Behavioral User Identification for Adaptive Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication and authorization systems in computer systems are vulnerable to compromise, unable to verify the identity of actors, and fail to detect malicious behavior.
Innovation Solution
Implement a system that analyzes command patterns, biometric inputs, log files, and touch interactions to dynamically enforce access control policies using a cloud machine learning engine and local rational agents, combining machine learning models to enhance user identification and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication and authorization systems are used, then the system is simple to operate, but the system is vulnerable to compromise and cannot verify actor identity
Solution Approach 1:
The patent combines multiple authentication factors (biometric data, behavioral patterns, device characteristics) into a unified authentication system. The rational agent integrates these diverse data sources to create a composite identity verification mechanism that is more reliable than traditional single-factor authentication while managing complexity through centralized processing.
Solution Approach 2:
The rational agent serves as an intermediary component between the user and the computer system. It continuously monitors and analyzes user interactions, collecting data from multiple sources and making authentication decisions based on synthesized information, thereby enhancing reliability without requiring direct complex interactions between all system components.
2Measurement precision
If multi-factor authentication is implemented, then identity verification improves, but the authentication process becomes more complex and time-consuming
Solution Approach 1:
The system collects and analyzes user behavioral data continuously during normal interactions, building profiles of typical user patterns before authentication events occur. This preliminary data collection enables faster authentication decisions when needed, as the system already has baseline information to compare against during the actual authentication process.
Solution Approach 2:
The rational agent continuously monitors user interactions and maintains updated profiles of user behavior patterns throughout the system's operation. This continuous data collection and analysis ensures that authentication decisions are based on current, relevant information, improving accuracy without requiring periodic re-authentication that would waste time.
3Reliability
If comprehensive monitoring of user interactions is implemented, then detection of malicious behavior improves, but the system complexity and computational requirements increase
Solution Approach 1:
The rational agent extracts and analyzes specific relevant features from raw user interaction data, such as command patterns, timing characteristics, and sequence of actions. By focusing on key discriminative features rather than processing all raw data equally, the system achieves effective malicious behavior detection while managing computational complexity through selective analysis.
Solution Approach 2:
The system implements feedback loops where authentication decisions and detected anomalies are used to refine the rational agent's analysis capabilities. The system learns from past authentication outcomes and adjusts its monitoring focus, improving detection accuracy over time while adapting to reduce unnecessary computational overhead based on observed patterns.
Data Source
AI summary
A system receives a request to identify a user. The system receives user data from a computing device containing usage data or computing device metadata. The usage data is indicative of a user's pattern of usage of an input device. The pattern of usage is based on a combination of one or more input device usage amount, usage frequency, or usage type. The computing device metadata includes a time of day information, active applications, a user security profile, log file entries, or system information. The system generates, using a machine learning engine, a user profile based on the user data that is unique to the user. The system analyzes the user profile, and determines, using the machine learning engine, an identity of the user. The system determines a security policy based on the identity of the user and executes a security procedure based on the security policy.


