Authorization-Based Behaviometric Identification for Secure Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing behaviometric user authentication methods face challenges in balancing inconspicuous data collection with user privacy, as unauthorized data collection can violate moral and legal standards.

Innovation Solution

A method involving a server that requests authorization for behaviometric data collection from an end-user device, using a request-response mechanism to determine if the user has previously consented to data collection, and if not, requesting device-identifying data to authenticate the user, thereby ensuring privacy and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If behaviometric data collection is implemented for user authentication, then authentication accuracy and security are improved, but user privacy and moral/legal compliance deteriorate due to unauthorized data collection

Engineering Contradiction:
Improveauthentication accuracyVSAvoiduser privacy violation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authorization requests before collecting behaviometric data. The server sends an authorization request to the end-user device, and only after receiving explicit user authorization does the system proceed with data collection. This preliminary action ensures user consent is obtained beforehand, preventing privacy violations while enabling authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The end-user device acts as an intermediary between the server and the behaviometric data collection process. The device receives authorization requests from the server, obtains user consent locally, and then either permits or blocks the data collection. This intermediary role protects user privacy by ensuring authorization is obtained before data flows to the server.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If explicit authorization requests are sent to end-user devices before data collection, then user privacy is protected through consent, but system complexity and authentication time increase

Engineering Contradiction:
Improveuser privacy protectionVSAvoidauthentication system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

Authorization status is determined in advance before the actual authentication process. The system checks whether the user has previously authorized behaviometric data collection, and stores this authorization status. During subsequent authentication attempts, the system only needs to verify the pre-stored authorization status rather than presenting full authorization requests, reducing complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The end-user device maintains local records of authorization status and uses these records to automatically respond to server requests without requiring repeated user interactions. Once the user provides initial authorization, the device autonomously manages subsequent authorization decisions based on stored credentials, reducing system complexity.

Inventive Principle:
Principle #25Self-service

3Productivity

If behaviometric data is collected without prior user consent, then authentication can be performed more inconspicuously and efficiently, but moral and legal privacy violations occur

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidprivacy violation
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system obtains user authorization in advance before implementing efficient behaviometric authentication. The preliminary authorization step ensures that subsequent data collection and authentication processes can proceed efficiently without repeated consent requests, while still maintaining moral and legal compliance through prior user consent.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11329975B1Authorization-based behaviometric identification
Publication Date: 2022.05.10 BEHAVIOSEC INC
  • US11329975B1 patent drawing
  • US11329975B1 patent drawing
  • US11329975B1 patent drawing

AI summary

A method of granting or denying access to data is disclosed herein. A server requests behaviometric data from a device regarding a user thereof. If behaviometric data is provided, the server uses it to authenticate the user. If behaviometric data is not provided, the server requests device-identifying data from the device. If the device-identifying data matches data of a device from which a user previously consented to collection of behaviometric data, behaviometric data is collected. If not, a request for collection is made.