Passive Security Engine for Continuous User Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device security technologies fail to provide continuous and adaptive authentication, allowing unauthorized users to access secured resources, especially when the initial authenticated user is no longer present or in a different context.
Innovation Solution
Implementing a passive security engine that uses implicit authentication methods such as facial recognition, biometrics, and behavioral analysis to continuously verify the user's identity, adjusting security levels and access based on likelihood scores and context, ensuring only the initial authenticated user maintains access to sensitive content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passive authentication is used to enable continuous verification, then security is improved, but device complexity increases
Solution Approach 1:
The system performs self-authentication by automatically analyzing user behavior patterns, device interaction characteristics, and contextual information without requiring active user participation. The authentication engine continuously verifies user identity through passive monitoring of typing patterns, mouse movements, and application usage, eliminating the need for repeated manual authentication while maintaining security.
Solution Approach 2:
The patent replaces traditional mechanical authentication systems (keyboards, biometric scanners, fingerprint sensors) with a software-based authentication engine that analyzes digital footprints and behavioral patterns. This substitution eliminates the need for additional hardware components while achieving continuous verification through software-only means, thereby improving reliability without proportionally increasing device complexity.
2Reliability
If active authentication is required for every access, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The system implements periodic authentication checks based on time intervals, context changes, or security policy requirements rather than requiring authentication for every single action. The authentication engine periodically re-evaluates user identity and access rights based on accumulated behavioral data, allowing seamless operation during trusted periods while maintaining security through scheduled verification.
Solution Approach 2:
The authentication system dynamically adjusts its verification intensity and frequency based on contextual factors such as location, time of day, application sensitivity, and user behavior consistency. When behavior patterns match expected profiles and context is trustworthy, the system operates in a permissive mode with minimal user interaction. When anomalies are detected or context changes, the system dynamically increases verification intensity, creating a flexible balance between security and ease of operation.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Example embodiments disclosed herein relate to performing a security function on an application based on processed passive user information. Applications are associated with a passive security engine. Passive user information is monitored via inputs. The passive user information is processed. A security function is performed for at least two of the applications based on the processed passive user information.