Authorization-Based Behaviometric Identification for Secure Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing behaviometric user authentication methods face challenges in balancing inconspicuous data collection with user privacy, as unauthorized data collection can violate moral and legal standards.
Innovation Solution
A method involving a server that requests authorization for behaviometric data collection from an end-user device, using a request-response mechanism to determine if the user has previously consented to data collection, and if not, requesting device-identifying data to authenticate the user, thereby ensuring privacy and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If behaviometric data collection is implemented for user authentication, then authentication accuracy and security are improved, but user privacy and moral/legal compliance deteriorate due to unauthorized data collection
Solution Approach 1:
The system performs preliminary authorization requests before collecting behaviometric data. The server sends an authorization request to the end-user device, and only after receiving explicit user authorization does the system proceed with data collection. This preliminary action ensures user consent is obtained beforehand, preventing privacy violations while enabling authentication.
Solution Approach 2:
The end-user device acts as an intermediary between the server and the behaviometric data collection process. The device receives authorization requests from the server, obtains user consent locally, and then either permits or blocks the data collection. This intermediary role protects user privacy by ensuring authorization is obtained before data flows to the server.
2Object-affected harmful factors
If explicit authorization requests are sent to end-user devices before data collection, then user privacy is protected through consent, but system complexity and authentication time increase
Solution Approach 1:
Authorization status is determined in advance before the actual authentication process. The system checks whether the user has previously authorized behaviometric data collection, and stores this authorization status. During subsequent authentication attempts, the system only needs to verify the pre-stored authorization status rather than presenting full authorization requests, reducing complexity.
Solution Approach 2:
The end-user device maintains local records of authorization status and uses these records to automatically respond to server requests without requiring repeated user interactions. Once the user provides initial authorization, the device autonomously manages subsequent authorization decisions based on stored credentials, reducing system complexity.
3Productivity
If behaviometric data is collected without prior user consent, then authentication can be performed more inconspicuously and efficiently, but moral and legal privacy violations occur
Solution Approach 1:
The system obtains user authorization in advance before implementing efficient behaviometric authentication. The preliminary authorization step ensures that subsequent data collection and authentication processes can proceed efficiently without repeated consent requests, while still maintaining moral and legal compliance through prior user consent.
Data Source
AI summary
A method of granting or denying access to data is disclosed herein. A server requests behaviometric data from a device regarding a user thereof. If behaviometric data is provided, the server uses it to authenticate the user. If behaviometric data is not provided, the server requests device-identifying data from the device. If the device-identifying data matches data of a device from which a user previously consented to collection of behaviometric data, behaviometric data is collected. If not, a request for collection is made.


