User Identity Confirmation via Output Aberration Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods, including password-based and biometric systems, are vulnerable to bypass by malicious intruders and bots, and continuous authentication methods are inefficient due to their lengthy validation processes and lack of user interaction.

Innovation Solution

A method and device that cause aberrations in computer output, such as cursor movements or character displays, to elicit responses from users, which are then compared to stored characteristics to authenticate human users and distinguish them from bots, utilizing motor control and interactive transparent continuous authentication techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If transparent continuous authentication is implemented to detect unauthorized users, then security against stolen credentials is improved, but authentication time increases and user involvement decreases

Engineering Contradiction:
Improvesecurity against stolen credentialsVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic interactive challenges during the user session rather than continuous monitoring. The authentication process occurs in discrete intervals where the system injects aberrations and evaluates user responses, reducing overall authentication time while maintaining security.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system uses the user's own natural reactions to aberrations as the authentication mechanism. The user's involuntary motor control responses serve as the authentication credential, eliminating the need for separate authentication steps and reducing time loss.

Inventive Principle:
Principle #25Self-service

2Reliability

If conventional TCA monitors user behavior continuously without interaction, then unauthorized users can be detected after credential theft, but the authentication process becomes pseudo-random and unpredictable

Engineering Contradiction:
Improvedetection of unauthorized usersVSAvoidsession predictability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system introduces controlled feedback loops by injecting aberrations and measuring user responses. This creates a supervised authentication process where the system actively probes user behavior rather than passively observing, making the authentication predictable and controllable while maintaining detection capability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary authentication checks by injecting aberrations early in the session and evaluating responses before full access is granted. This preliminary action establishes predictability and control from the outset rather than waiting for random behavior patterns to emerge.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If interactive challenges are introduced to distinguish humans from bots, then authentication accuracy is improved, but user experience complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidauthentication process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the essential authentication information from user responses to aberrations, focusing on specific motor control characteristics rather than analyzing entire user sessions. This extraction approach maintains high authentication accuracy while simplifying the processing complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the parameter being measured from complex behavioral patterns to specific motor control responses to controlled aberrations. This parameter transformation maintains authentication precision while reducing process complexity by focusing on involuntary physiological responses.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2646904B1Method and device for confirming computer end-user identity
Publication Date: 2018.08.29 BIOCATCH
  • EP2646904B1 patent drawingFigure 1A~1B
  • EP2646904B1 patent drawingFigure 2
  • EP2646904B1 patent drawingFigure 3

AI summary

The identity of an end-user operating a computer (44, 50) is confirmed by analyzing user reactions to aberrations in output. More specifically, an aberration is caused in output that the computer (44, 50) provides to an output device (54), and the end-user's response to the aberration is received, an end-user characteristic is extracted from the response and compared stored characteristic responses to find a match. A match is indicative of the identity of the computer user. It can also be checked whether, after causing an aberration in output the end-user responded differently to the output than if the output did not have the aberration. The lack of a different response can be interpreted as indicative that the end-user is a bot.