Behavioral Authentication Binding Mobile Devices via Secure Element

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device security mechanisms, such as PINs and biometric methods, lack the ability to effectively bind user behavior to a specific device, making them insecure and vulnerable to unauthorized access, as they do not incorporate 'something you are' authentication and do not restrict users to approved devices.

Innovation Solution

A system that monitors and gathers behavioral data from mobile device interactions, including keystroke patterns, device orientation, and application usage, and compares this data to stored profiles on a behaviometric server to authenticate users, ensuring secure access by binding authentication to specific devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional PIN or biometric methods are used for authentication, then user authentication is enabled, but the system cannot bind authentication to a specific device or restrict users to approved devices

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice binding capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication system is segmented into multiple independent components: device-specific identifiers stored in the mobile device, behaviometric templates stored on the server, and behavioral data collection from multiple sensors. This segmentation allows the system to bind authentication to both the user and the specific device simultaneously, resolving the contradiction between authentication reliability and device binding capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a new dimension to authentication by incorporating device-specific identifiers and location data alongside traditional biometric verification. This multi-dimensional approach enables the system to authenticate both who the user is and which device they are using, thereby achieving both high authentication security and device binding capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If behavioral data is collected and stored on the mobile device, then authentication accuracy is improved, but security vulnerabilities increase due to lack of binding to specific devices

Engineering Contradiction:
Improvebehavioral authentication accuracyVSAvoidsecurity binding
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The server acts as an intermediary that stores the behaviometric templates and device-specific identifiers, while the mobile device stores only the device identifier and sends behavioral data for verification. This intermediary architecture enables accurate behavioral authentication while maintaining security binding, as the sensitive behavioral data is not stored locally on the mobile device but rather verified against server-stored templates associated with specific devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple authentication factors are combined, then security is enhanced, but system complexity increases

Engineering Contradiction:
Improvesecurity clearanceVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses a universal behaviometric authentication mechanism that can work across different devices and platforms. The same behavioral data collection and verification process applies regardless of the specific mobile device type, simplifying the overall system architecture while still providing multi-factor authentication through the combination of device identifier verification and behavioral pattern recognition.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9301140B1Behavioral authentication system using a secure element, a behaviometric server and cryptographic servers to authenticate users
Publication Date: 2016.03.29 BEHAVIOSEC
  • US9301140B1 patent drawing
  • US9301140B1 patent drawing
  • US9301140B1 patent drawing

AI summary

Embodiments of the disclosed technology are directed to methods and/or systems for using behavioral authentication for authenticating particular users of particular mobile devices. The methods and/or systems may employ a behavior monitor, a secure element, a behaviometric server and/or cryptographic servers to authenticate users. The behavior monitor may gather, interpret, decrypt and/or encrypt behavior information using a secure element and a behaviometric server. The behaviometric server may be used to compare recorded behavior data and compare them to stored profiles of users in order to generate authentication information based on the comparison.