Guided Implicit Authentication via Contextual Behavior Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in efficiently authenticating users on mobile Internet devices, where password entry is tedious and error-prone due to limited input interfaces, and single sign-on mechanisms do not adequately defend against device theft, as they only verify device identity rather than user identity.

Innovation Solution

A guided implicit authentication system that uses contextual data such as location, time, social network information, and communication data to determine user behavior patterns, allowing for password-less access when patterns are consistent and prompting further verification when anomalies are detected, with the option for user confirmation and input to adjust behavior measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password entry is required for authentication, then security is improved, but ease of operation deteriorates due to tedious and error-prone password entry on mobile devices

Engineering Contradiction:
Improveauthentication securityVSAvoidease of authentication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs authentication automatically by analyzing contextual data and user behavior patterns without requiring manual password entry. The authentication system serves itself by making intelligent decisions about whether to prompt for credentials or grant access based on contextual analysis, eliminating the need for users to manually enter passwords.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical/password-based authentication system with an automated contextual analysis system. Instead of relying on manual password entry, the system uses software-based behavioral analysis of contextual data (location, time, device usage patterns) to determine authentication, substituting the mechanical input process with automated intelligent decision-making.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If single sign-on is implemented to enable access to multiple applications, then ease of operation is improved, but security deteriorates because it does not defend against device theft

Engineering Contradiction:
Improveease of access to applicationsVSAvoidsecurity against device theft
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system continuously monitors and analyzes contextual data and user behavior patterns, providing feedback about the current authentication risk level. Based on this feedback, the system dynamically adjusts its behavior - granting automatic access when risk is low and prompting for credentials when risk is high, thereby maintaining both ease of operation and security against device theft.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The authentication system transitions from static single sign-on to dynamic contextual-aware authentication. The system continuously adapts its authentication requirements based on real-time analysis of contextual data, device location, usage patterns, and potential anomalies, making the authentication process flexible and responsive to current conditions rather than fixed.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If implicit authentication based on contextual data is used, then ease of operation is improved by eliminating password entry, but measurement precision of user identity deteriorates due to potential false positives

Engineering Contradiction:
Improveease of authenticationVSAvoidaccuracy of user identity verification
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system applies partial authentication - it doesn't always require full explicit authentication, but rather uses contextual analysis to make partial authentication decisions. When contextual data strongly indicates legitimate user behavior, the system grants access without full authentication, improving ease of operation while maintaining sufficient precision through careful analysis of multiple contextual factors.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes the authentication parameters from static credentials (passwords) to dynamic contextual parameters (location, time, behavior patterns). By analyzing multiple contextual parameters and their patterns over time, the system achieves both ease of operation and high measurement precision, as the contextual analysis can detect subtle changes in user behavior that indicate either legitimate access or potential theft.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8800056B2Guided implicit authentication
Publication Date: 2014.08.05 SAMSUNG ELECTRONICS CO LTD
  • US8800056B2 patent drawing
  • US8800056B2 patent drawing
  • US8800056B2 patent drawing

AI summary

Embodiments of the present disclosure provide a method and system for guided implicit authentication. The system first receives a request to access the controlled resource from a user. The system then determines whether the user request is inconsistent with regular user behavior by calculating a user behavior measure derived from historical contextual data of past user events. Next, the system allows the user to provide information associated with regular user behavior and/or current contextual data. The system further updates the user behavior measure based on current contextual data.