Behavioral Biometric Authentication for Password Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional password reset processes are cumbersome, often requiring users to remember security questions or engage in time-consuming verification processes, and may fail due to issues with biometric authentication factors like face recognition or fingerprint scanning.

Innovation Solution

A system that monitors user interactions to extract unique features for authentication, allowing password recovery or reset without relying on secret data or security questions, by presenting users with specific tasks or challenges to recreate their behavior patterns, which can be used for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional password reset processes use security questions or biometric authentication, then user verification can be performed, but the process becomes cumbersome and time-consuming

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidpassword reset time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously monitoring and storing user interaction patterns during normal usage. Behavioral biometric data is collected and archived in advance, so when password recovery is needed, the verification can be performed quickly by comparing against pre-stored patterns rather than requiring time-consuming security questions or biometric scans at the moment of recovery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service password recovery by using the user's own behavioral patterns as the authentication mechanism. Instead of requiring assistance from support staff or complex verification processes, the user's natural interaction patterns with the device serve as the verification method, making the process autonomous and efficient.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If biometric authentication factors like face recognition or fingerprint scanning are used, then password recovery can be enabled, but the process may fail due to biometric authentication issues

Engineering Contradiction:
Improvepassword recovery easeVSAvoidauthentication reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Instead of relying on physical biometric traits that may fail (face recognition, fingerprint scanning), the system creates behavioral copies or patterns of how users interact with their devices. These behavioral biometric patterns serve as a reliable alternative that is not subject to the same failure modes as physical biometric authentication, while still providing ease of operation through automatic verification.

Inventive Principle:
Principle #26Copying

3Reliability

If security questions are used for password reset, then user verification can be performed, but users must remember secret data which increases complexity

Engineering Contradiction:
Improveverification reliabilityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system replaces the mechanical/cognitive system of remembering security questions with an automatic behavioral analysis system. Instead of requiring users to memorize and recall secret information, the system automatically captures and analyzes behavioral patterns during device interaction, eliminating the need for users to remember additional data while maintaining verification reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10164985B2Device, system, and method of recovery and resetting of user authentication factor
Publication Date: 2018.12.25 BIOCATCH
  • US10164985B2 patent drawing
  • US10164985B2 patent drawing

AI summary

Devices, systems, and methods of password recovery and password reset, as well as resetting or recovering other types of user-authentication factor. A system monitors and tracks user-interactions that are performed by a user of an electronic device or a computerized service. The system defines a user-specific task or challenge, in which the user is requested to enter a phrase or perform a task. A user-specific feature is extracted from the manner in which the user performs the task. Subsequently, that user-specific feature is utilized instead of a security question, in order to verify the identity of the user and to allow the user to perform password reset or to perform a reset of another user-authentication factor; by presenting to the user the same task or a similar task, and monitoring the manner in which the user performs the fresh task.