Biometric Authentication System with ML-Identified Primary Features
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric authentication methods on mobile devices are vulnerable to insider attacks, as authorized biometric features can be easily compromised by individuals familiar with the user, allowing unauthorized access to sensitive information.
Innovation Solution
A system that identifies primary biometric features using a machine learning algorithm based on user activity history, which cannot be manually added, updated, or removed, and uses these features for authenticating access-controlled operations, ensuring tamper-resistance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional biometric authentication mechanisms are used, then ease of operation is improved, but security is worsened due to vulnerability to insider attacks
Solution Approach 1:
The patent segments the biometric authentication system into multiple independent components: primary biometric features (identified through machine learning from user activity history) and secondary biometric features (manually enrolled). This segmentation allows the system to differentiate between genuine user biometrics and potential insider attacks, resolving the contradiction by maintaining ease of operation while improving security through layered verification.
Solution Approach 2:
The patent introduces machine learning algorithms as an intermediary between the user and the authentication system. The algorithm analyzes user activity history to identify primary biometric features that cannot be manually added or removed, creating a mediating layer that prevents insider attacks while maintaining seamless user experience.
2Adaptability or versatility
If multiple biometric features are stored for authentication, then adaptability is improved, but security is worsened due to increased vulnerability to compromise
Solution Approach 1:
The patent divides stored biometric features into two distinct categories: primary biometric features identified through machine learning analysis of user activity, and secondary biometric features manually enrolled by the user. This segmentation enables the system to leverage multiple biometric features for adaptability while using the machine-identified primary features as a security anchor that cannot be compromised through manual enrollment attacks.
Solution Approach 2:
The system performs preliminary analysis of user activity history before authentication to identify primary biometric features. This preliminary action establishes a baseline of genuine user behavior patterns that cannot be replicated by insiders, allowing the system to subsequently use multiple biometric features safely for authentication.
3Ease of operation
If manual biometric feature enrollment is allowed, then ease of operation is improved, but security is worsened due to ease of compromise by insiders
Solution Approach 1:
The patent segments biometric feature enrollment into two pathways: manual enrollment for secondary biometric features (maintaining ease of operation) and machine learning-based identification for primary biometric features (preventing insider attacks). The primary features are extracted from user activity history without manual intervention, making them immune to insider enrollment attacks while secondary features provide operational flexibility.
Solution Approach 2:
The system uses machine learning algorithms to automatically identify primary biometric features from user activity history without requiring manual user input. This self-service approach eliminates the vulnerability to insider attacks that arises from manual enrollment, while the system still allows manual enrollment of secondary features for operational convenience.
Data Source
AI summary
A method, system and computer program product for processing data are provided. In the method, a request is received to perform an access-controlled operation in a user device. A biometric feature input from an input module of the user device is received for the request. It is determined whether the received biometric feature matching with a primary biometric feature, the primary biometric feature being identified from a plurality of biometric features stored in the user device and being used to authenticate a user for the access-controlled operation. The access-controlled operation is enabled in response to determining the received biometric feature matching with a primary biometric feature.


