System; 5 Real-time collection of user interaction data, Measuring the physical movements of device usage, Creation of a behavioral biometric profile for the user, Comparison of immediate behavior with a reference model, Automatic session termination upon detection of unauthorized users and 10 Continuous authentication during the session It is configured to perform its operations. The structural and characteristic features and all the advantages of the invention are given in the figures below. This becomes clearer thanks to the detailed explanation written with references to these figures. This will be understood, and therefore the evaluation should also take these forms and detailed explanations into account. 15 It needs to be done by taking precautions. Figures that will help understand the invention. Figure 1 is a schematic representation of the system that is the subject of the invention. Figure 2 shows the flowchart of the method described in the invention. Description of Part References 20 1. System 2. Session control unit 3. Data collection module 4. Sensor analysis module 5. Behavioral profiler 25 6. Anomaly detection engine 3 Method 1000 1001. The user logs into the system via their device and the system provides services. start using the application 1002. User interaction data in the form of touch, scroll, and key press durations. Collection by the collection module 5 1003. Sensor analysis module, via which the device consists of an accelerometer and gyroscope. Obtaining usage and movement data from sensors 1004. Pre-processing the collected data by the behavioral profiler and filtering noise data 1005. Through the behavior profile generator, time intervals, speed, rhythm, pressure 10 Extracting user behavioral characteristics in the form of parameters 1006. Creating a behavioral biometric profile using a behavioral profile generator. or updating the existing profile 1007. Through the anomaly detection engine, the real-time user behavior is compared with the reference profile. comparison 15 1008. Calculating the matching score using the anomaly detection engine. 1009. The matching score is above the confidence threshold value, as determined by the anomaly detection engine. checking whether it exists 1010. If the matching score is above the threshold, the anomaly detection engine session ends. continuation 20 1011. If the matching score is below the threshold, the anomaly detection engine is considered unauthorized. detecting usage 1012. When unauthorized use is detected, the session is terminated by the session control unit. termination and request for re-authentication Detailed Description of the Invention 25 4 In this detailed description, the system (1) and method (1000) that are the subject of the invention are preferred. Their structures are explained solely to facilitate a better understanding of the subject. This invention is used in mobile devices, computers, banking applications, e-government platforms, User identity verification in corporate networks and all IT infrastructures requiring secure access. authentication used in verification processes and continuous authentication during the session 5 It is related to a system (1) and method (1000) that performs. The subject of the invention is a behavioral biometric authentication system (1), in particular password, PIN and It is implemented as an alternative to SMS verification processes or as an additional layer of security. The system, schematically shown in Figure 1 (1); performs real-time threshold control, and after this control, 10 unauthorized persons are identified. If it identifies the user, it restricts access to the device the user is using. Session control unit (2) that enables termination, It is an application programming interface with touch event capture capability. used to collect user interactions, using the user's device When it starts, it analyzes the user's touchscreen interactions, key press durations, 15 Key transition times and screen scrolling gestures in real time. data collection module (3) which records as used to measure the physical movements of the user's device usage, data obtained from accelerometer and gyroscope sensors in the user's device By processing the data, it analyzes the user's device grip angle, movement characteristics, and 20 Sensor analysis that determines micro-vibration behavior during use. module (4), data collected by the data collection module (3) and the sensor analysis module (4) the field, extracting the user model and modeling the time series, the resulting time By performing statistical modeling and pattern extraction on the series of data, 25 It creates a user-specific behavioral biometric reference profile and stores it in memory. behavior profiler (5) and The device has a machine learning anomaly algorithm and its use continues. while continuously comparing real-time user behavior with a reference profile, During this comparison, the matching score is calculated and the determined confidence level is 30. Situations falling below the threshold are considered unauthorized use and are deemed fraudulent. the session control unit that identifies the user and detects unauthorized use. (2) by enabling the automatic termination of the active user session, locking the screen and requesting optional re-authentication. anomaly detection engine (6) that enables it to be detected It includes. System (1); Real-time collection of user interaction data, 5 Measuring the physical movements of device usage, Creation of a behavioral biometric profile for the user, Comparison of immediate behavior with a reference model, Automatic session termination upon detection of unauthorized users and Continuous authentication during the session 10 It is configured to perform its operations. System (1) is software that identifies the user based on their behavior, not their password. It is an application with an algorithm that is installed on the user's device. System (1); Keystroke duration, 15 Time between two keys - flight time, screen scrolling speed touch pressure Device holding angle via accelerometer & gyroscope and writing rhythm 20 It continuously collects data: System (1) then; Creation of a behavioral biometric profile for the user, training the machine learning model, Continuous comparison is made in the background and 25 Automatic session termination if threshold value is exceeded It performs its operations. 6 System (1); time series analysis, Anomaly detection algorithm, dynamic thresholding and Sensor fusion - sensor fusion 5 It uses techniques. The method presented in the flowchart in Figure 2 (1000); the user logs into the system (1) via their device and the system (1) provides service (1001), User interaction data in the form of touch, scrolling, and key press durations 10 data collection by the data collection module (3) (1002), via the sensor analysis module (4) the device in the form of accelerometer and gyroscope Obtaining usage motion data from sensors (1003), The collected data are pre-processed by the behavior profiler (5). retention and filtering of noise data (1004), 15 through the behavior profile generator (5), time intervals, speed, rhythm, pressure Extraction of user behavioral characteristics in the form of parameters (1005), behavioral biometric profile through the behavioral profile generator (5) creation or updating of an existing profile (1006), Reference profile of instantaneous user behavior via an anomaly detection engine (6) 20 comparison with (1007), Calculation of the matching score (1008) via the anomaly detection engine (6), through the anomaly detection engine (6), the confidence threshold of the matching score checking whether it is on it (1009), If the matching score is above the threshold value, the anomaly detection engine (6) 25 continuation of the session (1010), If the matching score is below the threshold value, the anomaly detection engine (6) detecting unauthorized use (1011) and When unauthorized use is detected, the session is terminated by the session control unit (2). termination and request for re-authentication (1012) 30 It includes the steps involved in the process. 7 In the system in question (1), when the user starts using the device, data is first provided. User touchscreen interactions and button presses are collected by the collection module (3). Durations, keystroke times, and screen scrolling movements are displayed in real time. It is recorded as such. At the same time, the sensor analysis module (4), the accelerometer and gyroscope 5 located in the device By processing data from its sensors, it determines the user's grip angle and movement. It determines its characteristics and micro-vibration behavior during use. The collected data is transferred to the behavior profiler (5). Behavior profiler (5), statistical modeling and pattern extraction on the obtained time series data By doing so, it creates a user-specific behavioral biometric reference profile and stores it in memory. It hides. The device continuously detects anomalies in real-time user behavior while in use. The motor (6) is compared with the reference profile. During this comparison, the matching A score is calculated, and situations that fall below the defined confidence threshold are considered unauthorized use. It is considered as follows: 15 If the matching score falls below the threshold value, the session control unit (2) is activated. By entering this information, it automatically ends the active user session, locks the screen, and offers optional features. It requests re-verification. In this way, the system (1) provides continuous identification not only at the time of login but throughout the session. By performing verification, it technically prevents unauthorized access. 20 The system in question (1) is a client software that runs on a mobile device or computer. within a client-server architecture consisting of a remote authentication server He is working. When the user logs into the application, interaction and sensor data from the device are collected. The data is transmitted to the system (1) via a secure communication network. The system (1) has previously transmitted this data to the system (1) via a secure communication network. It produces a validation result by comparing it with the created user behavior profile, and the result depends on the relevant service infrastructure, such as banking, corporate networks or e-government It transmits it to the application. Thanks to this structure, the system (1) can be added to existing security infrastructures and the user Continuous authentication is performed as long as the session continues. 30
Claims
8 REQUESTS 1. Performs real-time threshold control, and after this control, prevents unauthorized access. If it identifies the user, it restricts access to the device the user is using. mobile device or session control unit (2) that enables termination. Remote authentication with client software running on a computer 5 mobile devices, operating within a client-server architecture consisting of a server, computers, banking applications, e-government platforms, corporate networks, and User authentication in all IT infrastructures requiring secure access used in transactions and performing continuous authentication during the session a system (1) and its feature is; 10 It is an application programming interface with touch event capture capability. used to collect user interactions, using the user's device When it starts, it analyzes the user's touchscreen interactions, button press durations, Key transition times and screen scrolling gestures in real time. Data collection module (3), which records as 15 used to measure the physical movements of the user's device usage, data obtained from accelerometer and gyroscope sensors in the user's device by processing the data, the user's device grip angle, movement characteristics, and Sensor analysis that determines micro-vibration behavior during use. module (4), 20 data collected by the data collection module (3) and the sensor analysis module (4) the field, extracting the user model and modeling the time series, the resulting time By performing statistical modeling and pattern extraction on series data. It creates a user-specific behavioral biometric reference profile and stores it in memory. behavior profiler (5) and 25 The device has a machine learning anomaly algorithm and its use continues. while continuously comparing real-time user behavior with a reference profile, During this comparison, the matching score is calculated and the determined confidence level is established. Situations falling below the threshold are considered unauthorized use and are deemed fraudulent. If the session control unit identifies the user and detects unauthorized use, it will shut down the session control unit. (2) by enabling the automatic termination of the active user session, locking the screen and requesting optional re-authentication. anomaly detection engine (6) that enables it to be detected 9 It includes.
2. Mobile devices, computers, banking applications, e-government platforms, corporate User identity verification in all computing infrastructures requiring networks and secure access authentication processes used and continuous authentication during the session a method that performs (1000) and its feature is; 5 the user logs into the system (1) via their device and the system (1) provides service (1001), User interaction data in the form of touch, scrolling, and key press durations data collection by the data collection module (3) (1002), Through the sensor analysis module (4), the device in the form of an accelerometer and gyroscope 10 Obtaining usage motion data from sensors (1003), The collected data are pre-processed by the behavior profiler (5). retention and filtering of noise data (1004), through the behavior profile generator (5), time intervals, speed, rhythm, pressure Extraction of user behavioral characteristics in the form of parameters (1005), 15 behavioral biometric profile through the behavioral profile generator (5) creation or updating of an existing profile (1006), Reference profile of instantaneous user behavior via an anomaly detection engine (6) comparison with (1007), Calculation of the matching score (1008) via the anomaly detection engine (6), 20 through the anomaly detection engine (6), the confidence threshold of the matching score checking whether it is on it (1009), If the matching score is above the threshold value, the anomaly detection engine (6) continuation of the session (1010), If the matching score is below the threshold value, the anomaly detection engine (6) 25 detecting unauthorized use (1011) and When unauthorized use is detected, the session is terminated by the session control unit (2). termination and request for re-authentication (1012) It includes the steps of the process.