Mobile Terminal Biometric Attack Detection via Motion Sensors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric authentication systems, particularly face recognition, are vulnerable to impersonation attacks that rely on user cooperation, such as blinking or speech interaction, which can be unreliable.

Innovation Solution

A method and apparatus using sensor data from mobile terminal devices, including acceleration and gyroscope data, to detect attacks through a trained attack determination model, reducing dependence on user cooperation by processing and analyzing sensor data to determine the occurrence of attacks during authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If liveness detection methods requiring user cooperation (blink, facial expression, speech interaction) are used, then detection effectiveness is improved, but user convenience deteriorates due to high dependence on user cooperation

Engineering Contradiction:
Improvedetection effectivenessVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses sensor data (acceleration, gyroscope) that is automatically collected during normal device operation to detect attacks. The detection process does not require user cooperation as the sensors passively capture device movement characteristics that differ between genuine and spoofed authentication attempts.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces physiological behavior detection (mechanical eye movement, facial muscle movement, speech production) with sensor-based detection of device movement characteristics. This substitution uses acceleration and gyroscope data to infer authentication authenticity without requiring user action.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If existing liveness detection technologies are implemented, then security is improved, but device complexity increases due to multiple detection mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent repurposes existing motion sensors (acceleration sensor and gyroscope) that are already present in mobile devices for their primary navigation and step-counting functions to also serve liveness detection purposes. This multi-functionality approach avoids adding dedicated detection hardware while enhancing security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system leverages sensor data that is already being collected by the device for other purposes (motion tracking, step counting, device orientation) and repurposes it for attack detection, eliminating the need for separate dedicated detection hardware.

Inventive Principle:
Principle #25Self-service

3Reliability

If sensor data collection and analysis is performed, then attack detection capability is improved, but processing time increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-processes sensor data during the authentication process itself, analyzing acceleration and gyroscope readings in real-time as they are collected. This preliminary analysis of motion patterns during the authentication window allows rapid attack detection without requiring separate post-processing steps.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11288348B2Biometric authentication, identification and detection method and device for mobile terminal and equipment
Publication Date: 2022.03.29 ADVANCED NEW TECHNOLOGIES CO LTD
  • US11288348B2 patent drawing
  • US11288348B2 patent drawing

AI summary

The application provides a method for attack detection in biometric authentication. The method may be implemented by a mobile terminal device, and comprises: obtaining sensor data of the mobile terminal device, wherein the sensor data is collected when the mobile terminal device performs biometric authentication, and the sensor data comprises acceleration sensor data of the mobile terminal device indicating accelerations of the mobile terminal device in x, y, and z axes of a three-dimensional space, and/or gyroscope data of the mobile terminal device indicating angular velocities in the x, y, and z axes of the three-dimensional space; and inputting the sensor data into an attack determination model to determine whether an attack occurs in the biometric authentication, wherein the attack determination model is trained by using sensor training data obtained based on sensor data of the mobile terminal device collected when the mobile terminal device performed biometric authentication historically.