Use-based Security Challenge Authentication for Electronic Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication mechanisms for devices are cumbersome when users forget log-in credentials, often requiring external accounts or factory resets, which can result in data loss and are inefficient.

Innovation Solution

Implementing use-based security challenge authentication, where usage frequency metrics are collected to generate personalized security challenges based on critical device features, allowing users to access devices without losing data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication mechanisms (password, MFA) are used, then security is maintained, but user access becomes cumbersome and time-consuming when credentials are forgotten

Engineering Contradiction:
Improveease of device accessVSAvoidtime required for authentication
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary action by collecting and storing usage frequency metrics for device features in advance, creating a profile of the user's typical behavior patterns. This pre-collected data enables rapid authentication without requiring users to remember complex credentials, as the system can quickly compare current access attempts against the stored usage patterns to determine authorization.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If factory reset is used to recover access, then device security is restored, but user data is lost

Engineering Contradiction:
Improvesecurity restorationVSAvoiddata loss
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The system introduces an intermediary mechanism - usage frequency metric analysis - that mediates between security requirements and data preservation. Instead of requiring a factory reset to restore security, the system analyzes usage patterns to determine whether an access request is legitimate, thereby restoring security through intelligent authentication rather than destructive reset operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If usage frequency metrics are collected for all features, then authentication accuracy is improved, but system complexity and data processing requirements increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies local quality by selectively monitoring and collecting usage frequency metrics only for specific device features and functions that are most relevant to authentication, rather than tracking all possible operations. This targeted approach maintains authentication accuracy for critical access decisions while reducing the overall complexity of data collection and processing requirements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240095319A1Use-based security challenge authentication
Publication Date: 2024.03.21 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20240095319A1 patent drawing
  • US20240095319A1 patent drawing
  • US20240095319A1 patent drawing

AI summary

Aspects of the present disclosure relate to use-based security challenge authentication. Usage frequency metrics for features of an electric device can be collected over time. A set of critical features can be determined based on the collected usage frequency metrics, where each critical feature has a usage frequency exceeding a usage frequency threshold. A determination can be made whether a condition is met for use-based authentication. In response to determining that the condition is met for use-based authentication, a use-based security challenge can be generated using a critical feature, the use-based security challenge based on use frequency of the critical feature. The generated use-based security challenge can be presented to the user. A response to the use-based security challenge can be received. A sufficiency of the response to the use-based security challenge can be determined. Access to the electronic device can be authorized based on a sufficiency of the response.