Implicit User Authentication via Behavior Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge in user authentication on Mobile Internet Devices (MIDs) lies in the tedious and error-prone process of password entry due to limited input interfaces, and existing Single Sign-On (SSO) mechanisms do not adequately defend against device theft as they only verify the device's identity, not the user's.

Innovation Solution

A system that implicitly authenticates users by determining a user behavior score based on contextual data, such as GPS, accelerometer, and application usage, to assess consistency with historical patterns, allowing access to controlled resources without explicit password entry, while also serving as a second-factor authentication mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If explicit password authentication is required, then security is improved, but ease of operation deteriorates due to tedious password entry process

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs authentication automatically by monitoring device context and user behavior patterns without requiring explicit user action. The authentication process serves itself by continuously collecting contextual data (location, device state, usage patterns) and comparing it against established user profiles to determine authenticity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical/password-based authentication system with a contextual analysis system that uses software-based behavior pattern recognition. Instead of relying on explicit password entry, the system substitutes this with automated monitoring of device context, location data, and usage patterns to infer user identity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If Single Sign-On is implemented, then ease of operation is improved by allowing access to multiple applications, but security deteriorates because it does not defend against device theft

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces contextual data analysis as an intermediary layer between device authentication and resource access. Instead of directly trusting device identity, the system inserts a verification step that analyzes behavior patterns, location, and device state to determine whether the device is being used by the authorized user, thereby mediating the security risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication approach transitions from static device verification to dynamic behavior analysis. The system continuously monitors and compares real-time device context against historical user behavior patterns, making the authentication decision adaptive and responsive to current usage conditions rather than relying on fixed device trust.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If multiple data streams are collected for authentication, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improvemeasurement precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the authentication process into distinct modules: data collection from multiple sources (location services, device state monitoring, usage pattern tracking), data processing and analysis, and authentication decision-making. This segmentation allows each component to be optimized independently while working together to achieve precise authentication.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8312157B2Implicit authentication
Publication Date: 2012.11.13 SAMSUNG ELECTRONICS CO LTD
  • US8312157B2 patent drawing
  • US8312157B2 patent drawing
  • US8312157B2 patent drawing

AI summary

Embodiments of the present disclosure provide a method and system for implicitly authenticating a user to access controlled resources. The system receives a request to access the controlled resources. The system then determines a user behavior score based on a user behavior model, and recent contextual data about the user. The user behavior score facilitates identifying a level of consistency between one or more recent user events and a past user behavior pattern. The recent contextual data, which comprise a plurality of data streams, are collected from one or more user devices without prompting the user to perform an action explicitly associated with authentication. The plurality of data streams provide basis for determining the user behavior score, but a data stream alone provides insufficient basis for the determination of the user behavior score. The system also provides the user behavior score to an access controller of the controlled resource.