Behavioral Authentication for Mobile Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile computing devices lack an effective mechanism to prevent unauthorized access to sensitive data once an unauthorized user has gained access, as they appear as authorized users after accessing the data.

Innovation Solution

A system that collects and generates usage patterns from authentic users, monitors device usage, and encrypts data if usage exceeds predetermined thresholds, preventing further access by unauthorized users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password protection is implemented to prevent unauthorized access, then security against unauthorized users is improved, but authorized users cannot access their own data when the device is lost or stolen

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to data
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by collecting usage pattern data during normal device operation and establishing baseline behavioral profiles before unauthorized access occurs. This pre-collected data enables the system to automatically distinguish between authorized and unauthorized users without requiring manual password intervention, thus resolving the contradiction between security and ease of access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by automatically monitoring and analyzing usage patterns to authenticate users without requiring manual password entry. The device autonomously determines whether the current user is authorized based on behavioral analysis, eliminating the need for users to manually input passwords while maintaining security, thereby improving both security reliability and ease of operation.

Inventive Principle:
Principle #25Self-service

2Reliability

If remote data removal is implemented to prevent unauthorized access, then security is improved, but authorized users lose access to their own data when the device is lost

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary actions by continuously collecting and analyzing usage pattern data before unauthorized access occurs. This pre-established behavioral baseline enables the system to automatically authenticate users and prevent unauthorized access without requiring remote data removal, thus avoiding information loss while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring usage patterns and automatically adjusting access permissions based on real-time behavioral analysis. When unauthorized usage is detected, the system provides feedback by automatically locking data access without requiring remote intervention, thereby maintaining security while preventing information loss through premature data removal.

Inventive Principle:
Principle #23Feedback

3Reliability

If behavioral monitoring is implemented to distinguish authorized users, then security against unauthorized access is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically performing behavioral analysis and authentication without requiring complex external verification systems. The device autonomously monitors usage patterns, compares them against established baselines, and makes authentication decisions internally, thereby improving security while minimizing the need for additional complex external components.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system applies parameter changes by analyzing variations in usage behavior patterns rather than relying on fixed authentication credentials. By monitoring changes in temporal, spatial, and interaction parameters of device usage, the system achieves enhanced security through behavioral differentiation without requiring complex hardware modifications, thus improving security while managing device complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3080743B1User authentication for mobile devices using behavioral analysis
Publication Date: 2020.12.02 MCAFEE LLC
  • EP3080743B1 patent drawingFigure 1
  • EP3080743B1 patent drawingFigure 2
  • EP3080743B1 patent drawingFigure 3

AI summary

Usage patterns of an authentic user of a mobile device are generated from data collected representing usage by the authentic user. These usage patterns may then be compared to monitored usage of the mobile device. If usage of the mobile device exceeds a threshold based on one or more of the usage patterns, access to data on the mobile device can be prevented.