Behavioral Authentication Using Route Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current two-factor authentication methods, particularly those using mobile devices, are vulnerable to interception and delays due to reliance on cellular networks and insecure SMS-based passcodes, and can be compromised if the mobile device is stolen or out of range.
Innovation Solution
Behavioral authentication systems that use a mobile device to record and match a user's daily route to generate an access-enabling token, allowing secure access without external communication or insecure message transmission, ensuring access even when the device is out of range.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If mobile device two-factor authentication using SMS or dynamic passcodes is used, then authentication convenience is improved (no need to carry additional factors), but security is worsened (vulnerable to interception, wiretapping, and theft)
Solution Approach 1:
The patent extracts the authentication mechanism from dependency on cellular networks and SMS infrastructure. By using local geographic fingerprinting and device sensors to generate authentication tokens, the system removes the vulnerable communication channel while maintaining convenience. The authentication proof is generated locally on the device without requiring network communication during the authentication moment.
Solution Approach 2:
The system performs preliminary actions by continuously collecting and analyzing geographic location data, movement patterns, and device sensor information in advance. This creates a baseline of legitimate user behavior that enables authentication without requiring real-time network communication. The authentication token is generated based on pre-established patterns rather than reactive SMS delivery.
2Reliability
If mobile device authentication requires cellular network coverage, then passcode delivery is ensured, but access may be impossible when out of range
Solution Approach 1:
The mobile device performs self-service authentication by generating its own authentication proof using local sensors, geographic location data, and pre-stored routing information. The device does not need to request or receive authentication codes from external servers during the authentication moment, enabling operation in areas without cellular coverage.
Solution Approach 2:
The patent transitions from network-dependent authentication to spatial-temporal pattern recognition. By utilizing geographic coordinates, movement trajectories, and timing information as authentication dimensions, the system creates a new authentication paradigm that operates independently of cellular network availability.
3Ease of operation
If SMS-based passcodes are used for authentication, then authentication can be delivered to mobile devices, but authentication delays occur due to message delivery time
Solution Approach 1:
The system performs preliminary authentication by continuously monitoring and analyzing user behavior patterns, geographic routes, and device characteristics in advance. When authentication is needed, the system can immediately verify the device's current state against pre-established patterns, eliminating the delay of requesting and delivering passcodes in real-time.
4Ease of operation
If mobile phones combine both authentication factors (something known and something possessed), then authentication is simplified to one factor, but security is worsened (stolen phones can access accounts)
Solution Approach 1:
The patent segments the authentication proof into multiple independent components: geographic location data, movement pattern analysis, device sensor readings, and temporal information. Even if a thief obtains the physical device, they cannot replicate the legitimate user's unique combination of these segmented authentication factors, particularly the dynamic geographic and behavioral patterns.
Data Source
AI summary
Behavioral authentication is described. A mobile device records a first location of the mobile device. The mobile device records a second location of the mobile device. The mobile device determines whether a route from the first location to the second location matches an expected route. The mobile device generates an access-enabling token in response to a determination that the route from the first location to the second location matches the expected route. The mobile device enables access to an entity by a user of the mobile device based on the mobile device providing the access-enabling token to the entity.


