Behavioral Authentication via Sensor Data Fusion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods, such as PINs and passwords, are vulnerable to unauthorized access due to forgetfulness, guessability, and ease of espionage, while fingerprint sensors face issues with recognition in various conditions, leading to inadequate security in accessing mobile and communication systems.

Innovation Solution

A behavior-based authentication system that uses intrinsic user behavior patterns, collected by sensors in mobile and wearable devices, to authenticate users without the need for PINs or passwords, leveraging gross motor movements, application usage, and biometric data to create a unique authentication profile.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If PIN or password authentication is used, then ease of operation is improved, but security is worsened due to forgetfulness, guessability, and espionage vulnerability

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces traditional mechanical authentication systems (PIN pads, keyboard entry) with a behavioral biometric system that uses sensors to detect and analyze user interactions with the mobile device. The system captures data from accelerometers, gyroscopes, and touchscreens to create a behavioral profile, substituting the manual entry mechanism with automated behavioral analysis that occurs in the background during normal device usage.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication system operates autonomously by continuously collecting behavioral data during normal device usage and automatically comparing it against stored profiles. The system self-updates its behavioral models and performs real-time authentication without requiring active user participation or conscious effort, making the security verification transparent and seamless.

Inventive Principle:
Principle #25Self-service

2Reliability

If fingerprint sensor is used, then security is improved, but ease of operation is worsened due to recognition failures in various conditions

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication reliability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent employs multiple sensors including accelerometers, gyroscopes, magnetometers, and touchscreen controllers to perform authentication. This multi-functional approach allows the system to collect behavioral data from various device interactions, making the authentication system universally applicable regardless of environmental conditions that might affect fingerprint recognition.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the authentication parameters from static physical characteristics (fingerprint patterns) to dynamic behavioral parameters (movement patterns, touch pressure, swipe velocity, device orientation changes). These behavioral parameters can be captured under various conditions and are less susceptible to environmental factors like moisture, dirt, or wear.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If traditional authentication methods are used, then device complexity is reduced, but security is worsened due to vulnerability to unauthorized access

Engineering Contradiction:
Improveauthentication system complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the authentication system into distinct functional modules: data collection from multiple sensors, behavioral profile creation and storage, real-time behavioral analysis, and authentication decision-making. This segmentation allows each component to be optimized independently and facilitates implementation on mobile devices with existing sensor infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by continuously collecting and storing behavioral data during normal device usage before authentication is needed. Behavioral profiles are created and updated in advance, allowing rapid authentication when required without adding significant processing burden at the moment of access request.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3404570B1Method and system for behavioral authentication
Publication Date: 2021.08.04 BUNDESDRUCKEREI GMBH
  • EP3404570B1 patent drawingFigure 1
  • EP3404570B1 patent drawingFigure 2
  • EP3404570B1 patent drawingFigure 3a~3b

AI summary

Method for authenticating a current user (1) of a first communication system (100) to a second communication system (156) by means of behavior-based authentication, which is carried out using the first communication system (100) and the second communication system (156). The first communication system (100) is a mobile, portable communication system, wherein the first communication system (100) comprises a first sensor (110) configured to collect data (500), wherein the data (500) comprises behavior-based data of the user (1). The second communication system (156) comprises a second sensor (110) configured to collect data (500) of the user (1).The procedure comprises: - Receiving a first intermediate result of the behavior-based authentication from the first communication system (100) by the second communication system (156), - Generating a classification result (600) by the second communication system (156) from the first intermediate result and a second intermediate result, - Evaluating the classification result (600) according to a predefined test criterion (800) by the second communication system (156), - Controlling the device (152) by means of a control signal by the second communication system (156) depending on whether the classification result (600) meets the test criterion, wherein the user (1) is authenticated if the classification result (600) meets the test criterion.