Keystroke Dynamics for Continuous Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user authentication methods, such as usernames and passwords, fingerprint scans, and facial recognition, are either insecure, intrusive, or lack continuous authentication capabilities, making them inadequate for ensuring the security of computing systems.

Innovation Solution

The use of keystroke dynamics to generate cryptographic keys based on timing information from user keystroke patterns, which are unique and can change over time, allowing for continuous authentication without the need for secret protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (usernames/passwords, fingerprint scans, facial recognition) are used, then user identification can be achieved, but security is compromised, hardware requirements increase, or user convenience deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses the user's own typing behavior as the authentication mechanism. The keyboard controller automatically captures keystroke timing data and generates authentication signatures without requiring the user to consciously participate in the authentication process, making it both secure and convenient

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces physical authentication mechanisms (fingerprint scanners, facial recognition cameras) with a software-based analysis of mechanical typing patterns. Instead of requiring specialized hardware to capture biometric data, the system uses timing information from standard keyboard input to generate cryptographic signatures

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If fingerprint scans or facial recognition are implemented, then authentication capability is improved, but hardware complexity and intrusiveness increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system makes the standard keyboard serve multiple functions: both normal text input and authentication signature generation. The same keyboard hardware used for typing also captures the timing patterns needed for cryptographic key generation, eliminating the need for separate authentication hardware

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent substitutes specialized biometric hardware (fingerprint scanners, cameras) with a software-based system that analyzes temporal patterns from standard keyboard input. The authentication capability is derived from the timing characteristics of keystrokes rather than from dedicated sensing hardware

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If continuous authentication is implemented, then security against unauthorized use is improved, but system complexity increases

Engineering Contradiction:
Improvecontinuous authenticationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system continuously generates authentication signatures during normal typing activities. Every keystroke sequence contributes to maintaining the cryptographic key, providing continuous authentication without requiring separate verification steps or interrupting the user's workflow

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent merges the authentication process with normal typing operations. The same keystroke data used for text input is simultaneously used to generate and update cryptographic signatures, combining productivity and security functions into a single seamless process

Inventive Principle:
Principle #5Merging (Combining)

4Ease of operation

If keystroke dynamics are used for authentication, then user convenience and continuous authentication are improved, but measurement precision requirements increase

Engineering Contradiction:
Improveuser convenienceVSAvoidtiming measurement precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system transforms precise timing measurements into discrete cryptographic bits through threshold comparisons. By converting continuous timing data into binary decisions (above/below threshold), the system maintains security while being tolerant of minor timing variations and measurement noise

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10693661B1Dynamic signature generation from keystroke dynamics
Publication Date: 2020.06.23 NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA LLC
  • US10693661B1 patent drawing
  • US10693661B1 patent drawing
  • US10693661B1 patent drawing

AI summary

Described herein are various technologies pertaining to extracting cryptographic keys from user behavioral biometrics, specifically keystroke dynamics. Such cryptographic keys can be used for, among other things, user authentication throughout computer sessions. Keystroke dynamics are timing data indicating when keys were pressed and when they were released.