Behavioral Authentication System for Multi-User Account Differentiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing behavioral authentication systems are inadequate for handling multiple users sharing the same account, as they cannot differentiate between individuals based on their unique behaviors, leading to security clearance issues in shared account settings such as family or company accounts.

Innovation Solution

A method and system that gather and store behavioral data from multiple users, creating a combined behavioral profile to authenticate access, with a temporary profile for new users and an update mechanism to flag multi-user profiles based on legitimacy confirmation from primary users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single behavioral profile is created for shared accounts, then authentication is simplified, but the system cannot differentiate between multiple users with different behaviors

Engineering Contradiction:
Improveauthentication simplicityVSAvoiduser differentiation accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments the behavioral profile into multiple user-specific profiles within a single shared account. Each user has their own behavioral characteristics stored separately, allowing the system to differentiate between users while maintaining the shared account structure. This is achieved by creating distinct behavioral profiles for each user (e.g., User A and User B) under the same account, enabling accurate user identification without compromising authentication simplicity.

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If behavioral data from multiple users is combined into one profile, then the profile becomes more comprehensive, but the behavioral patterns become indistinguishable

Engineering Contradiction:
Improvebehavioral data volumeVSAvoidbehavioral pattern distinction
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent prevents mixing of behavioral data by maintaining separate, user-specific behavioral profiles. Each user's behavioral characteristics (keystroke patterns, mouse movements, typing speed, etc.) are stored independently without being combined with other users' data. This segmentation ensures that behavioral patterns remain distinct and distinguishable while still allowing comprehensive data collection for each individual user.

Inventive Principle:
Principle #1Segmentation

3Reliability

If traditional authentication methods (PIN, smart card) are used, then security is strengthened, but user experience becomes more cumbersome

Engineering Contradiction:
Improvesecurity strengthVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication by automatically collecting behavioral data from users during normal interaction with the system. The behavioral biometrics are gathered passively through monitoring of typing patterns, mouse movements, and other natural interactions, eliminating the need for users to manually input authentication credentials. This provides secure authentication comparable to traditional methods while maintaining seamless user convenience.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10068076B1Behavioral authentication system using a behavior server for authentication of multiple users based on their behavior
Publication Date: 2018.09.04 BEHAVIOMETRICS
  • US10068076B1 patent drawing
  • US10068076B1 patent drawing
  • US10068076B1 patent drawing

AI summary

A method and a corresponding device for authenticating a user for access to protected information, the method comprising generating a behavioral user profile associated with a first user known to be a legitimate user of the protected information, obtaining from a second user, using a behavioral input device associated with a second computing device, a behavioral user sample, storing the behavioral user sample, associated with the second user, in a temporary user profile, comparing the behavioral user sample of the second user to the behavioral user profile, and if the behavioral user sample does not match the behavioral user profile contacting the legitimate first user and receiving from the legitimate first user information regarding the legitimacy of the second user and based on the information received from the first user, providing a response to the second user and updating the user profile.