USER AUTHENTICATION SYSTEM THROUGH PHYSICAL ENVIRONMENT INTERACTION
Patent Information
- Application Number
- TR202615282
- Authority / Receiving Office
- TR · TR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-09-07
- Publication Date
- 2026-09-21
Abstract
Description
1 TARIFF USER AUTHENTICATION THROUGH PHYSICAL ENVIRONMENT INTERACTION SYSTEM Technical Area 5 This invention allows users to interact with the physical world using electronic device sensors. with a user authentication system that requires interaction It is related. Previous Technique Current technology includes mobile applications, digital banking, and e-payment systems. Identity verification is required when conducting transactions through platforms (e-Government) Similar processes are being carried out. Users are asked to verify their identity before 15 minutes from bots. or needs to be separated from automation tools. Existing CAPTCHA and While OTP systems are effective in distinguishing users from bots, users This can negatively impact the experience and may make it inaccessible for visually impaired people. And in some cases, these can be overcome with artificial intelligence. Furthermore, these systems are generally... It provides one-time verification and 20% protection against session hijacking. It does not offer protection. Therefore, it is necessary to overcome the shortcomings mentioned. A new system is needed for this. United States Law No. US2025307376, which is included in the known state of the art. 25 An identifier used to verify the creation of digital content in the patent document. The text refers to a verification system. The system is related to the content creation process. a machine learning structured to analyze data points The classifier applies predefined criteria to data points. a structured programmatic rule-based analytics component and content generation 30 human-structured to provide a visual representation of the process It includes a viewable playback component. The authentication system, 2 from the machine learning classifier, from the programmatic rule-based analysis component and outputs from the human-viewable playback component based on whether the digital content was created by a human or by artificial intelligence (AI). It is configured to determine whether it was created. Keys are used between data points. Stroke dynamics, syntax and style analysis, error patterns and corrections, content 5 revision history, behavioral data, content creation timeline, gestures, and tactile interactions, brushstrokes and drawing patterns, sound and voice analysis, physical interaction with devices, eye tracking and gaze patterns, and biometrics. Data may be included. Brief Description of the Invention The purpose of this invention is to enable users to physically interact with electronic device sensors. a user identity verification that requires interaction with the world The goal is to implement the system. 15 Detailed Description of the Invention The "Physical Environment Interaction" experiment was conducted to achieve the purpose of this invention. The "User Authentication System" is shown in the attached figure; this figure is 20. Figure 1. Schematic view of the system described in the invention. The parts shown in the figure are individually numbered, and the corresponding numbers correspond to these numbers. given below: 25 1. System 2. Electronic device 3. Server 3 Users interact with the physical world using electronic device sensors. The invention involves user authentication, which requires interaction. system (1); - Users can make transfers, send passwords via an application or a web interface. to perform critical operations in the form of modification, operation 5 taking the necessary actions to verify the user during the process, the task is presented for verification, and the light is detected by the sensors it possesses in relation to the task. the collection of data on physical interactions such as closing, hitting or shaking, at least one electronic device that enables the collected data to be signed with a private key. (2) and 10 -in the process of users performing critical operations via electronic devices (2) It is triggered the moment a one-time verification is performed, for the verification Unique verification request ID, random one-time token, timeout. information and the creation of a task to be performed, electronic response to the task receive the signature generated from the device (2) as a response, then the verification request 15 Is the ID valid, has it been used before, has it expired, or is it a device? Is it a registered device with an ID, and can the signature be verified with a public key? checks such as whether the timing is within a reasonable range and whether high risk has been identified. the process must be completed, and verification must be successful if all checks are passed. and the user can continue with the transaction, otherwise the transaction will be rejected. 20 It includes at least one server (3) configured to provide. The electronic device (2) included in the system (1) which is the subject of the invention, enables users to telecommunication operators, banks, e-commerce platforms and government institutions For transactions to be carried out on platforms, an application or 25 to provide at least one interface that allows them to access it via the web page It is configured. Electronic device (2), users can make transfers, change passwords in authentication processes to perform critical operations such as these by interacting with their physical environment and collecting data about the environment It is configured to provide data input. The electronic device (2) allows data input. a phone, tablet, or portable computer with a screen that provides 4 It is a device in the form of an electronic device (2), the light produced when the screen is turned off. It has at least one light sensor to detect a drop in its level. Electronic device (2), short sounds created in the environment such as hitting the table, clapping hands It has at least one microphone that enables the detection of impact sounds. Electronic When the device (2) is shaken or moved slightly, the relevant condition is 5 It contains at least one gyroscope / accelerometer capable of sensing. Electronic device (2), The shadow change that occurs when the user places their hand in front of the screen is image data. at least one camera that allows detection solely based on density difference. It includes an electronic device (2) which requires user authentication. enter transaction requests, 10 for identity verification upon request the task requested from the user in written and visual form display, execution of the displayed task, perception of the task, task If the authentication was successfully completed, then the identity verification is deemed appropriate and the desired result has been obtained. at least one that provides the user with information that the transaction can be carried out It includes an interface. The electronic device (2) is specially designed for use in signature operations. to enable the creation and storage of a private key is configured. The electronic device (2) has the unique authentication request ID, timestamp data, response time, and task completion result are stored privately. It is configured to sign with a key. The electronic device (2) is configured to sign with the server (3) 20 to generate a signature that can be verified with the public key is structured. Electronic device (2), located in the known state of the art. connect to the server (3) using any remote communication protocol and to exchange data with the server (3) through this established connection It is structured. The preferred application of the invention is an electronic device (2), Exchange of data with the server (3) using a data bus in the form of the Internet 25 It is structured to accomplish this. The server (3) in the system in question (1) is located in the known state of the art. to communicate with an electronic device (2) using any communication protocol and data exchange with electronic device (2) through this established communication 30 It is configured to perform. Server (3), electronic device (2) performing a transaction that requires user authentication triggered by the request, it creates a one-time authentication request for the user. It is configured to request. The server (3) requests the unique validation request. Its ID, a random one-time use token, timeout information, and an action to be performed. It is configured to include tasks. The server (3) has 5 tasks. This will be done if the user is asked to cover the screen with their finger. to transmit the task in written and visual form to the electronic device (2) and to change the light level The data regarding whether there is a drop in light level is measured by the light sensor. It is configured to enable it to be obtained without having it. The server (3) is configured as a task. 10 actions to be performed if the user is asked to tap on the table or clap their hands to transmit the task in written and visual form to the electronic device (2) and while hitting the table The short pulsed sound data generated while flapping the wool is detected by the microphone, and its frequency is determined. After conducting a time analysis, only data on whether or not a coup occurred should be collected. It is configured to provide the server (3), as a task for the user's electronic If asked to shake his (2) device, the task to be performed will be documented in writing and visually. 15 to transmit to the electronic device (2) and the oscillation motion with the gyroscope / accelerometer by separating the device from smooth and repetitive robotic movements, (2) slightly The server is configured to receive data on whether or not it is shaking. (3), as a task, the shadow in front of the user’s electronic device (2) camera If it is desired to create a change in light intensity in the form of its formation, then 20 to transmit the task to be performed in written and visual form to the electronic device (2) and without recording any image with the camera, only the light intensity of the environment. The server (3) is configured to enable the acquisition of the change data. collecting sensor data and analyzing the presence of physical interaction, 25 Enable calculation of the user's response time to the task. The server (3) is configured to set a timeout period for the task. The server (3) is configured with the unique authentication request ID, timestamp, Combining response time and task outcome data, then using a private key. To ensure that signed data is verified with a public key. is configured. Server (3) performs validation on combined data 30 The server is configured to enable this process and the calculation of the risk score. 6 (3), securing the session after successful verification and identity Allow the user to proceed with an action that requires verification. and to ensure the risk situation is monitored throughout the session. is configured. Server (3), geographic location, device profile, behavior pattern, Generating a risk score using data such as transaction frequency and adding an additional 5 in case of high risk. The verification trigger is being configured. Industrial Application of the Invention The system (1) that is the subject of the invention enables users to use electronic device (2) sensors to 10 a verification system that requires interaction with the physical world It offers. The user is asked to close the screen, tap lightly, or use the device. Simple, quick, and natural movements like shaking, and types of movements that bots cannot perform. Security is enhanced by facilitating physical interactions. Around these fundamental concepts, the invention is called "Interaction Between the Physical Environment and the User". It is possible to develop a wide variety of applications related to the Verification System (1)” and the invention cannot be limited to the examples described here, but mainly to the claims as stated.
Claims
7 REQUESTS 1. Users interacting with the physical world using electronic device sensors. requiring interaction; - Users can make a transfer, password 5 via an application or a web interface. The process involves performing critical operations such as modification. doing so is necessary for user authentication during the process. taking actions, presenting the user with a task for verification, assigning the task Based on its sensors, it can turn off the light when it is hit or shaken. the collection of physical interaction data in the form of 10 at least one electronic device (2) that enables signing with a private key and -users performing critical operations via electronic device (2) a one-time verification is performed by being triggered at the moment the process is in progress For verification, a unique verification request ID is used; randomly selected. The token, timeout information, and the creation of a task to be performed, 15 In response to the task, the signature generated from the electronic device (2) is in reply. receive it, then check if the verification request ID is valid or has been used before. Is it unused, has the time limit expired, is the device ID registered? Can the signature be verified with a public key? Is the response time reasonable? Checks should be carried out to determine whether it is within the range or if a high risk has been identified, 20 If all checks are passed, the verification will be successful. the user can continue the process, otherwise the process will be terminated with at least one server (3) configured to ensure its rejection a characterized user authentication system (1).
2. Users' telecommunications operators, banks, e-commerce platforms and for transactions that it will carry out on platforms in the form of state institutions platforms that allow them to access them via an application or web page electronic device (2) configured to provide at least one interface A system like the one in Claim 1, characterized (1). 30 8 3. Critical user transactions such as money transfers and password changes. physical locations where they are undergoing identity verification processes to carry out By interacting with the environment, it enables the collection of data related to the environment. Claim 1 is characterized by an electronic device (2) configured to be or A system like the one in 2 (1). 5 4. A phone or tablet computer with a screen that allows data entry. or electronic device (2) which is a portable computer a system like any of the above characterized claims (1). 10 5. To detect the drop in light level caused by turning off the screen. electronic device (2) characterized by having a small light sensor a system like any of the above requests (1).
6. A short, spontaneous impact created in the environment, such as banging on a table or clapping hands. an electronic device that has at least one microphone to enable the detection of sounds (2) like any of the above-mentioned claims characterized by system (1).
7. Able to detect the relevant situation when gently shaken or moved. electronic device (2) characterized by containing at least one gyroscope / accelerometer a system like any of the above requests (1).
8. The shadow change that occurs when the user places their hand in front of the screen. 25 The best way to detect density difference without receiving image data. the above characterized by an electronic device (2) containing a small camera a system like any of the requests (1).
9. Performing an action that requires user authentication 30 enter their requests, request identity verification from the user upon request. 9 providing written and visual representations of the task requested to be performed, the displayed task being performed, the task being perceived, the task being successful If it was carried out as requested, then the authentication is deemed appropriate and the desired result is obtained. enabling the user to be provided with information regarding whether the transaction can be carried out. The above 5 is characterized by an electronic device (2) containing at least one interface. a system like any of the requests (1).
10. Private key for use in signature processes. electronic systems structured to enable the creation and storage of data. 10 of the above claims characterized by the device (2) such a system (1).
11. Unique authentication request ID, timestamp data, response time and to sign the completed task result with a private key. The above 15 is characterized by the structured electronic device (2). a system like any of the requests (1).
12. Signature that the server can verify with the (3) public key. characterized by an electronic device (2) configured to produce a system like any of the above requests (1). 20 13. Connect to the server (3) using any remote communication protocol. to establish and exchange data with the server (3) through this established connection characterized by an electronic device (2) configured to perform a system like any of the above requests (1). 25 14. Exchange of data with the server (3) using a data bus in the form of the Internet. characterized by an electronic device (2) configured to perform a system like the one in Request 13 (1). 10 15. Communicate with an electronic device (2) using any communication protocol. to establish and to send data via electronic device (2) through this established communication Characterized by the server (3) configured to carry out the transaction. a system like any of the above-mentioned requests (1).
16. Electronic device (2) requiring user authentication triggered by a request to perform an action, a one-time user transaction with the server (3) configured to create a verification request a system like any of the above characterized claims (1). 10 17. The unique verification request ID of the request is a random one-time use token. Ensure it includes timeout information and a task to be performed. from the above requests characterized by the server (3) configured for a system like any other (1). 15 18. If the task involves the user covering the screen with their finger... The task to be performed is recorded in writing and visually on an electronic device (2) transmitting and detecting whether there is a sudden drop in light level with the light sensor 20 to provide the above characterized by the configured server (3) a system like any of the requests (1).
19. As a task, the user is asked to tap on the table or clap their hands. The task to be performed must be recorded in written and visual form on an electronic device. 25 (2) transmitting and short pulse sounds produced when hitting the table or clapping. After the data is detected by the microphone and frequency and duration analysis is performed It was structured solely to provide data on whether or not a coup took place. in any of the above requests characterized by the server (3) such a system (1). 30 11 20. Task: The user is asked to shake their electronic device (2). The task to be performed will be recorded electronically in written and visual form on an electronic device. (2) to transmit and smooth the rocking motion with gyroscope / accelerometer by separating the device from repetitive robotic movements (2) slightly The configured server 5 enables the collection of data on whether it is shaking or not. (3) like any of the above-mentioned claims characterized by system (1).
21. As a task, the user's shadow in front of the electronic device (2) camera If it is desired to create a change in light intensity in the form of its formation, then 10 The task to be performed is recorded in writing and visually on an electronic device (2) to transmit and record images with a camera, only showing the surrounding environment. The system is configured to enable the acquisition of light intensity change data. in any of the above requests characterized by the server (3) such a system (1). 15 22. Collection of all sensor data and analysis of the presence of physical interaction. the calculation of the user's response time to the task to provide the above characterized by the configured server (3) a system like any of the requests (1). 20 23. A timeout period is being configured for the task. Server (3), unique validation request ID, timestamp, response time and task The result is the merging of the data and then signed with a private key. 25 Ensuring that data is verified with a public key from the above requests characterized by the configured server (3) a system like any other (1).
24. Verification and risk score on the combined data. 30 characterized by the configured server (3) to enable calculation. a system like any of the above requests (1). 12 25. After successful verification, secure the session and verify identity. Allow the user to perform an action that requires verification. to ensure and monitor the risk situation throughout the session. 5 of the above requests characterized by the configured server (3). a system like any other (1).
26. Geographic location, device profile, behavioral pattern, and transaction frequency. Generating a risk score from data and providing additional verification in high-risk situations. The above 10 is characterized by triggering configured server (3). a system like any of the requests (1). 20 30