Post-Authentication User Verification via Interaction Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cybersecurity solutions, such as antivirus and firewall systems, often fail to keep pace with new threats in industrial environments, making it difficult for organizations to protect their networks and systems from intrusions, as they primarily rely on known threats and configurations, leaving vulnerabilities unaddressed.

Innovation Solution

Implementing post-authentication user verification based on user interactions by collecting metadata during valid user sessions to create profiles of typical interactions, which are then compared to subsequent sessions to detect anomalies, indicating potential malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cybersecurity solutions (antivirus, firewall) are used, then protection against known threats is provided, but they cannot keep pace with new threats and leave vulnerabilities unaddressed

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidability to respond to new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by collecting user interaction data during authenticated sessions and generating behavioral profiles before threats occur. These profiles establish a baseline of normal user behavior that enables the system to detect anomalies and potential threats in real-time, rather than relying solely on post-incident response or pre-configured security rules.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where user interactions are monitored, compared against established profiles, and used to dynamically adjust security assessments. When anomalies are detected, the system can trigger additional verification steps or alerts, creating a responsive security mechanism that adapts to observed behavior patterns rather than relying on static security configurations.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If post-authentication user verification based on interaction analysis is implemented, then detection of unauthorized access is improved, but system complexity increases

Engineering Contradiction:
Improveuser session validation accuracyVSAvoidverification system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system employs self-service mechanisms by automatically collecting user interaction data, generating behavioral profiles, and performing anomaly detection without requiring manual configuration or intervention. The profiles are created and maintained autonomously based on observed user patterns, reducing the operational burden while maintaining high validation accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system applies partial verification by focusing on specific interaction patterns and behaviors that are most indicative of unauthorized access, rather than analyzing every possible user action. This selective approach maintains high detection precision while avoiding the complexity of comprehensive analysis of all user activities.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3547185A3Apparatus and method for post-authentication user verification based on user interactions
Publication Date: 2019.11.27 HONEYWELL INTERNATIONAL INC
  • EP3547185A3 patent drawing
  • EP3547185A3 patent drawing
  • EP3547185A3 patent drawing

AI summary

A method includes obtaining (702) first data identifying first user interactions with one or more computing or networking resources during at least one first user session that is known to be valid. The method also includes generating (704) one or more profiles defining typical user interactions with the one or more resources based on the first data. The method further includes obtaining (708) second data identifying second user interactions with at least one of the one or more resources during a subsequent second user session. The method also includes determining (712) whether the second user session is valid based on the second data and at least one of the one or more profiles by comparing the second user interactions to the typical user interactions defined in the at least one profile. In addition, the method includes taking (714, 716) one or more actions in response to determining that the second user session is not valid.