Multi-factor Authentication Using Behavioral Metrics and Motion Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current user authentication methods, particularly for financial accounts, are insecure due to vulnerabilities in four-digit PIN codes and two-factor systems, which can be hacked or intercepted, leading to potential brute force attacks and 'man in the middle' scenarios.
Innovation Solution
Implementing a multi-factor authentication system that recognizes behavioral metrics, such as movement, position, and performance factors, in addition to traditional PIN or biometric methods, to create a hidden and dynamic authentication process that combines various user interactions, including tapping, swiping, and image recognition, to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional four-digit PIN codes are used for authentication, then the authentication process is simple and easy to operate, but the security level is low and vulnerable to brute force attacks
Solution Approach 1:
The authentication process is segmented into multiple independent factors: something you know (PIN), something you have (device), and something you are/do (behavioral metrics). Each factor operates independently but contributes to the overall authentication decision, making the system more secure while maintaining usability through modular design
Solution Approach 2:
The patent transitions from one-dimensional authentication (single PIN code) to multi-dimensional authentication by adding behavioral metrics such as typing rhythm, swipe patterns, and device handling characteristics. These new dimensions create a much larger authentication space that is resistant to traditional attack methods
2Reliability
If two-factor authentication systems are implemented, then security is improved compared to single-factor PIN, but the system becomes more complex and vulnerable to interception attacks
Solution Approach 1:
The patent merges multiple authentication factors (PIN, device possession, behavioral metrics) into a unified authentication framework. The behavioral metrics are extracted and processed alongside traditional factors, creating a consolidated authentication decision that simplifies the overall system architecture while enhancing security
Solution Approach 2:
The system introduces behavioral metrics as an intermediary factor that bridges the gap between traditional authentication methods and modern security requirements. This intermediary layer provides additional verification without requiring complete redesign of existing authentication infrastructure
3Reliability
If user-specific information is used to generate dynamic PIN codes, then authentication security is enhanced, but the system becomes vulnerable to man-in-the-middle attacks and information interception
Solution Approach 1:
The system performs preliminary verification of behavioral metrics before final authentication decisions are made. By analyzing user behavior patterns in advance and establishing baseline characteristics, the system can detect anomalies and prevent interception attacks before they compromise security
Solution Approach 2:
The authentication system dynamically adjusts its requirements based on real-time behavioral analysis. Rather than using static user-specific information that can be intercepted, the system continuously monitors and adapts to changing behavior patterns, making interception ineffective against dynamic authentication states
4Reliability
If behavioral metrics and motion detection are added to authentication, then security against hacking is significantly improved, but the device complexity and processing requirements increase
Solution Approach 1:
The system uses the device's existing sensors and processing capabilities to collect and analyze behavioral metrics without requiring additional specialized hardware. The device serves itself by leveraging its own motion detectors, touch screens, and processors to generate authentication data, minimizing added complexity while maximizing security
Data Source
AI summary
Systems and methods to authenticate a user using. Techniques for authenticating a user focus less on what the user enters, and more on how the user enters it. Different user specific factors are recognized, such as the speed with which a pattern, drawing or the like is produced, pressure applied, or the area of contact. In some embodiments, the user is able to produce the PIN using several different techniques. Some methods of the present invention utilize actions that the user is familiar with executing, or naturally performs on a regular basis. Furthermore, some methods of the present invention consist of embodiments wherein mathematical operations or device motions are used during the PIN authentication process.


