Continuous User Authentication via Behavioral Deviation Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods for electronic devices are inadequate in continuously verifying user identity, particularly in preventing unauthorized access and device misuse, as they often rely on static credentials and do not effectively differentiate between legitimate users and imposters.

Innovation Solution

A computer-implemented method and apparatus for continuous user authentication using a combination of touch measurements, accelerometer data, gyroscope measurements, application context, and power consumption patterns, which builds a behavior model and enforces access control policies based on deviations from a pre-defined baseline, allowing for real-time authentication and dynamic policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static credentials are used for authentication, then the authentication process is simple and fast, but the system cannot continuously verify user identity and is vulnerable to unauthorized access

Engineering Contradiction:
Improveuser authentication reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static authentication into dynamic continuous authentication by continuously monitoring multiple behavioral parameters (touch patterns, accelerometer data, gyroscope measurements, application context, power consumption) and comparing them against established baseline models. This dynamic approach allows the system to adaptively verify user identity throughout device usage rather than relying on one-time static credentials.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent combines multiple different types of behavioral data (touch measurements, motion sensor data, application context, power measurements) into a composite authentication model. By fusing these diverse data sources and analyzing them together through machine learning algorithms, the system achieves more reliable authentication than any single parameter could provide alone.

Inventive Principle:
Principle #40Composite materials

2Measurement precision

If continuous authentication with multiple parameters is implemented, then the ability to differentiate legitimate users from imposters improves, but the computational complexity and processing requirements increase

Engineering Contradiction:
Improveuser identification accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by continuously collecting and preprocessing authentication data in the background during normal device usage. Behavioral baselines are established and updated over time, and data normalization and feature extraction are performed proactively so that when authentication decisions are needed, the processing requirements are reduced and decisions can be made more efficiently.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system operates autonomously by automatically collecting data from multiple sensors, processing the information through machine learning models, making authentication decisions, and enforcing access control policies without requiring manual intervention. The system self-manages the entire authentication lifecycle from data collection to policy enforcement.

Inventive Principle:
Principle #25Self-service

3Reliability

If access control policies are dynamically enforced based on real-time authentication, then security against unauthorized access improves, but the processing overhead and impact on device performance increases

Engineering Contradiction:
Improveaccess control securityVSAvoiddevice operational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements periodic authentication checks at strategically determined intervals rather than continuously monitoring every action. The system evaluates whether re-authentication is necessary based on contextual factors such as the sensitivity of the application, the user's current behavior patterns, and the security risk level. This periodic approach maintains security while reducing unnecessary processing overhead.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system dynamically adjusts authentication parameters and policy enforcement levels based on real-time conditions. When risk is low and user behavior matches established patterns, the system operates with minimal overhead. When anomalies are detected or high-security applications are accessed, the system increases monitoring intensity and enforcement strictness, optimizing the balance between security and performance based on current context.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10776463B2Active authentication of users
Publication Date: 2020.09.15 A2 LABS LLC
  • US10776463B2 patent drawing
  • US10776463B2 patent drawing
  • US10776463B2 patent drawing

AI summary

Embodiments herein disclose a method and system for authenticating users of an electronic device. In an example, data pertaining to a user of the electronic device is collected for authentication. The data is data indicative of an interaction behavior of the user with the electronic device. A deviation of the collected data from a behavior model of the user is checked. To generate the behavior model, data from multiple users is collected to create the behavior model corresponding to each of the users, each behavior model is indicative of data uncommon between the user corresponding to the behavior model and other users in the plurality of users to separate the user corresponding to the behavior model from other users in the multiple users. Further, an access control policy is enforced on the electronic device, based on the deviation of the collected data from the behavior model of the user.