User Authentication via Behavioral Data Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

User authentication in digital communications faces challenges, particularly in remote verification over networks, where traditional methods are vulnerable to man-in-the-middle attacks and require additional security measures to ensure identity validation.

Innovation Solution

A system that authenticates user identities by utilizing data rows from trusted third-party systems, including aggregator and monitoring systems, to match user actions over time, providing a confidence score for authentication, thus enhancing security by requiring malicious actors to replicate extensive user activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods (ID and password) are used, then ease of operation is improved, but reliability is worsened due to vulnerability to man-in-the-middle attacks

Engineering Contradiction:
Improveease of authenticationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces trusted third-party systems (aggregator systems and monitoring systems) as intermediaries between the user and the authentication system. These intermediaries collect and verify behavioral data from multiple sources, creating a layered verification process that prevents direct interception attacks while maintaining user convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary data collection and analysis by gathering behavioral data from trusted third-party systems before the actual authentication moment. This pre-collection of behavioral patterns, transaction histories, and device information enables the system to establish a baseline of normal user behavior that can be compared during authentication.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If additional authentication factors are added to improve security, then reliability is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically collects behavioral data from multiple trusted third-party systems without requiring user intervention. The aggregator system autonomously gathers information from monitoring systems, analyzes behavioral patterns, and generates authentication verification, eliminating the need for users to manually provide multiple authentication factors.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication system is designed to work with multiple different trusted third-party systems simultaneously, using a unified approach to collect and analyze various types of behavioral data. This multi-functional capability allows the system to leverage diverse data sources (transactions, communications, device usage) through a single authentication framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If behavioral data from multiple trusted systems is collected and analyzed, then reliability is improved through better identity verification, but loss of time is worsened due to data matching requirements

Engineering Contradiction:
Improveidentity verification accuracyVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Behavioral data from trusted third-party systems is collected and pre-processed before authentication is needed. The system maintains up-to-date profiles of user behavioral patterns, transaction histories, and device information, so that during authentication, the system only needs to perform matching operations rather than collecting raw data from multiple sources in real-time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12099620B1User authentication
Publication Date: 2024.09.24 ROCKLOANS MARKETPLACE LLC
  • US12099620B1 patent drawing
  • US12099620B1 patent drawing
  • US12099620B1 patent drawing

AI summary

A method for authenticating a user identity linked to a user account may include receiving information that asserts a user identity including a user identifier, accessing external data stores to receive data rows that are associated with the user identity, and accessing monitoring systems to receive data vectors. The monitoring systems may monitor transmissions to receiving systems, the data vectors may include numerical target values for the receiving systems, and the data vectors may be accessed using the user identifier. The method may also include determining whether the data rows can be matched to the data vectors, and based on that determination, authenticating the user identity.