Behavior-Based Authentication With Fallback for Reliable Mobile Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for mobile communication systems, such as PINs, passwords, and fingerprint sensors, are cumbersome, insecure, or prone to failure due to user behavior changes or environmental conditions, necessitating an improved and reliable authentication method.

Innovation Solution

A hybrid authentication system that combines behavior-based authentication with a fallback option using predefined authentication characteristics, such as alphanumeric strings, biometrics, or possession factors, ensuring seamless and secure access by leveraging user behavior and alternative methods when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If behavior-based authentication is used, then ease of operation is improved, but reliability deteriorates when user behavior changes or environmental conditions affect the behavior

Engineering Contradiction:
Improveauthentication convenienceVSAvoidauthentication reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically switches between behavior-based authentication and fallback authentication methods based on detected changes in user behavior or environmental conditions. When behavior patterns deviate from the norm or environmental factors interfere with behavior capture, the system transitions from behavior-based to alternative authentication methods, ensuring continuous reliability while maintaining ease of operation under normal conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system pre-establishes multiple fallback authentication methods (PIN, password, biometric) as backup mechanisms before behavior-based authentication fails. This prior preparation ensures that when behavior-based authentication becomes unreliable due to user behavior changes or environmental interference, the system can immediately switch to pre-configured alternative methods without compromising security or user experience.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If traditional authentication methods (PIN, password, fingerprint) are used, then reliability is improved, but ease of operation deteriorates due to complexity and user burden

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs authentication automatically by analyzing user behavior patterns without requiring explicit user actions. The device monitors and evaluates behavioral characteristics (typing patterns, swipe gestures, device handling) in the background, automatically verifying user identity without prompting the user to enter PINs, passwords, or present fingerprints, thereby eliminating user burden while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual authentication mechanisms (typing PINs, entering passwords, placing fingers on sensors) with automated behavioral analysis. Instead of requiring users to consciously perform authentication actions, the system passively captures and analyzes behavioral data from device interactions, substituting mechanical user actions with automated computational verification while preserving the security functions of traditional methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If secure passwords are used, then reliability is improved, but ease of operation deteriorates due to complexity of entering passwords

Engineering Contradiction:
Improvepassword securityVSAvoidpassword entry difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically performs password verification through behavioral analysis without requiring users to manually enter complex passwords. By analyzing typing patterns, keystroke dynamics, and other behavioral characteristics during normal device interaction, the system autonomously verifies user identity, eliminating the need for users to type or remember complex secure passwords while maintaining equivalent security levels.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces the mechanical act of typing or entering passwords with automated behavioral capture and analysis. Instead of requiring users to consciously input authentication credentials through physical keyboard interaction, the system passively records and analyzes behavioral patterns during natural device usage, substituting the manual password entry mechanism with computational behavioral verification that preserves security without the operational burden.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3487200B1Behaviour-based authentication with fall-back position
Publication Date: 2026.03.25 BUNDESDRUCKEREI GMBH
  • EP3487200B1 patent drawingFigure 1
  • EP3487200B1 patent drawingFigure 2a
  • EP3487200B1 patent drawingFigure 2b

AI summary

The invention relates to a method for authenticating a user, which comprises behavior-based authentication with the following steps: • Acquiring behavior-based data (500), • Evaluating the acquired behavior-based data (500), • Generating a first authentication signal if the evaluated behavior-based data corresponds to a characteristic behavior of a registered user, wherein, if the evaluated behavior-based data (500) of the current user does not correspond to a characteristic behavior of the registered user, the method further comprises, as a fallback, behavior-independent authentication based on at least one behavior-independent predefined authentication feature (502): • Acquiring the at least one predefined behavior-independent authentication feature (502), • Evaluating the acquired predefined authentication feature (502),• Generating a second authentication signal if the evaluated predefined authentication feature (502) corresponds to a characteristic knowledge, possession and/or biological property of the registered user, wherein the second authentication signal indicates successful authentication.