Dynamic Authentication Switching for Sensitive Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional authentication methods in computing devices are vulnerable to unauthorized access, particularly when sensitive user information is exposed without prior authentication, as malicious entities can exploit biometric data to gain access to devices storing multiple user identities.

Innovation Solution

Implementing a secure circuit that adjusts authentication requirements by changing the authentication type in response to requests for sensitive information, such as requiring manual entry of a passcode instead of biometric authentication, to enhance security and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric authentication is used to reduce user burden, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system dynamically switches between biometric and manual authentication modes based on the state of the device. When sensitive information is exposed without proper authentication, the system transitions from allowing biometric authentication to requiring manual authentication, making the authentication mechanism adaptive to security conditions rather than static

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system preemptively changes authentication requirements when it detects that sensitive information has been exposed. By switching to manual authentication before a potential security breach can occur, the system prevents unauthorized access rather than reacting after authentication fails

Inventive Principle:
Principle #9Preliminary anti-action

2Ease of operation

If sensitive information is disclosed without authentication, then accessibility is improved, but security deteriorates

Engineering Contradiction:
ImproveaccessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system monitors whether sensitive information is accessed without proper authentication and uses this feedback to change authentication requirements. When the system detects that information has been exposed, it feeds this information back into the authentication mechanism by switching to manual authentication mode

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11537699B2Authentication techniques in response to attempts to access sensitive information
Publication Date: 2022.12.27 APPLE INC
  • US11537699B2 patent drawing
  • US11537699B2 patent drawing
  • US11537699B2 patent drawing

AI summary

The present disclosure describes techniques for changing a required authentication type based on a request for a particular type of information. For example, consider a situation where a user has asked a virtual assistant “who owns this device?” By default, the device may allow biometric authentication to unlock. In response to identification of the owner by the virtual assistant, however, the device may require one or more other types of authentication (e.g., manual entry of a passcode) to unlock the device. In various embodiments, the disclosed techniques may increase the security of the device by making it more difficult for malicious entities to obtain the sensitive information or to access device functionality once the sensitive information has been disclosed. In various embodiments, this may prevent or reduce unauthorized access to the device.