Continuous User Authentication via Behavioral Biometrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control systems for connected devices and services are vulnerable to security threats such as relay attacks, cloning, and other forms of misuse, particularly in the context of IoT and connected transportation, where secure and flexible access management is needed without compromising user experience.
Innovation Solution
Implementing a method that uses multi-factor considerations across users, equipment, and external context to provide flexible, convenient, and secure access control through continuous authentication, leveraging sensors and machine learning algorithms to generate likelihood values and authenticate users based on behavioral and contextual data, with secondary authentication methods triggered when necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional access control systems are used, then ease of operation is improved, but security is worsened due to vulnerability to relay attacks and cloning
Solution Approach 1:
The system performs preliminary authentication by analyzing behavioral biometrics and contextual data before granting access. Sensors continuously collect data about user behavior patterns, device usage characteristics, and environmental context, which are processed to establish a baseline of authorized user behavior before access decisions are made.
Solution Approach 2:
The system implements continuous feedback loops where sensor data from accelerometers, gyroscopes, touchscreens, and other devices is constantly monitored and analyzed. This feedback mechanism allows the system to detect anomalies in real-time and adjust authentication requirements dynamically, preventing relay attacks while maintaining convenience for legitimate users.
2Reliability
If continuous authentication with multiple sensors is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The system leverages existing multi-functional mobile devices as authentication tokens. Smartphones and wearables that users already carry are utilized to collect behavioral biometric data through their built-in sensors (accelerometers, gyroscopes, touchscreens). This approach eliminates the need for separate dedicated authentication devices while achieving enhanced security through continuous multi-parameter monitoring.
Solution Approach 2:
The system performs self-authentication by automatically analyzing behavioral patterns and contextual data without requiring active user participation. The continuous authentication process runs in the background, autonomously evaluating sensor data and making access decisions, thereby reducing the perceived complexity for end users while maintaining robust security.
3Measurement precision
If behavioral biometrics and contextual data are analyzed, then measurement precision of user identity is improved, but loss of information processing increases
Solution Approach 1:
The system extracts and analyzes only the most discriminative features from sensor data, such as typing rhythm, device holding patterns, and movement characteristics. By focusing on key behavioral biometric indicators rather than processing all raw sensor data, the system achieves high identity verification accuracy while minimizing computational overhead and information processing requirements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods and systems for continuously authenticating a user of a device by comparing current sensor data of the device being used with a fingerprint generated from sensor data collected from the device during use by an authorized user. A likelihood value, indicating the likelihood that the user is an authorized user of the device, is generated and the user is authenticated when the likelihood value is determined to be acceptable.