Dynamic Passive Authentication With Continuous Biometric Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems that rely on initial login credentials fail to ensure ongoing user authorization, allowing unauthorized access and proxy worker usage, particularly in enterprise environments.

Innovation Solution

Implement passive biometric authentication by capturing and continuously comparing user biometric data, such as facial images and fingerprints, using integrated devices like web cameras and keyboards, to verify ongoing user identity and initiate mitigation actions if a mismatch occurs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If initial login credentials are used for authentication, then users can access computing devices, but unauthorized access and proxy worker usage cannot be detected

Engineering Contradiction:
ImproveUser access to computing deviceVSAvoidAuthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs authentication continuously throughout the computing session rather than only at login. Biometric data is captured and compared at multiple points during the session to ensure the authorized user remains present, transforming authentication from a one-time event to an ongoing verification process that prevents proxy workers and unauthorized access.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system establishes a feedback loop where biometric data is continuously captured, compared against registered user data, and used to determine whether to maintain or revoke access. When a mismatch is detected, the system provides feedback by blocking access or requiring reauthentication, creating a dynamic security mechanism that responds to changing conditions during the session.

Inventive Principle:
Principle #23Feedback

2Reliability

If passive biometric authentication is implemented, then continuous authentication is achieved, but device complexity increases

Engineering Contradiction:
ImproveContinuous authenticationVSAvoidAuthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system operates autonomously without requiring active user participation. Biometric data is captured automatically through devices like web cameras and keyboards as users naturally interact with the system, and the comparison process runs in the background. This self-service approach achieves continuous authentication while minimizing user burden and perceived complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Existing hardware components such as web cameras, keyboards, and mice are made multi-functional by enabling them to capture and transmit biometric data for authentication purposes. Rather than adding dedicated authentication hardware, the system leverages universal devices already present in the computing environment, reducing overall system complexity while achieving continuous authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12388817B2Dynamic passive authentication
Publication Date: 2025.08.12 BANK OF AMERICA CORP
  • US12388817B2 patent drawing
  • US12388817B2 patent drawing
  • US12388817B2 patent drawing

AI summary

Arrangements for providing dynamic passive authentication are provided. In some aspects, registration data may be received for a plurality of users. The registration data may include biometric data of each user of the plurality of users, and identification of one or more user computing devices that each user is authorize to access. In response to receiving an indication of login to a user computing device by a first user, one or more passive authentication functions may be activated and biometric data may be received from devices associated with the user computing device. The computing platform may compare the received biometric data to registration biometric data associated with the first user. If the received data matches the registration data, the system may capture additional biometric data at a subsequent time. If the received data does not match the registration data, one or more mitigation actions may be identified and executed.