Behavioral Profile Authentication for Security-Efficiency Trade-offs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information security systems face challenges in preventing unauthorized access while optimizing technical operations, as they struggle to efficiently and effectively utilize machine-learned user behavior profiles for authentication requests.

Innovation Solution

A computing platform captures behavioral parameters from client devices, evaluates them against user behavior profiles to determine deviation scores, and selects authentication actions to allow or deny access to secured resources, using a machine-learning algorithm to generate and refine profiles based on interaction data across various channels and devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used to ensure security, then unauthorized access is prevented, but operational efficiency and user convenience deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The authentication system dynamically adjusts the strictness of authentication requirements based on real-time behavioral analysis. When user behavior deviates from established patterns, the system automatically increases security measures; when behavior is normal, it streamlines authentication processes, thus adapting security levels to actual risk rather than applying fixed rules

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters (such as required verification steps, monitoring intensity, and access restrictions) based on behavioral deviation scores. The machine learning model continuously updates behavioral parameters and thresholds, allowing the system to optimize the balance between security and efficiency as it learns more about legitimate user patterns

Inventive Principle:
Principle #35Parameter changes

2Reliability

If strict authentication controls are implemented to prevent unauthorized access, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-learning and self-adjustment through machine learning algorithms that automatically analyze user behavior patterns and update authentication parameters without requiring manual configuration. The behavioral profiles are automatically created and refined based on observed interactions, reducing the need for complex manual security policy management

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where authentication decisions and user responses are fed back into the machine learning model to refine behavioral profiles. This automatic feedback mechanism allows the system to learn from outcomes and improve its authentication strategies without increasing operational complexity

Inventive Principle:
Principle #23Feedback

3Measurement precision

If behavioral parameters are captured and analyzed for each authentication request, then authentication accuracy is improved, but processing time increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary behavioral analysis by continuously capturing and storing behavioral parameters during normal user interactions, even during off-peak times. Behavioral profiles are pre-built and updated in the background, so when authentication is needed, the system can quickly compare current behavior against pre-analyzed patterns rather than performing full analysis in real-time

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11790062B2Processing authentication requests to secured information systems based on machine-learned user behavior profiles
Publication Date: 2023.10.17 BANK OF AMERICA CORP
  • US11790062B2 patent drawing
  • US11790062B2 patent drawing
  • US11790062B2 patent drawing

AI summary

Aspects of the disclosure relate to processing authentication requests to secured information systems based on machine-learned user behavior profiles. A computing platform may receive an authentication request corresponding to a request for a user of a client computing device to access one or more secured information resources associated with a user account. The computing platform may capture behavioral parameters associated with the client computing device and may evaluate the behavioral parameters using a behavioral profile associated with the user account to determine a behavioral deviation score. Based on the behavioral deviation score, the computing platform may select an authentication action from a plurality of pre-defined authentication actions. Subsequently, the computing platform may generate commands directing an account portal computing platform to allow access, conditionally allow access, or prevent access based on the selected authentication action. Then, the computing platform may send the commands to the account portal computing platform.