Local Implicit Authentication via Dynamic User Behavior Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless mobile device authentication methods, particularly password-based and biometric approaches, are vulnerable to attacks and lack reliability due to their reliance on insecure data connections and the need for explicit user authorization, leading to security and usability issues.

Innovation Solution

Implementing continuous, local implicit authentication within the device, using a user profile generated from behavior metrics like location and usage patterns, which dynamically updates and adapts to user behavior, ensuring secure and accurate authentication without relying on external networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remote implicit authentication is implemented using user behavior data, then authentication security is improved, but data confidentiality is compromised due to transmission over insecure connections

Engineering Contradiction:
Improveauthentication securityVSAvoiddata confidentiality
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the authentication processing function from the remote server and implements it locally within the mobile device. The user profile and behavior data are stored and processed locally, eliminating the need to transmit sensitive user data over insecure networks while still enabling comprehensive implicit authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a local authentication manager as an intermediary component that handles all authentication processing within the device. This intermediary processes user behavior data and compares it against the user profile locally, acting as a mediator between the user's behavior and the authentication decision without requiring external communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If on-demand implicit authentication is performed remotely, then authentication is simplified, but authentication accuracy deteriorates due to outdated behavioral data

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent implements continuous implicit authentication that operates in the background without requiring explicit user requests. The authentication manager continuously monitors user behavior, updates the user profile in real-time, and performs continuous verification, ensuring that the most current behavioral data is always used for authentication decisions.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs self-updating of the user profile automatically without requiring external intervention or explicit user authorization for each update. The authentication manager continuously learns from user behavior and adapts the profile dynamically, making the system self-improving and eliminating the need for periodic manual updates.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If explicit user authorization is required for model updates, then user control is improved, but system adaptability deteriorates causing false negative determinations

Engineering Contradiction:
Improveuser controlVSAvoidauthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a two-stage authentication process where preliminary continuous implicit authentication operates in the background to adapt the user profile and verify user identity. Only when this preliminary authentication fails or is explicitly triggered does the system require additional explicit user authorization, thus maintaining both adaptability and user control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors user behavior and provides feedback to dynamically update the user profile. The authentication manager uses feedback from ongoing behavior analysis to adaptively adjust the profile parameters and authentication thresholds, enabling the system to learn and adapt to changing user patterns without requiring explicit reauthorization.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3009950B1Method and apparatus for continuous and implicit local authentication of wireless mobile users based on dynamic profiling of conduct patterns
Publication Date: 2019.09.25 FUNDACIO EURECAT
  • EP3009950B1 patent drawingFigure 1
  • EP3009950B1 patent drawingFigure 2
  • EP3009950B1 patent drawingFigure 3

AI summary

The invention provides methods and apparatus for local, continuous and implicit authentication of wireless communication device users. The implicit authentication method is devised to constantly and transparently monitor the user behaviour and match it against a previously learnt model. The monitoring and matching operations are performed locally in a Trusted Execution Environment inside the device and thus all the sensitive data remains always under the control of the user and isolated from other applications. When the implicit authentication method considers that the device is being used by a non-legitimate user, it asks for an explicit, biometric-based authentication mechanism.