Behavioral Pattern Authentication for Seamless Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods, such as two-factor authentication, can be frustrating for users while compromising security, and there is a need for a seamless experience without additional steps.

Innovation Solution

Utilizing a user's activity pattern, including location and application usage history, as an additional authentication parameter to grant access to protected applications without requiring additional authentication steps.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-factor authentication or additional authentication steps are implemented, then security is improved, but user experience and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically monitors user activities and generates activity patterns without requiring user intervention. The authentication process is self-serve as the system autonomously compares current activities against stored patterns and makes authentication decisions, eliminating the need for users to manually complete additional authentication steps while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors user activities and provides feedback by comparing real-time activities against historical patterns. This feedback mechanism enables dynamic authentication decisions based on behavioral anomalies, improving security while maintaining a seamless user experience as users are not aware of the additional security layer being applied

Inventive Principle:
Principle #23Feedback

2Ease of operation

If traditional authentication methods (username and password) are used, then ease of operation is maintained, but security is compromised

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system merges traditional authentication (username and password) with behavioral biometric authentication by combining multiple activity parameters (location, application usage, typing patterns) into a comprehensive activity pattern. This combination maintains the simplicity of traditional login while adding a layer of security based on unique user behavior patterns that are difficult to replicate

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If activity pattern monitoring is implemented, then authentication security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses existing mobile device sensors and applications (GPS, accelerometer, microphone, keyboard, screen) for multiple purposes - both for their primary functions and for collecting authentication-relevant data. This multi-functionality approach avoids adding dedicated hardware complexity while enabling comprehensive activity pattern monitoring through software-based solutions

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11893097B2System to utilize user's activities pattern as additional authentication parameter
Publication Date: 2024.02.06 CAPITAL ONE SERVICES LLC
  • US11893097B2 patent drawing
  • US11893097B2 patent drawing
  • US11893097B2 patent drawing

AI summary

Various embodiments for a system to utilize user's location pattern as an authentication parameter are disclosed. An embodiment operates by retrieving a location history of a user based on past locations of a user equipment (UE) device at various times and traffic data associated with the location history. A request to access a protected application is received and a present location of the UE device at a time associated with the request is determined. A locational pattern is generated based on both the location history of the user and the traffic data. The present location of the UE device is compared with the locational pattern, and it is determined that a level of authentication necessary to grant access to the protected application is satisfied based on both the comparing and a determination that the present location falls within the locational range generated based on the traffic data.