FIDO Authentication with Behavioral Biometric Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The FIDO protocol lacks robustness in ensuring that only the authorized user or entity can maintain a secure network connection, as it does not effectively differentiate between legitimate and unauthorized access, especially in cases of physical or remote device compromise.

Innovation Solution

Incorporating a behavioral biometric component into the FIDO authentication process by creating and monitoring a behavioral profile of the user's device usage patterns, such as touch screen interactions, device handling, and sensor data, to verify that the same user is operating the device during the secure data network session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional FIDO authentication is used, then the authentication process is simple and fast, but the security is insufficient when device compromise occurs

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines traditional FIDO cryptographic authentication with behavioral biometric analysis into a unified authentication system. The behavioral profile, created from sensor data capturing user interactions with the device, is merged with the cryptographic authentication process to provide enhanced security without requiring a separate authentication mechanism.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary behavioral profiling during the authentication process. Before granting access, the system captures sensor data from multiple sensors (accelerometer, gyroscope, touchscreen, etc.) to create or update a behavioral profile of the user's interaction patterns with the device, then compares this profile against stored profiles to verify authenticity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If behavioral monitoring is added to FIDO authentication, then the security against unauthorized access is improved, but the processing requirements and complexity increase

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidprocessing energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system uses existing device sensors that serve multiple functions. Sensors like the accelerometer, gyroscope, and touchscreen controllers are already present for standard device operations; the patent repurposes these sensors to also capture behavioral data for security authentication, eliminating the need for additional dedicated hardware and reducing overall processing overhead.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If continuous behavioral profiling is performed, then the detection of unauthorized access is more accurate, but the time required for authentication increases

Engineering Contradiction:
Improvebehavioral match accuracyVSAvoidauthentication time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs behavioral profiling selectively rather than continuously analyzing all sensor data in detail. It captures essential interaction patterns from sensors and compares key behavioral features against stored profiles, performing sufficient analysis to achieve accurate authentication without processing every possible data point, thus balancing accuracy with speed.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10848309B2Fido authentication with behavior report to maintain secure data connection
Publication Date: 2020.11.24 BEHAVIOSEC INC
  • US10848309B2 patent drawing
  • US10848309B2 patent drawing
  • US10848309B2 patent drawing

AI summary

FIDO authentication is augmented to include a behavioral score indicating that during a secure network session between a host and client device, the client device is being operated by a user with expected behavioral actions. The authenticated network session is maintained, stepped-up, or ended based on either or a combination of a positive response to a FIDO challenge and threshold of match between a current behavioral profile and a stored behavioral profile for the user.