Authentication Using Cursor Location Features
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods using keystroke dynamics expose key codes to potential theft during transmission and storage, making them vulnerable to credential theft through man-in-the-middle attacks and other security breaches.
Innovation Solution
A system that authenticates users based on features extracted from cursor locations and action types within a text field, using latency between events, without exposing key codes, employing a learning model or statistical mechanism for user verification and identification in both static and free text contexts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If keystroke dynamics authentication is implemented using key codes, then user authentication capability is improved, but security deteriorates due to exposure of key codes during transmission and storage
Solution Approach 1:
The patent extracts only the essential authentication information (cursor locations and timing data) from the complete keystroke events, eliminating the need to transmit or store actual key codes. This extraction approach maintains authentication capability while removing the security vulnerability associated with key code exposure.
Solution Approach 2:
The system introduces cursor location data as an intermediary representation of user input. Instead of directly using key codes for authentication, the system mediates through cursor position and timing information, which preserves authentication reliability while preventing credential theft since cursor locations do not reveal the actual typed content.
2Object-affected harmful factors
If cursor location data is used for authentication, then security is improved by reducing credential exposure, but measurement precision deteriorates due to indirect input tracking
Solution Approach 1:
The patent changes the measurement parameters from direct key code identification to cursor location coordinates and timing intervals. This parameter transformation maintains sufficient precision for authentication by capturing the unique temporal and spatial patterns of user typing behavior, while improving security by not exposing actual credential content.
3Speed
If traditional keystroke authentication is used, then authentication speed is improved, but vulnerability to attacks increases due to direct key code handling
Solution Approach 1:
The system extracts only the necessary temporal and spatial features (cursor locations and timing data) needed for authentication, eliminating the transmission and storage of vulnerable key code information. This maintains authentication speed by processing compact feature data while reducing attack vulnerability through minimized data exposure.
Data Source
AI summary
In an example computer-implemented method, a number of cursor locations within a text field, and associated action types and time stamps are received via a processor. One or more features including a latency between a number of events associated with the cursor locations is extracted via the processor based on the cursor locations and the associated action types and time stamps. A user is authenticated, identified, or verified via the processor based on the extracted one or more features and a learning model or a statistical mechanism.


