Typing Cadence Authentication via Biometric Passphrases
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Classic password authentication methods are vulnerable to discovery, inference, and hacking, and while passphrase solutions exist, they require users to remember complex strings, which is frustrating and does not significantly enhance security.
Innovation Solution
The Passphrase system learns a user's typing cadence and muscle patterns, generating one-time authentication challenges that do not require remembering a password, using a combination of typing metrics and sentence construction to create phrases that are statistically matched during authentication, eliminating the need for password remembrance and expiration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If classic password authentication is used, then security is compromised due to vulnerability to discovery and hacking, but user convenience is maintained through simple memorization
Solution Approach 1:
The patent replaces the traditional password-based authentication system with a biometric-based system that analyzes typing cadence, gesture dynamics, and QR code scanning patterns. This substitutes the mechanical/password-based verification with a physiological/behavioral verification system, eliminating vulnerabilities to hacking and discovery while maintaining high reliability.
Solution Approach 2:
The system automatically collects and analyzes user typing and gesture data without requiring explicit user input or configuration. The authentication model is built passively from normal user interactions, and the system self-adjusts to recognize legitimate users while detecting anomalies, providing both security and convenience without user burden.
2Reliability
If passphrase solutions are implemented, then security is improved, but user frustration increases due to the need to remember complex strings
Solution Approach 1:
The patent replaces the cognitive burden of remembering complex passphrases with an automatic biometric verification system. The system analyzes typing cadence, gesture dynamics, and QR code scanning patterns to authenticate users, eliminating the need for users to memorize complex strings while maintaining or improving security.
Solution Approach 2:
The authentication system automatically builds and updates user profiles from normal typing and gesture interactions without requiring users to consciously remember or input authentication data. The system handles the entire authentication process transparently, improving ease of operation while maintaining security.
3Ease of manufacture
If traditional password systems are used, then implementation is simple, but security vulnerabilities persist due to password reuse and expiration requirements
Solution Approach 1:
The patent replaces traditional password storage and verification mechanisms with a biometric analysis system that processes typing cadence, gesture dynamics, and QR code scanning patterns. This substitution eliminates security vulnerabilities associated with password reuse and expiration while maintaining implementation feasibility through integration with existing input devices and software.
Data Source
AI summary
Disclosed herein are techniques for authenticating a user via gestures, QR codes, and passphrases generated to incorporate typing habits of the user. A passphrase system generates a one-time use passphrase, which incorporates hallmarks and/or quirks of the user's typing, and presents the generated passphrase as an authentication challenge to authenticate as the user. If metrics collected during the authentication challenge are statistically similar to metrics of the user's typing, the authentication succeeds; otherwise, the authentication fails. A user's gesture habits during input of an authentication drawing may be used as a target for future authentication attempts. A user's input motions (typing and/or gestures) may be converted into a secure QR code; a different host device may use the secure QR code to obtain the target metrics for future authentication attempts of the user.


