Motion-Based Touch Attestation for Mobile Emulator Spoofing Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device browser and platform authentication systems are vulnerable to spoofing attacks via device emulators, which simulate genuine user interactions, compromising security and identity verification.
Innovation Solution
A method using machine learning classifiers to analyze sensor data from mobile devices, distinguishing between genuine user interactions and emulated events by processing signals from accelerometers, gyroscopes, and touch screens, combined with biometric data if available, to verify the authenticity of touch events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If device emulator software is used to simulate mobile device environments, then accessibility and development testing are improved, but security and authentication reliability deteriorate due to spoofing attacks
Solution Approach 1:
The patent introduces motion sensors (accelerometer, gyroscope, magnetometer) as intermediary components that detect physical motion characteristics. These sensors act as a mediator between the user's physical actions and the digital touch events, providing a layer of verification that distinguishes genuine user interactions from simulated emulator inputs. The sensor data serves as an intermediary proof of authentic physical presence and action.
Solution Approach 2:
The patent replaces traditional software-based touch simulation with hardware-based motion sensing. Instead of relying solely on software emulators to simulate touch events, the system uses mechanical motion sensors to detect actual physical movements of the device during user interaction. This substitution of mechanical detection for software simulation provides a more reliable authentication mechanism that is difficult to fake.
2Device complexity
If traditional touch event validation is used, then system simplicity is maintained, but vulnerability to spoofing attacks increases
Solution Approach 1:
The patent merges multiple data sources (touch screen coordinates, accelerometer data, gyroscope orientation, magnetometer directional information) into a unified authentication system. By combining these diverse sensor inputs, the system creates a comprehensive verification mechanism that validates touch events based on multiple independent criteria, making spoofing attacks significantly more difficult while maintaining reasonable system complexity.
Solution Approach 2:
The patent performs preliminary validation of motion characteristics before accepting touch events for authentication. The system analyzes motion sensor data in advance to establish baseline patterns and detect anomalies, preparing verification criteria before the actual authentication occurs. This preliminary action allows the system to preemptively identify and reject spoofed events before they can compromise security.
Data Source
AI summary
Methods of verifying a genuine presence and identity of a user of a mobile device include analyzing a stream of data from sensors of the mobile device over a period spanning a user press of a button displayed on a touch screen of the device. Results of the analysis are used to distinguish a genuine user button press from a simulated event generated by device emulation software or other simulation tool. The presence and identity verification are determined in part by the results of the sensor stream analysis, optionally in conjunction with an analysis of biometric data captured by the mobile device when the press of a button on the device touch screen has been elicited. The biometric data may include capture of imagery of a user face or body part by a camera of the mobile device.


