Continuous User Authentication via Behavioral Biometrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems for connected devices and services are vulnerable to security threats such as relay attacks, cloning, and other forms of misuse, particularly in the context of IoT and connected transportation, where secure and flexible access management is needed without compromising user experience.

Innovation Solution

Implementing a method that uses multi-factor considerations across users, equipment, and external context to provide flexible, convenient, and secure access control through continuous authentication, leveraging sensors and machine learning algorithms to generate likelihood values and authenticate users based on behavioral and contextual data, with secondary authentication methods triggered when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional access control systems are used, then ease of operation is improved, but security is worsened due to vulnerability to relay attacks and cloning

Engineering Contradiction:
Improveaccess control convenienceVSAvoidsecurity against relay attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication by analyzing behavioral biometrics and contextual data before granting access. Sensors continuously collect data about user behavior patterns, device usage characteristics, and environmental context, which are processed to establish a baseline of authorized user behavior before access decisions are made.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where sensor data from accelerometers, gyroscopes, touchscreens, and other devices is constantly monitored and analyzed. This feedback mechanism allows the system to detect anomalies in real-time and adjust authentication requirements dynamically, preventing relay attacks while maintaining convenience for legitimate users.

Inventive Principle:
Principle #23Feedback

2Reliability

If continuous authentication with multiple sensors is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improvecontinuous authentication securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system leverages existing multi-functional mobile devices as authentication tokens. Smartphones and wearables that users already carry are utilized to collect behavioral biometric data through their built-in sensors (accelerometers, gyroscopes, touchscreens). This approach eliminates the need for separate dedicated authentication devices while achieving enhanced security through continuous multi-parameter monitoring.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs self-authentication by automatically analyzing behavioral patterns and contextual data without requiring active user participation. The continuous authentication process runs in the background, autonomously evaluating sensor data and making access decisions, thereby reducing the perceived complexity for end users while maintaining robust security.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If behavioral biometrics and contextual data are analyzed, then measurement precision of user identity is improved, but loss of information processing increases

Engineering Contradiction:
Improveuser identity verification accuracyVSAvoiddata processing load
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system extracts and analyzes only the most discriminative features from sensor data, such as typing rhythm, device holding patterns, and movement characteristics. By focusing on key behavioral biometric indicators rather than processing all raw sensor data, the system achieves high identity verification accuracy while minimizing computational overhead and information processing requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3926498B1System and method for continuous user authentication
Publication Date: 2024.11.27 IRDETO BV
  • EP3926498B1 patent drawingFigure 1
  • EP3926498B1 patent drawingFigure 2
  • EP3926498B1 patent drawingFigure 3

AI summary

Methods and systems for continuously authenticating a user of a device by comparing current sensor data of the device being used with a fingerprint generated from sensor data collected from the device during use by an authorized user. A likelihood value, indicating the likelihood that the user is an authorized user of the device, is generated and the user is authenticated when the likelihood value is determined to be acceptable.