Handwriting-Based Authentication Using Device Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SMS-based multi-factor authentication (MFA) is vulnerable to SIM swapping attacks, compromising network and data security and requiring significant computing resources for incident management.

Innovation Solution

Implement device-independent user authentication using device metadata (orientation, touch pressure, typing speed) and handwriting analysis, employing user-specific machine learning models to verify user identity, reducing reliance on device-specific characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SMS-based multi-factor authentication is used, then user access control is implemented, but the system becomes vulnerable to SIM swapping attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidSIM swapping attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the SMS-based authentication mechanism with a biometric-based authentication mechanism using handwriting analysis. Instead of relying on SMS messages that can be intercepted through SIM swapping, the system uses unique handwriting characteristics captured through device sensors, substituting a vulnerable communication-based system with a biometric-based system that is inherently more secure against such attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces device metadata and handwriting analysis as an intermediary layer between the user and the authentication system. Rather than directly relying on SMS messages, the system uses handwriting characteristics captured through device sensors as an intermediate verification method that cannot be compromised by SIM swapping attacks, adding a layer of security that bridges traditional authentication with biometric verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional authentication methods are used, then access control is provided, but computing resources are consumed for incident management

Engineering Contradiction:
Improveaccess controlVSAvoidcomputing resources
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent implements self-service authentication by using the user's own handwriting characteristics as the authentication credential. The system automatically captures device metadata and handwriting inputs during normal user interaction, eliminating the need for separate authentication actions. This self-service approach reduces the burden on both users and system resources, as authentication is seamlessly integrated into the user experience without requiring additional computing resources for incident management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary authentication verification by analyzing handwriting characteristics before granting access. By capturing and verifying device metadata and handwriting inputs during the initial interaction, the system prevents unauthorized access before it can consume computing resources for incident management. This preliminary action ensures that only authenticated users can access the system, avoiding the need for resource-intensive security incidents.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If device-specific authentication is used, then user identity is verified, but the system lacks adaptability to different devices

Engineering Contradiction:
Improveuser identity verificationVSAvoiddevice independence
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal authentication mechanism that works across multiple devices by using handwriting characteristics rather than device-specific identifiers. The system captures device metadata including orientation, touch pressure, and typing speed, which are inherent to the user's interaction style rather than the specific device. This allows the authentication system to adapt to different devices while maintaining precise user identity verification, as the handwriting characteristics remain consistent across various devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the authentication parameters from device-specific characteristics to user-specific interaction characteristics. By focusing on parameters such as touch pressure, typing speed, and device orientation that reflect user behavior rather than device properties, the system achieves both precise user identity verification and adaptability to different devices. The authentication parameters are transformed from static device identifiers to dynamic user interaction metrics that remain consistent across device changes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260065714A1Device-independent user authentication
Publication Date: 2026.03.05 CAPITAL ONE SERVICES LLC
  • US20260065714A1 patent drawing
  • US20260065714A1 patent drawing
  • US20260065714A1 patent drawing

AI summary

In some implementations, a device may receive, from a user device, a login request to access an account associated with a user. The device may determine device metadata relating to a use of the user device in connection with the login request. The device may determine whether the use is recognized for the user based on the device metadata. The device may cause, responsive to a determination that the use is not recognized for the user, the user device to provide a prompt for inputting a handwriting sample. The device may determine input metadata relating to an inputting of the handwriting sample. The device may determine whether the handwriting sample is valid for the user based on the input metadata and an image of the handwriting sample. The device may authorize the login request responsive to a determination that the handwriting sample is valid for the user.