Behavioral Biometric Authentication for Mobile Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures, such as passwords and passcodes, are inadequate in preventing data theft as they can be compromised within a short time frame, allowing thieves to steal and transmit data quickly, causing inconvenience to legitimate users.
Innovation Solution
Implementing software on devices to monitor usage patterns and physical characteristics, detecting suspicious or unauthorized behavior, and taking actions such as locking the device or sending alerts to prevent illicit use, thereby reducing the need for continuous user interaction and minimizing data theft.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a timeout of one minute is set for password re-entry, then legitimate users experience convenience, but data can be stolen and transmitted in that time
Solution Approach 1:
The system performs preliminary actions by continuously monitoring usage patterns and detecting suspicious behavior before data theft can occur. The behavioral biometric authentication is established in advance, allowing the system to identify and prevent unauthorized access attempts before they result in data theft, rather than relying on periodic password checks.
Solution Approach 2:
The system implements continuous feedback by monitoring device usage patterns in real-time and comparing them against established behavioral biometrics. When deviations indicating unauthorized use are detected, the system immediately responds by locking the device or alerting the user, creating a dynamic security response that adapts to current usage conditions rather than relying on fixed timeout intervals.
2Reliability
If password or passcode protection is implemented, then data security is improved, but the device must be locked frequently causing inconvenience
Solution Approach 1:
The system performs self-service by automatically analyzing usage patterns and detecting unauthorized access attempts without requiring user intervention. The behavioral biometric authentication occurs automatically in the background, continuously verifying device usage against established patterns and taking corrective action when anomalies are detected, eliminating the need for manual password entry during legitimate use.
Solution Approach 2:
The system replaces the mechanical password entry system with a behavioral biometric authentication system. Instead of requiring users to manually enter passwords at fixed intervals, the system uses sensors to automatically capture and analyze behavioral patterns such as typing rhythm, swipe gestures, and device handling characteristics, providing continuous authentication without interrupting legitimate users.
3Reliability
If continuous monitoring of usage patterns is implemented, then detection of unauthorized use is improved, but device complexity increases
Solution Approach 1:
The system achieves multi-functionality by using existing device sensors and components for dual purposes: their original functions plus behavioral biometric authentication. The same accelerometer, gyroscope, touchscreen, and keyboard sensors used for normal device operation are also utilized to capture behavioral patterns, eliminating the need for separate dedicated hardware and reducing overall system complexity.
Solution Approach 2:
The system changes parameters by analyzing temporal and spatial characteristics of user interactions rather than requiring additional hardware complexity. By measuring variables such as typing speed, pressure applied to the touchscreen, angle and velocity of swipes, and timing between gestures, the system extracts behavioral biometric data from existing sensor outputs, achieving sophisticated authentication without increasing device complexity.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Illicit use of devices, and misappropriation of the data on those devices, may be prevented by detecting patterns of behavior that suggest illicit use, and by taking action when such illicit use is detected. A device may store information that describes suspicious patterns of use, and may also store information that describes normal patterns of use of known legitimate users. If current use of the device matches a suspicious pattern of use, and if the user of the device cannot be confirmed to be a known legitimate user, then action may be taken, such as locking the device's user interface, shutting down the device's communication facilities, issuing a warning message, sending a communication, or any other action.