Mobile Device Security via Behavior-Based Event Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device security systems are limited in their ability to monitor and respond to both secure and non-secure events, often requiring user reporting and network connectivity to secure the device, which can lead to delayed protection of sensitive information in case of loss or theft.

Innovation Solution

A system that employs an authentication module and behavior module to apply rules to determine if events are secure or non-secure, authenticating and authorizing access to applications and data, and updating rule data to secure the device if unauthorized access is detected, allowing for secure device operation even without network connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current security systems require user reporting and network connectivity to secure the device, then the device can be locked or wiped remotely, but the protection is delayed and requires user action and network availability

Engineering Contradiction:
Improvedevice securityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security system automatically monitors user behavior patterns and detects anomalies without requiring user reporting. The device self-secures by locking or wiping data when suspicious behavior is detected, eliminating the need for user action and network connectivity to initiate protection

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes baseline behavior patterns during normal use and prepares security rules in advance. When anomalies are detected, pre-configured security actions are immediately executed without waiting for user reporting or network commands, enabling proactive protection

Inventive Principle:
Principle #10Preliminary action

2Reliability

If limited predefined events are monitored for security, then the system can operate without network connectivity, but the security mechanism is very limited and not robust

Engineering Contradiction:
Improvesecurity robustnessVSAvoidevent monitoring complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically adapts security monitoring by learning normal user behavior patterns over time and adjusting what constitutes suspicious activity. The behavior module continuously updates baseline patterns and modifies security rules based on observed behavior, enabling robust security without requiring complex predefined event lists

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops where security events are monitored, analyzed against behavior patterns, and used to update future security decisions. The behavior module learns from each security event and adjusts monitoring sensitivity, creating a self-improving security mechanism that becomes more robust over time

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8789136B2Securing a device based on atypical user behavior
Publication Date: 2014.07.22 AVAYA INC
  • US8789136B2 patent drawing
  • US8789136B2 patent drawing
  • US8789136B2 patent drawing

AI summary

A system and method for securing the mobile device applies the rules to determine if an event associated with an application is a secure event. If the event is a secure event, the system applies the rules to determine if the event is authenticated. If the event is authenticated, the event is authorized and the system updates rule data associated with the event and/or other associated events. Updating the rule data allows other associated events to be authenticated. If the event is not authenticated, the system requests authentication from a user. If the authentication is valid, the event is authorized and the system updates the rule data associated with the event and/or other associated events. If the authentication is not valid, the system secures the mobile device. Authorizing the event enables a user to access the application and/or data associated with the application.