Biometric Authentication Using Eye Tracking and Physiological Signals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods, such as user ID and password, face recognition, and fingerprint scanning, fail to reliably verify a user's identity and intent, as they can be compromised by theft, accidental triggering, or forced use, lacking sufficient security against unauthorized access.

Innovation Solution

A computing device that gathers biometric and environmental data to evaluate a user's identity, intent, and possession of secret knowledge by using eye tracking, physiological responses, and machine learning models to generate an authentication score, allowing varying levels of access based on confidence levels and detecting duress indicators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (user ID and password) are used, then ease of operation is maintained, but reliability of identity verification deteriorates due to theft or guessing

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple authentication factors (biometric data, eye tracking, physiological responses, and secret knowledge verification) into a unified authentication system. This merging of multiple verification methods resolves the contradiction by maintaining high reliability through comprehensive checks while integrating them into a seamless user experience that does not significantly increase operational complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces eye tracking and physiological response monitoring as intermediary verification layers between traditional credentials and system access. These intermediaries provide additional reliability by detecting user state (intent, duress) without requiring complex user actions, thus resolving the contradiction between verification reliability and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If face recognition or fingerprint scanning is used, then ease of operation improves, but reliability of intent verification deteriorates due to accidental triggering or forced use

Engineering Contradiction:
Improveauthentication convenienceVSAvoidintent verification reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system continuously monitors physiological responses (pupillary response, heart rate, galvanic skin response) and eye tracking data during authentication to provide real-time feedback on user intent. This feedback mechanism detects signs of duress or accidental triggering, allowing the system to distinguish between voluntary and forced authentication while maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary verification of user intent through eye tracking and physiological baseline assessment before completing authentication. By checking for signs of duress or accidental activation in advance, the system prevents unauthorized access while maintaining convenient authentication for genuine users, resolving the contradiction between convenience and intent verification reliability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple authentication factors are combined, then reliability of authentication improves, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a multi-functional authentication system where a single integrated framework handles multiple verification types (biometric scanning, eye tracking, physiological monitoring, and knowledge verification). This universal approach resolves the contradiction by achieving high reliability through diverse verification methods while consolidating them into one cohesive system rather than separate complex components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If full access is provided upon authentication, then ease of operation is maintained, but security against duress deteriorates

Engineering Contradiction:
Improveaccess provisionVSAvoidprotection against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically adjusts access levels based on continuous monitoring of physiological responses and eye tracking data during and after authentication. When signs of duress are detected, the system transitions from providing full access to providing modified access (plausible deniability mode), where sensitive information is hidden. This dynamic adaptation resolves the contradiction by maintaining ease of operation for legitimate users while automatically enhancing security when duress is detected.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11636188B2Combining biometrics, hidden knowledge and intent to authenticate
Publication Date: 2023.04.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11636188B2 patent drawing
  • US11636188B2 patent drawing
  • US11636188B2 patent drawing

AI summary

A computing device is configured to verify a user's identity, intent to authenticate, and/or possession of secret knowledge by evaluating biometric and/or environmental data. In embodiments, such verification is performed by evaluating a user's reaction to a stimulus based on such data. Biometric data may comprise eye tracking data, and a computing device may be configured to use such data to verify that the person has gazed through objects in a predetermined order. In embodiments, the user's intent to authenticate is verified by combining such eye tracking data with other biometric data. Physiological and other types of biometric data may be used to evaluate the user for indicia of duress. Embodiments may be configured to provide modified access to the computing device or resources stored thereon where indicia of duress have been detected. Such modified access may comprise hiding information stored on the device.