Behaviometric Authentication via TLS and FIDO Standards
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems require users to manage multiple online credentials, which can lead to security vulnerabilities and inconvenience, especially in online services that do not effectively differentiate between human and bot interactions.
Innovation Solution
A method utilizing a user device with an authentication-client and a behaviometric server to collect and analyze behavioral data during sessions, comparing it to stored profiles to validate user identity and detect fraudulent access, while ensuring secure communication through TLS and FIDO standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication systems are used requiring multiple credentials, then user identity verification can be achieved, but system complexity and user burden increase significantly
Solution Approach 1:
The patent implements a universal authentication system where a single credential can be used across multiple online services. The authentication server and behaviometric server work together to provide a unified authentication mechanism that replaces the need for service-specific credentials, allowing one credential to serve multiple authentication purposes across different platforms and services.
Solution Approach 2:
The patent introduces an authentication server and behaviometric server as intermediary components between the user agent and various online services. These servers mediate the authentication process by verifying credentials and analyzing behaviometric data, eliminating the need for users to directly manage credentials for each individual service while maintaining security and reliability.
2Reliability
If traditional authentication systems are used without behaviometric analysis, then authentication process is simpler, but security against bot interactions and fraudulent access is weakened
Solution Approach 1:
The patent implements a feedback mechanism where the behaviometric server continuously monitors user interactions and provides feedback to the authentication server. The system collects behaviometric data during user interactions, analyzes this data to detect patterns indicative of bots or fraudulent access, and uses this feedback to dynamically adjust authentication decisions, thereby enhancing security without requiring complete system redesign.
Solution Approach 2:
The patent performs preliminary behaviometric analysis during the authentication process itself, collecting and analyzing behavioral data before final authentication decisions are made. This preliminary action allows the system to identify suspicious patterns early in the interaction sequence, enabling proactive security measures rather than reactive responses after potential breaches occur.
3Reliability
If behavioral data is collected and analyzed continuously, then user identity validation is improved, but processing time and computational resources increase
Solution Approach 1:
The patent implements periodic behaviometric analysis where the system collects behavioral data continuously but performs comprehensive analysis at predetermined intervals or triggered by specific events during the user session. This periodic approach allows the system to maintain accurate identity validation while avoiding continuous computational processing, thereby reducing time loss and resource consumption compared to constant analysis.
Data Source
AI summary
Method for a secure authenticating of a user identity of a device for a service during a session including a transaction between an authentication-client and a connected authentication-server, whereby said authentication-client is running on said device using a user-agent with a specific authentication-interface to communicate encrypted authentication messages using a Transport Layer Security (TLS) protocol between said user-agent of said authentication-client and a web-server of both said authentication-server of a ‘Relying Party’ using a unique and secret authentication-identifier (e.g. a hash-value created from ‘Relying Party’, date and time) between them, and a Behaviometric-server using a unique and secret Behaviometric-identifier (e.g. a hash-value created from a Behaviometric-Server, date and time) between them, whereby said session comprising an earlier authentication stage and at least in authentication case (said user identity is positively authenticated) a later controlling stage. Also a related computer program algorithm and a computer-system executing this.

