Behavior-Based Authentication Using User Activity History

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods are inconvenient and insecure, often requiring users to remember lengthy passwords or use physical devices, leading to potential security breaches and user avoidance of logging out of services.

Innovation Solution

Behavior-based authentication system that collects, classifies, and stores user event data from applications to generate authentication questions and answers based on user activity, allowing for secure and convenient access by verifying user behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based authentication is used, then security is provided, but user convenience deteriorates due to lengthy passwords and frequent authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically collects user behavior data from applications and generates authentication questions based on this data without requiring user intervention. The user's daily activities within applications serve as the authentication mechanism, eliminating the need for separate authentication actions while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-collects and stores user behavior data from application usage during normal operations. This preliminary data collection enables rapid generation of authentication questions when needed, eliminating the need for users to manually recall detailed password information during authentication events.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If physical authentication devices are used, then security is improved, but user convenience deteriorates due to the need to retrieve and use the device every time

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system replaces physical authentication devices with a software-based authentication mechanism that leverages digital footprints from application usage. Instead of requiring physical device retrieval and interaction, the system uses automated analysis of user behavior data to generate and verify authentication questions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If passwords are used across multiple services, then ease of operation is improved, but security deteriorates due to potential compromise of multiple services

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication mechanism is customized for each service based on its specific application usage patterns. Each service generates authentication questions from its own local behavior data, creating service-specific authentication credentials that are unique to each application context, thereby preventing cross-service security compromise.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If detailed user behavior data is collected, then authentication accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements a universal data collection framework that captures user behavior across multiple applications through a common interface. This multi-functional approach allows the same infrastructure to serve various applications, reducing overall system complexity while maintaining high authentication accuracy through comprehensive behavior data.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11811780B2Behavior-based authentication
Publication Date: 2023.11.07 CITRIX SYSTEMS INC
  • US11811780B2 patent drawing
  • US11811780B2 patent drawing
  • US11811780B2 patent drawing

AI summary

Methods and systems for authenticating users based on user application activities are described herein. One or more questions and one or more answers may be generated and stored based on a history of user application activities associated with a user. The one or more questions and one or more answers may be generated randomly, and may relate to one or more other users. A request for access to a service may be received. Based on the request, a question associated with the history of user application activity may be selected and presented to the user. A candidate answer may be received from the user, and the user may be authenticated based on comparing the candidate answer to an answer associated with the question presented.