Behavioral Authentication Using Route Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current two-factor authentication methods, particularly those using mobile devices, are vulnerable to interception and delays due to reliance on cellular networks and insecure SMS-based passcodes, and can be compromised if the mobile device is stolen or out of range.

Innovation Solution

Behavioral authentication systems that use a mobile device to record and match a user's daily route to generate an access-enabling token, allowing secure access without external communication or insecure message transmission, ensuring access even when the device is out of range.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile device two-factor authentication using SMS or dynamic passcodes is used, then authentication convenience is improved (no need to carry additional factors), but security is worsened (vulnerable to interception, wiretapping, and theft)

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the authentication mechanism from dependency on cellular networks and SMS infrastructure. By using local geographic fingerprinting and device sensors to generate authentication tokens, the system removes the vulnerable communication channel while maintaining convenience. The authentication proof is generated locally on the device without requiring network communication during the authentication moment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary actions by continuously collecting and analyzing geographic location data, movement patterns, and device sensor information in advance. This creates a baseline of legitimate user behavior that enables authentication without requiring real-time network communication. The authentication token is generated based on pre-established patterns rather than reactive SMS delivery.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If mobile device authentication requires cellular network coverage, then passcode delivery is ensured, but access may be impossible when out of range

Engineering Contradiction:
Improvepasscode delivery reliabilityVSAvoidaccess availability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The mobile device performs self-service authentication by generating its own authentication proof using local sensors, geographic location data, and pre-stored routing information. The device does not need to request or receive authentication codes from external servers during the authentication moment, enabling operation in areas without cellular coverage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transitions from network-dependent authentication to spatial-temporal pattern recognition. By utilizing geographic coordinates, movement trajectories, and timing information as authentication dimensions, the system creates a new authentication paradigm that operates independently of cellular network availability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If SMS-based passcodes are used for authentication, then authentication can be delivered to mobile devices, but authentication delays occur due to message delivery time

Engineering Contradiction:
Improveauthentication deliveryVSAvoidauthentication delay
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by continuously monitoring and analyzing user behavior patterns, geographic routes, and device characteristics in advance. When authentication is needed, the system can immediately verify the device's current state against pre-established patterns, eliminating the delay of requesting and delivering passcodes in real-time.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If mobile phones combine both authentication factors (something known and something possessed), then authentication is simplified to one factor, but security is worsened (stolen phones can access accounts)

Engineering Contradiction:
Improveauthentication simplificationVSAvoidsecurity against theft
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication proof into multiple independent components: geographic location data, movement pattern analysis, device sensor readings, and temporal information. Even if a thief obtains the physical device, they cannot replicate the legitimate user's unique combination of these segmented authentication factors, particularly the dynamic geographic and behavioral patterns.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10237733B2Behavioral authentication
Publication Date: 2019.03.19 SALESFORCE INC
  • US10237733B2 patent drawing
  • US10237733B2 patent drawing
  • US10237733B2 patent drawing

AI summary

Behavioral authentication is described. A mobile device records a first location of the mobile device. The mobile device records a second location of the mobile device. The mobile device determines whether a route from the first location to the second location matches an expected route. The mobile device generates an access-enabling token in response to a determination that the route from the first location to the second location matches the expected route. The mobile device enables access to an entity by a user of the mobile device based on the mobile device providing the access-enabling token to the entity.