Continuous User Authentication via Behavioral Deviation Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication methods for electronic devices are inadequate in continuously verifying user identity, particularly in preventing unauthorized access and device misuse, as they often rely on static credentials and do not effectively differentiate between legitimate users and imposters.
Innovation Solution
A computer-implemented method and apparatus for continuous user authentication using a combination of touch measurements, accelerometer data, gyroscope measurements, application context, and power consumption patterns, which builds a behavior model and enforces access control policies based on deviations from a pre-defined baseline, allowing for real-time authentication and dynamic policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static credentials are used for authentication, then the authentication process is simple and fast, but the system cannot continuously verify user identity and is vulnerable to unauthorized access
Solution Approach 1:
The patent transforms static authentication into dynamic continuous authentication by continuously monitoring multiple behavioral parameters (touch patterns, accelerometer data, gyroscope measurements, application context, power consumption) and comparing them against established baseline models. This dynamic approach allows the system to adaptively verify user identity throughout device usage rather than relying on one-time static credentials.
Solution Approach 2:
The patent combines multiple different types of behavioral data (touch measurements, motion sensor data, application context, power measurements) into a composite authentication model. By fusing these diverse data sources and analyzing them together through machine learning algorithms, the system achieves more reliable authentication than any single parameter could provide alone.
2Measurement precision
If continuous authentication with multiple parameters is implemented, then the ability to differentiate legitimate users from imposters improves, but the computational complexity and processing requirements increase
Solution Approach 1:
The patent performs preliminary actions by continuously collecting and preprocessing authentication data in the background during normal device usage. Behavioral baselines are established and updated over time, and data normalization and feature extraction are performed proactively so that when authentication decisions are needed, the processing requirements are reduced and decisions can be made more efficiently.
Solution Approach 2:
The authentication system operates autonomously by automatically collecting data from multiple sensors, processing the information through machine learning models, making authentication decisions, and enforcing access control policies without requiring manual intervention. The system self-manages the entire authentication lifecycle from data collection to policy enforcement.
3Reliability
If access control policies are dynamically enforced based on real-time authentication, then security against unauthorized access improves, but the processing overhead and impact on device performance increases
Solution Approach 1:
The patent implements periodic authentication checks at strategically determined intervals rather than continuously monitoring every action. The system evaluates whether re-authentication is necessary based on contextual factors such as the sensitivity of the application, the user's current behavior patterns, and the security risk level. This periodic approach maintains security while reducing unnecessary processing overhead.
Solution Approach 2:
The system dynamically adjusts authentication parameters and policy enforcement levels based on real-time conditions. When risk is low and user behavior matches established patterns, the system operates with minimal overhead. When anomalies are detected or high-security applications are accessed, the system increases monitoring intensity and enforcement strictness, optimizing the balance between security and performance based on current context.
Data Source
AI summary
Embodiments herein disclose a method and system for authenticating users of an electronic device. In an example, data pertaining to a user of the electronic device is collected for authentication. The data is data indicative of an interaction behavior of the user with the electronic device. A deviation of the collected data from a behavior model of the user is checked. To generate the behavior model, data from multiple users is collected to create the behavior model corresponding to each of the users, each behavior model is indicative of data uncommon between the user corresponding to the behavior model and other users in the plurality of users to separate the user corresponding to the behavior model from other users in the multiple users. Further, an access control policy is enforced on the electronic device, based on the deviation of the collected data from the behavior model of the user.


