Behaviometric Authentication via TLS and FIDO Standards

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems require users to manage multiple online credentials, which can lead to security vulnerabilities and inconvenience, especially in online services that do not effectively differentiate between human and bot interactions.

Innovation Solution

A method utilizing a user device with an authentication-client and a behaviometric server to collect and analyze behavioral data during sessions, comparing it to stored profiles to validate user identity and detect fraudulent access, while ensuring secure communication through TLS and FIDO standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication systems are used requiring multiple credentials, then user identity verification can be achieved, but system complexity and user burden increase significantly

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication system where a single credential can be used across multiple online services. The authentication server and behaviometric server work together to provide a unified authentication mechanism that replaces the need for service-specific credentials, allowing one credential to serve multiple authentication purposes across different platforms and services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an authentication server and behaviometric server as intermediary components between the user agent and various online services. These servers mediate the authentication process by verifying credentials and analyzing behaviometric data, eliminating the need for users to directly manage credentials for each individual service while maintaining security and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional authentication systems are used without behaviometric analysis, then authentication process is simpler, but security against bot interactions and fraudulent access is weakened

Engineering Contradiction:
Improvesecurity against fraudVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the behaviometric server continuously monitors user interactions and provides feedback to the authentication server. The system collects behaviometric data during user interactions, analyzes this data to detect patterns indicative of bots or fraudulent access, and uses this feedback to dynamically adjust authentication decisions, thereby enhancing security without requiring complete system redesign.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary behaviometric analysis during the authentication process itself, collecting and analyzing behavioral data before final authentication decisions are made. This preliminary action allows the system to identify suspicious patterns early in the interaction sequence, enabling proactive security measures rather than reactive responses after potential breaches occur.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If behavioral data is collected and analyzed continuously, then user identity validation is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveidentity validation accuracyVSAvoidsession processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic behaviometric analysis where the system collects behavioral data continuously but performs comprehensive analysis at predetermined intervals or triggered by specific events during the user session. This periodic approach allows the system to maintain accurate identity validation while avoiding continuous computational processing, thereby reducing time loss and resource consumption compared to constant analysis.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10437971B2Secure authentication of a user of a device during a session with a connected server
Publication Date: 2019.10.08 BEHAVIOSEC INC
  • US10437971B2 patent drawing
  • US10437971B2 patent drawing

AI summary

Method for a secure authenticating of a user identity of a device for a service during a session including a transaction between an authentication-client and a connected authentication-server, whereby said authentication-client is running on said device using a user-agent with a specific authentication-interface to communicate encrypted authentication messages using a Transport Layer Security (TLS) protocol between said user-agent of said authentication-client and a web-server of both said authentication-server of a ‘Relying Party’ using a unique and secret authentication-identifier (e.g. a hash-value created from ‘Relying Party’, date and time) between them, and a Behaviometric-server using a unique and secret Behaviometric-identifier (e.g. a hash-value created from a Behaviometric-Server, date and time) between them, whereby said session comprising an earlier authentication stage and at least in authentication case (said user identity is positively authenticated) a later controlling stage. Also a related computer program algorithm and a computer-system executing this.