User Identity Differentiation via Behavioral Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems often mistakenly identify legitimate users accessing computerized services from new devices as potential fraud, leading to unnecessary fraud mitigation steps and 'false positive' errors, and struggle to differentiate between users and cyber-attackers, especially when users switch between hardware platforms.

Innovation Solution

A system that monitors and analyzes user interactions across multiple devices, extracts user-specific traits, and predicts behavior based on group patterns to authenticate legitimate users and detect fraudulent activities, using a combination of hardware-independent biometric and behavioral features to differentiate between users and classify interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional systems use basic authentication methods to verify user identity, then security checks are simple to implement, but the systems produce false positive errors by mistakenly identifying legitimate users as fraud

Engineering Contradiction:
Improveuser identity differentiation accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments user identification into multiple independent components: hardware configuration analysis, software environment detection, user behavior monitoring, and interaction pattern recognition. Each component contributes partial information that is combined to form a comprehensive user profile, improving identification accuracy without requiring a single complex authentication mechanism

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes multiple parameters simultaneously to create a unique fingerprint for each user: hardware identifiers, software versions, browser characteristics, interaction timing, click patterns, and navigation behavior. By monitoring changes in these parameters across multiple sessions, the system can accurately distinguish legitimate users from fraudsters while maintaining manageable complexity through modular implementation

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the system implements strict fraud mitigation measures to detect attackers, then security detection capability improves, but legitimate users experience unnecessary fraud mitigation steps

Engineering Contradiction:
Improvefraud detection reliabilityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary analysis of user characteristics during initial login attempts and early interactions, building a baseline profile before fraud mitigation is triggered. By establishing expected behavior patterns in advance, the system can later distinguish between legitimate users exploring new devices and actual fraudsters, reducing unnecessary mitigation steps while maintaining detection reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors user interactions and compares actual behavior against predicted patterns derived from historical data and group analysis. When deviations occur, the system adjusts its fraud assessment in real-time, providing feedback that allows legitimate users to complete transactions smoothly while maintaining heightened scrutiny for suspicious patterns, thus balancing security and user experience

Inventive Principle:
Principle #23Feedback

3Measurement precision

If the system monitors detailed user interactions to differentiate users, then user differentiation accuracy improves, but data processing requirements and system resources increase

Engineering Contradiction:
Improveuser behavior analysis precisionVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system extracts only the most discriminative features from user interaction data, such as timing patterns, navigation sequences, and device configuration characteristics, while discarding redundant information. By focusing computational resources on extracting and analyzing only the most informative parameters, the system achieves high user differentiation precision with reduced processing overhead and lower energy consumption

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9536071B2Method, device, and system of differentiating among users based on platform configurations
Publication Date: 2017.01.03 BIOCATCH
  • US9536071B2 patent drawing
  • US9536071B2 patent drawing
  • US9536071B2 patent drawing

AI summary

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a cyber-attacker. An end-user device interacts and communicates with a server of a computerized server (a banking website, an electronic commerce website, or the like). The interactions are monitored, tracked and logged. User Interface (UI) interferences or irregularities are introduced; and the server tracks the response or the reaction of the end-user to such interferences. The system determines whether the user is a legitimate user, or a cyber-attacker or automated script posing as the legitimate user. The system utilizes classification of users into classes or groups, to deduce or predict how a group-member would behave when accessing the service through a different type of device. The system identifies user-specific traits that are platform-independent and thus can be further monitored when the user switches from a first platform to a second platform.