Blockchain Authentication Using Behavioral Biometrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems rely on static credentials, making them vulnerable to unauthorized access and malicious activities, as they cannot differentiate between the actual user and a bad actor posing as the user.

Innovation Solution

An information security architecture utilizing private and semi-private blockchains to securely store and share user information, authenticating users based on their recent activity patterns rather than static credentials, by mirroring user data between the two blockchains with restricted access through anonymized blocks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static authentication credentials (username and password) are used, then authentication is simple and fast, but the system becomes vulnerable to unauthorized access by bad actors who obtain credentials

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transitions from static authentication credentials to dynamic behavioral biometrics. The system continuously collects user interaction data (keystroke patterns, mouse movements, scrolling behavior) and updates behavioral profiles in real-time. This dynamic approach allows the authentication system to adapt to changing user behaviors while maintaining security, resolving the contradiction between simplicity and security by making authentication both continuous and context-aware.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-authentication by automatically analyzing user behavioral patterns without requiring explicit user input. The behavioral biometric engine continuously monitors and analyzes user interactions with the device, automatically creating and updating behavioral profiles. This self-service mechanism maintains security while preserving ease of operation, as users simply need to interact naturally with the device for authentication to occur.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If the system stores detailed user information for behavioral analysis, then authentication accuracy improves, but information security and privacy protection become more challenging

Engineering Contradiction:
Improveauthentication accuracyVSAvoidinformation security risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent implements differential privacy protection where different levels of data protection are applied to different types of information. Personally identifiable information (PII) receives stronger protection through aggregation and anonymization, while behavioral pattern data maintains higher fidelity for authentication purposes. This local quality approach allows the system to preserve authentication accuracy for behavioral metrics while applying appropriate security measures to sensitive user information.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces cryptographic hash functions and anonymization techniques as intermediaries between raw user data and stored behavioral profiles. Instead of storing actual user inputs or identifiable information, the system processes data through cryptographic transformations that preserve behavioral patterns while removing personally identifiable information. This intermediary layer maintains authentication accuracy while protecting user privacy and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system continuously monitors user behavior for authentication, then security against credential theft improves, but device complexity and computational resources increase

Engineering Contradiction:
Improvesecurity against credential theftVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a progressive monitoring approach where behavioral data collection starts with basic interaction patterns and gradually incorporates more sophisticated metrics as the behavioral profile develops. Initially, the system focuses on fundamental keystroke and mouse patterns, then progressively adds more complex behavioral dimensions. This partial action approach maintains security while managing computational complexity by not immediately implementing all possible monitoring capabilities.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary data processing and feature extraction at the point of data generation, transforming raw interaction data into condensed behavioral features before storage and analysis. By pre-processing data locally on the device and extracting only relevant behavioral characteristics, the system reduces the computational burden on centralized servers while maintaining security. This preliminary action approach simplifies the overall system architecture while preserving security effectiveness.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11658978B2Authentication using blockchains
Publication Date: 2023.05.23 BANK OF AMERICA CORP
  • US11658978B2 patent drawing
  • US11658978B2 patent drawing
  • US11658978B2 patent drawing

AI summary

An authentication device that includes a memory operable to store a behavior signature for a user and a distributed ledger comprising information for a private blockchain and a semi-private blockchain associated with the user. The network device further includes an authentication engine implemented by a processor. The authentication engine is configured to receive an authentication request for a network resource and to determine a resource classification type based on the network resource. The authentication engine is further configured to identify one of the private blockchain and the semi-private blockchain based on the resource classification type and to extract data from one or more blocks in the identified blockchain. The authentication engine is further configured to determine at least a portion of the extracted data matches the stored behavior signature for the user and to provide access to the network resource in response to the determination.