Behavior-Based Authentication Using User Activity History
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods are inconvenient and insecure, often requiring users to remember lengthy passwords or use physical devices, leading to potential security breaches and user avoidance of logging out of services.
Innovation Solution
Behavior-based authentication system that collects, classifies, and stores user event data from applications to generate authentication questions and answers based on user activity, allowing for secure and convenient access by verifying user behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional password-based authentication is used, then security is provided, but user convenience deteriorates due to lengthy passwords and frequent authentication requirements
Solution Approach 1:
The system automatically collects user behavior data from applications and generates authentication questions based on this data without requiring user intervention. The user's daily activities within applications serve as the authentication mechanism, eliminating the need for separate authentication actions while maintaining security.
Solution Approach 2:
The system pre-collects and stores user behavior data from application usage during normal operations. This preliminary data collection enables rapid generation of authentication questions when needed, eliminating the need for users to manually recall detailed password information during authentication events.
2Reliability
If physical authentication devices are used, then security is improved, but user convenience deteriorates due to the need to retrieve and use the device every time
Solution Approach 1:
The system replaces physical authentication devices with a software-based authentication mechanism that leverages digital footprints from application usage. Instead of requiring physical device retrieval and interaction, the system uses automated analysis of user behavior data to generate and verify authentication questions.
3Ease of operation
If passwords are used across multiple services, then ease of operation is improved, but security deteriorates due to potential compromise of multiple services
Solution Approach 1:
The authentication mechanism is customized for each service based on its specific application usage patterns. Each service generates authentication questions from its own local behavior data, creating service-specific authentication credentials that are unique to each application context, thereby preventing cross-service security compromise.
4Measurement precision
If detailed user behavior data is collected, then authentication accuracy is improved, but system complexity increases
Solution Approach 1:
The system implements a universal data collection framework that captures user behavior across multiple applications through a common interface. This multi-functional approach allows the same infrastructure to serve various applications, reducing overall system complexity while maintaining high authentication accuracy through comprehensive behavior data.
Data Source
AI summary
Methods and systems for authenticating users based on user application activities are described herein. One or more questions and one or more answers may be generated and stored based on a history of user application activities associated with a user. The one or more questions and one or more answers may be generated randomly, and may relate to one or more other users. A request for access to a service may be received. Based on the request, a question associated with the history of user application activity may be selected and presented to the user. A candidate answer may be received from the user, and the user may be authenticated based on comparing the candidate answer to an answer associated with the question presented.


