Dynamic Mobile Authentication via Context-Aware Security Tasks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current password-based authentication systems on mobile devices face challenges due to users selecting weak passwords, which are easily compromised, especially in public or insecure environments, and complexity requirements can reduce ease-of-use while not always preventing weak password selection.

Innovation Solution

The system generates dynamic security tasks based on user-specific and device-specific information, such as interaction history, location, and sensor data, to create a set of security tasks that require users to authenticate, adjusting the tasks based on user responses and environmental context.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complexity requirements are imposed on passwords, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of use
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic authentication that adapts to environmental conditions. The system monitors whether the device is in a secure or insecure environment and adjusts authentication requirements accordingly. In secure environments, simpler authentication is accepted, while in insecure environments, more stringent verification is applied. This dynamic approach resolves the contradiction by making security requirements flexible rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters based on environmental context. It monitors device state, location, and security context to dynamically adjust authentication strength. When the device detects an insecure environment, it increases authentication stringency; when in a secure environment, it relaxes requirements. This parameter adaptation allows the system to maintain security while preserving ease of use in appropriate contexts.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If user-selected passwords are used, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of useVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements feedback loops that continuously monitor authentication attempts and environmental security conditions. When weak passwords are detected or insecure environments are identified, the system provides feedback by increasing authentication stringency. This feedback mechanism allows user-selected passwords to remain in use while compensating for their weaknesses through dynamic security adjustments.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system takes preliminary anti-action by proactively detecting insecure environments and potential security threats before they can compromise user data. It monitors device state, location, and authentication patterns to preemptively strengthen security measures when risks are detected, preventing weak passwords from being exploited in insecure contexts.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If dynamic security tasks are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct modules: environment monitoring, risk assessment, and dynamic authentication task generation. Each module performs a specific function and can be independently managed. This segmentation allows the complex dynamic security system to be implemented in a modular fashion, reducing the burden of system complexity while maintaining enhanced security capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10313882B2Dynamic unlock mechanisms for mobile devices
Publication Date: 2019.06.04 AMAZON TECH INC
  • US10313882B2 patent drawing
  • US10313882B2 patent drawing
  • US10313882B2 patent drawing

AI summary

An access control application for mobile devices is provided. The access control application may be configured to generate a set of security tasks based at least in part on information corresponding to a user's interactions with the mobile device. An unlock screen of the mobile device may be triggered and security tasks from the generated set of security tasks may be displayed through a user interface of the mobile device. The user's response to the security tasks may be obtained and a confidence score may be calculated, based at least in part on the response. The access control application may then determine, based at least in part on the score and one or more attributes of the environment, whether to unlock the mobile device or prompt the user to provide an additional response to another security task.