Auxiliary Behavioral Biometric Authentication Factor

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication schemes that rely on demonstrating possession of an object, such as a mobile phone, are vulnerable to attackers gaining physical access to the object, allowing unauthorized access to user accounts.

Innovation Solution

A computer-implemented method that includes an auxiliary authentication factor based on behavioral biometrics, which verifies whether the object being used as a possession factor is still in the possession of the correct user, enhancing security by requiring attackers to also imitate user characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication schemes use possession factors (such as mobile phone) to enhance security, then authentication security is improved, but the system becomes vulnerable to physical theft of the possession object

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to physical theft
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the authentication parameter from static possession verification to dynamic behavioral verification. By monitoring behavioral biometric parameters (typing rhythm, mouse movement patterns, device handling characteristics) and comparing them against stored baseline parameters, the system continuously verifies user identity even when the possession object is stolen, thereby resolving the vulnerability to physical theft while maintaining authentication security

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements continuous feedback by monitoring user interactions with the possession object and providing real-time verification. The authentication system receives feedback from behavioral sensors, analyzes deviations from normal usage patterns, and can trigger additional authentication challenges or alert security systems when anomalies are detected, thereby preventing unauthorized access even if the possession object is compromised

Inventive Principle:
Principle #23Feedback

2Reliability

If additional authentication factors are required to improve security, then security against attacks is enhanced, but user convenience and ease of operation deteriorates

Engineering Contradiction:
Improvesecurity against attacksVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs authentication automatically without requiring additional user actions. Behavioral biometrics are captured passively during normal device interaction, and the authentication process occurs in the background without interrupting the user workflow. This self-service approach maintains high security by continuously verifying identity while preserving user convenience by eliminating manual authentication steps

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent merges the authentication function with the normal device usage experience. Instead of separating authentication into distinct steps, the system combines security verification with everyday interactions such as typing, scrolling, and device handling. This integration allows the system to collect authentication data during routine activities, thereby enhancing security without adding separate authentication procedures that would reduce user convenience

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20240073207A1User authentication
Publication Date: 2024.02.29 BRITISH TELECOM PLC
  • US20240073207A1 patent drawing
  • US20240073207A1 patent drawing
  • US20240073207A1 patent drawing

AI summary

A computer implemented method for authenticating a user, the method including receiving an authentication request from a first computer system, the authentication request including an indication of an identity of the user to be authenticated; receiving one or more authentication factors for verifying the identity of the user, the one or more authentication factors including at least one authentication factor obtained from a second computer system associated with the user having the indicated identity; receiving an auxiliary authentication factor, the auxiliary authentication factor comprising data for verifying that the second computer system is currently in the possession of the user having the indicated identity; and verifying the identity of the user based on the one or more authentication factors and the auxiliary authentication factor.