Continuous Authentication Service for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic devices, such as smartphones and tablets, face challenges in providing simultaneous effective authentication while maintaining a seamless user experience, as they need to balance secure access control with user convenience and uninterrupted operation.

Innovation Solution

A system and method for continuous user authentication that launches a continuous authentication service at boot time, utilizing both explicit and implicit authentication information, and determines a security state based on time intervals and contextual factors to control access to device resources, minimizing unnecessary locking and prompts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used, then security is maintained, but user experience is disrupted due to frequent locking and authentication prompts

Engineering Contradiction:
Improveauthentication securityVSAvoiduser experience continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts authentication requirements based on the current security state, which is continuously updated based on user behavior patterns, device context, and environmental factors. This allows the authentication mechanism to adapt between strict security modes and convenient access modes, resolving the contradiction between security and ease of operation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of authentication frequency and strictness based on the security state value. When the security state indicates trusted usage patterns, the system reduces authentication frequency, thereby improving user experience while maintaining security through continuous monitoring

Inventive Principle:
Principle #35Parameter changes

2Reliability

If continuous authentication monitoring is implemented, then access control reliability is improved, but device power consumption increases

Engineering Contradiction:
Improveaccess control reliabilityVSAvoiddevice power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs authentication monitoring at periodic intervals rather than continuously, analyzing user behavior patterns and device state at scheduled times. This periodic approach maintains access control reliability while significantly reducing power consumption compared to continuous monitoring

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The authentication system leverages existing device sensors, processors, and operating system components to perform monitoring and analysis, rather than requiring dedicated high-power hardware. The system uses available computational resources efficiently to maintain security without proportionally increasing power consumption

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11985132B2System and method for resource access authentication
Publication Date: 2024.05.14 SAMSUNG ELECTRONICS CO LTD
  • US11985132B2 patent drawing
  • US11985132B2 patent drawing
  • US11985132B2 patent drawing

AI summary

A method of providing continuous user authentication for resource access control includes launching a continuous authentication service at a boot time of a first device, wherein the first device includes a processor, a memory, and one or more sensors configured to collect authentication information. Additionally, the method includes receiving authentication information comprising one or more of explicit authentication information or implicit authentication information, and receiving a request for access to a resource of the first device. Further, the method includes the operations of determining, by the continuous authentication service, a current value of a security state, the current value of the security state based in part on a time interval between a receipt time of the authentication information and a current time and controlling access to the resource based on the current value of the security state.