Context-Based Authentication State Machine for Mobile Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile computing devices face security risks due to reduced user control, particularly when devices are shared or left unattended, leading to inconvenient and potentially insecure frequent authentication requests.

Innovation Solution

Implementing a context-based authentication system that uses sensors to determine the device's context, such as being carried or located, to manage authentication and security states, reducing the need for frequent active security challenges by transitioning between authentication and security states based on the device's context.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If frequent user authentication requests are implemented to improve security, then security level increases, but user convenience deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic authentication policies that adjust security requirements based on real-time context factors such as device location, time of day, and user behavior patterns. The system transitions between different authentication states (e.g., locked, unlocked, biometric-only) depending on contextual conditions, allowing security levels to fluctuate dynamically rather than remaining static. This resolves the contradiction by providing high security when needed while maintaining convenience during trusted usage scenarios.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters based on context state, including modifying authentication timeout periods, required authentication methods, and security challenge frequencies. For example, the system may extend authentication validity duration or reduce challenge frequency when contextual indicators suggest low risk, while tightening requirements when risk indicators are present. This parameter adaptation allows the system to optimize both security and user experience for different operational contexts.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If repeated user authentication is required to enhance security, then security improves, but user efficiency deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication assessments by continuously monitoring contextual factors such as device orientation, location, and usage patterns to pre-determine appropriate authentication requirements. Before requiring full authentication, the system evaluates whether contextual indicators suggest the device is in a trusted state, allowing users to bypass authentication steps when conditions indicate low risk. This preliminary evaluation prevents unnecessary authentication interruptions while maintaining security vigilance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial authentication mechanisms that require only subset of full authentication procedures when contextual risk assessment indicates reduced threat levels. For example, the system may accept simplified biometric verification or shortened passcode entry instead of full multi-factor authentication during low-risk periods or trusted locations. This partial action approach maintains adequate security while significantly reducing the time and effort required for authentication during normal usage scenarios.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If authentication frequency is increased to reduce security risks, then security improves, but user experience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system continuously monitors contextual feedback including device sensors, location data, and usage patterns to dynamically adjust authentication frequency and requirements. When feedback indicates the device is in a trusted context (e.g., recognized location, typical usage pattern, device in user possession), the system reduces authentication frequency. Conversely, when feedback suggests potential security concerns (e.g., unusual location, device left unattended, suspicious behavior patterns), the system increases authentication frequency. This feedback-driven adaptation resolves the contradiction by aligning authentication demands with actual security needs rather than applying uniform frequent authentication.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements dynamic transitions between different authentication states based on real-time contextual assessment. The system can smoothly transition between states such as fully authenticated, partially authenticated, and unauthenticated depending on contextual factors, allowing authentication requirements to flow dynamically rather than switching abruptly. This dynamic state management maintains security by ensuring appropriate authentication levels are present when needed while providing continuous, seamless user experience during trusted usage by eliminating unnecessary authentication interruptions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3238115B1Technologies for authenticating a user of a computing device based on authentication context state
Publication Date: 2023.06.07 INTEL CORP
  • EP3238115B1 patent drawingFigure 1
  • EP3238115B1 patent drawingFigure 2
  • EP3238115B1 patent drawingFigure 3~6

AI summary

Technologies for authenticating a user of a computing device based on an authentication context state includes generating context state outputs indicative of various context states of a mobile computing device based on sensor data generated by sensors of the mobile computing device. An authentication manager of the computing device implements an authentication state machine to authenticate a user of the computing device. The authentication state machine includes a number of authentication states, and each authentication state includes one or more transitions to another authentication state. Each of the transitions is dependent upon a context state output. The computing device may also include a device security manager, which implements a security state machine that includes a number of security states. Transition between security states is dependent upon the present authentication state of the user. The device security manager may implement a different security function in each security state.