Biometric Authentication Platform for Bot Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing CAPTCHAs are vulnerable to being solved by computer models, failing to effectively distinguish human input from machine input, which compromises website security against malicious bot attacks.
Innovation Solution
A human authentication platform that instructs users to perform biometric parameter-stimulating tasks, such as exercising, to validate their humanity, by measuring changes in parameters like heart rate or skin temperature, ensuring only humans can access the server device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional CAPTCHA tests are used to distinguish humans from bots, then website security is maintained, but the tests become vulnerable to being solved by computer models
Solution Approach 1:
The patent changes the authentication parameter from static knowledge-based responses (traditional CAPTCHA) to dynamic biometric measurements (heart rate, skin temperature, galvanic skin response) that reflect physiological states. These biometric parameters are collected before, during, and after task performance to create a temporal pattern that is difficult for AI to replicate.
Solution Approach 2:
The system introduces dynamic elements by measuring biometric parameters across multiple time points (baseline, during task, after task) to capture physiological responses that change over time. This temporal dynamics creates authentication data that reflects genuine human physiological reactions rather than static responses.
2Reliability
If biometric measurements are taken at multiple time points to validate human authentication, then authentication reliability improves, but system complexity increases
Solution Approach 1:
The patent employs a multi-functional system where a single computing device performs multiple roles: presenting CAPTCHA challenges, collecting biometric data through various sensors (camera, microphone, keyboard), processing the data, and making authentication decisions. This consolidates complexity into a universal platform rather than requiring separate specialized devices.
Solution Approach 2:
The system uses the user's own device and existing hardware (camera, microphone, keyboard) to collect biometric data, eliminating the need for external specialized measurement equipment. The user's device serves itself by leveraging its built-in capabilities for authentication purposes.
3Reliability
If physical tasks are required to stimulate biometric parameter changes, then bot detection effectiveness improves, but user convenience decreases
Solution Approach 1:
The system requires only partial physical action - simple interactions like clicking, typing, or scrolling - rather than demanding excessive physical effort. These minimal actions are sufficient to stimulate detectable biometric changes (heart rate, skin temperature, galvanic skin response) while maintaining ease of operation.
Solution Approach 2:
The system provides real-time feedback by monitoring biometric parameter changes during task performance. This feedback loop allows the system to validate that genuine human physiological responses are occurring, enhancing bot detection while keeping the user experience intuitive through familiar interaction patterns.
Data Source
AI summary
A device transmits an instruction for completing a human authentication challenge, to access a server device. The instruction includes information indicating a biometric parameter to be provided by a user, and information indicating a task, to be performed by the user, for varying the biometric parameter. The device receives a request to validate performance of the task. The device obtains a first measurement of the biometric parameter, provided by the user at a first point in time, and obtains a second measurement of the biometric parameter, provided by the user at a second point in time that is later than the first point in time. The device compares the first measurement and the second measurement, and selectively validates the request, based on a result of comparing the first measurement and the second measurement, to selectively grant access to the server device.


