Behavior-Based Physiological Authentication for Secure Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for accessing physiological data from mobile, portable communication systems often rely on insecure authentication methods, such as PINs and passwords, which can be forgotten or easily guessed, and lack secure mechanisms for consent-based access to sensitive user data.

Innovation Solution

A behavior-based authentication system that uses physiological data, such as heart rate and movement patterns, to authenticate users and ensure consent for accessing their data, employing a classification module to evaluate user behavior and generate authentication signals, with optional end-to-end encryption for secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (PIN, password) are used, then access control is implemented, but security is compromised because users may forget PINs or choose weak passwords that can be easily guessed

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidease of remembering credentials
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces mechanical authentication systems (PIN entry, password typing) with a physiological-based authentication system that automatically detects user presence and identity through sensors. The system substitutes manual credential entry with automatic biometric verification, eliminating the need for users to remember complex credentials while maintaining high security through physiological data analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-authentication by automatically detecting and verifying user physiological characteristics without requiring active user participation. The sensors continuously monitor physiological parameters and the system autonomously determines authentication status, freeing users from the burden of managing authentication credentials while ensuring reliable access control.

Inventive Principle:
Principle #25Self-service

2Productivity

If physiological data is stored persistently in a storage system, then data availability is improved, but security risks increase due to potential unauthorized access

Engineering Contradiction:
Improvedata access efficiencyVSAvoidunauthorized access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication layer between the storage system and access requests. Before allowing access to stored physiological data, the system verifies the user's current physiological state through sensors and confirms identity through behavioral analysis. This intermediary verification mechanism ensures that even though data is persistently stored and easily accessible, only authenticated users can retrieve it, effectively neutralizing the security risk of persistent storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication verification before granting access to stored physiological data. By continuously monitoring physiological parameters and verifying user identity before data retrieval operations, the system ensures that authentication occurs in advance of any data access, preventing unauthorized access while maintaining efficient data availability for legitimate users.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If behavior-based authentication is implemented, then security is enhanced through physiological data verification, but system complexity increases due to classification modules and sensor integration

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework where a single integrated system handles multiple authentication functions using the same sensor array and classification module. The system can authenticate users through various physiological parameters (heart rate, temperature, movement patterns) and can adapt to different authentication scenarios without requiring separate systems for each function. This multi-functionality reduces overall system complexity compared to having dedicated systems for each authentication method.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines sensor data acquisition, physiological analysis, behavioral classification, and authentication decision-making into a single integrated system architecture. Rather than having separate modules for each function, the system merges these components into a unified authentication framework that processes multiple physiological parameters simultaneously through a single classification engine, thereby reducing system complexity while maintaining high security standards.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3477515B1Provision of physiological data
Publication Date: 2020.01.22 BUNDESDRUCKEREI GMBH
  • EP3477515B1 patent drawingFigure 1
  • EP3477515B1 patent drawingFigure 2
  • EP3477515B1 patent drawingFigure 3

AI summary

The invention relates to a device for enabling access by a computer system (400) to physiological data of a registered user of a mobile, portable communication system (100), which are persistently stored in a storage system (150).The mobile, portable communication system (100) is configured to execute the access granting procedure, which includes: • Authenticating the computer system (400) to the communication system (100) using the communication interface (140) of the communication system (100), • Behavioral authentication of the user to the communication system (100), • Generating an authentication signal by the mobile, portable communication system (100) that depends on the success of the authentication of the computer system (400) and the user, • Granting the computer system (400) access to the physiological data of the registered user persistently stored in the storage system (150), if the authentication signal indicates successful authentication of the computer system (400) and the current user, and if the user has consented to the access.