Dynamic Malicious Identity Profiles for Biometric Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional biometric authentication blacklists are static and outdated due to the reliance on explicit fraud feedback, often lacking updates when customers do not share biometric readings from fraudulent transactions, and consist only of manually confirmed fraudulent data.

Innovation Solution

Creating malicious identity profiles from failed authentication attempts, which are dynamic and shared among authentication servers, using data from unsuccessful attempts to learn fraudulent behaviors without labeled fraud data, and assigning scores via machine learning analytics for risk-based authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional blacklists are created from manually confirmed fraudulent biometric readings, then the blacklist contains verified fraudulent data, but the blacklist becomes static and outdated when customers do not share new fraudulent readings

Engineering Contradiction:
Improveaccuracy of blacklist dataVSAvoidtimeliness of blacklist updates
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The patent transforms the static blacklist into a dynamic system by automatically generating malicious identity profiles from failed authentication attempts. The system continuously updates profiles based on new failure patterns detected in real-time, making the blacklist adaptive and current without requiring manual customer input or sharing of fraudulent data.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops where failed authentication attempts are automatically analyzed and fed back into the profile generation process. This continuous feedback mechanism allows the blacklist to self-update based on observed failure patterns, maintaining both accuracy and timeliness simultaneously.

Inventive Principle:
Principle #23Feedback

2Duration of action of stationary object

If customers share biometric readings from fraudulent transactions to update blacklists, then the blacklist remains current, but customers find sharing readings overly burdensome

Engineering Contradiction:
Improvetimeliness of blacklist updatesVSAvoidburden on customers to share data
Core Design Contradiction:
Duration of action of stationary objectVSEase of operation

Solution Approach 1:

The system performs self-service by automatically generating malicious identity profiles from its own operational data (failed authentication attempts). No customer action or data sharing is required - the system independently detects patterns, creates profiles, and updates the blacklist autonomously, eliminating the burden on customers while maintaining timeliness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses internal feedback from authentication failures to automatically update the blacklist, removing the need for external customer input. The feedback loop operates independently within the system, continuously improving the blacklist without requiring customers to share biometric readings.

Inventive Principle:
Principle #23Feedback

3Duration of action of stationary object

If blacklists are updated frequently with new fraudulent readings, then the blacklist remains current, but the system requires explicit fraud feedback which is not always available

Engineering Contradiction:
Improvetimeliness of blacklist updatesVSAvoidlack of labeled fraud data
Core Design Contradiction:
Duration of action of stationary objectVSLoss of information

Solution Approach 1:

Instead of waiting for explicit fraud confirmation (successful fraudulent transactions), the system inverts the approach by using failed authentication attempts as the primary data source. By analyzing patterns in failures rather than successes, the system generates malicious identity profiles without requiring labeled fraud data or explicit customer confirmation of fraud.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system creates a feedback mechanism that extracts valuable information from failed authentication attempts rather than requiring successful fraud cases. The feedback loop analyzes failure patterns, identifies malicious behavior, and generates profiles autonomously, eliminating the dependency on explicit fraud feedback while maintaining current and accurate blacklists.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9509688B1Providing malicious identity profiles from failed authentication attempts involving biometrics
Publication Date: 2016.11.29 EMC IP HLDG CO LLC
  • US9509688B1 patent drawing
  • US9509688B1 patent drawing
  • US9509688B1 patent drawing

AI summary

A technique provides malicious identity profiles. The technique involves storing unsuccessful authentication entries in a database, the unsuccessful authentication entries including (i) descriptions of failed attempts to authenticate users and (ii) biometric records captured from the users during the failed attempts to authenticate the users. The technique further involves generating a set of malicious identity profiles based on the descriptions and the biometric records of the unsuccessful authentication entries stored in the database. Each malicious identity profile includes a profile biometric record for comparison with new biometric records during new authentication attempts. The technique further involves outputting the set of malicious identity profiles. Such a set of malicious identity profiles is well suited for use in future authentication operations, i.e., well suited for predicting intruder attacks and fraud attempts, and for sharing risky identities among authentication systems (e.g., among different security products within a cybercrime detection network).