Personalized inferred authentication for virtual assistance

US10187394B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10187394-B2
Application numberUS-201615087777-A
CountryUS
Kind codeB2
Filing dateMar 31, 2016
Priority dateMar 31, 2016
Publication dateJan 22, 2019
Grant dateJan 22, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Aspects of the technology described herein provide a mechanism for controlling access to secure computing resources based on inferred user authentication. A current user may be authenticated and access to secure computing resources permitted based on a determined probability that the current user is a legitimate user associated with the secure computing resource. Legitimacy of the current user may be inferred based on a comparison of user-related activity of the current user to a persona model, which may comprise behavior patterns, rules, or other information for identifying a legitimate user. If it is determined that the current user is likely legitimate, then access to secure information may be permitted. However, if it is determined that the current user is likely illegitimate, than a verification procedure may be provided to the current user, such as a temporal, dynamic security challenge based on recent activity conducted by the legitimate user.

First claim

Opening claim text (preview).

The invention claimed is: 1. A computing device comprising a computer memory and a computer processor that is configured to allow a personal digital assistant to control access to secure computing resources based on a measure of legitimacy for a current user, the computing device comprising: the personal digital assistant that is a computer program stored on the computer memory having computer instructions that when executed by the computer processor cause the personal digital assistant to: monitor ongoing user-related activity for a user associated with a current user-session on the computing device; determine an authentication confidence score for the user associated with the current user-session on the computing device, the authentication confidence score determined based on a comparison of information from the monitored ongoing user-related activity and a persona model corresponding to a legitimate user associated with the computing device, wherein the persona model comprises activity patterns of the legitimate user, and wherein the authentication confidence score is determined from the monitored ongoing user-related activity and the persona model by an application or service to be used when the current user attempts to access secure data, applications, or services; receive an indication of a request to access a first secure computing resource from a set of secure computing resources; if the determined authentication confidence score indicates the current user is likely the legitimate user, then granting access to the first secure computing resource; and if the determined authentication confidence score does not indicate that the current user is likely to be the legitimate user, then restricting access to the set of secure computing resources, wherein the persona model is determined from user-related activity information of the legitimate user. 2. The computing device of claim 1 , wherein the user-related activity information of the legitimate user used for determining the persona model comprises information detected via the computing device including one or more of a geographical location, a venue, a communication network, browsing history, application-usage history, or calling history. 3. The computing device of claim 2 , wherein the persona model comprises one or more patterns of user-activity for the legitimate user, and wherein determining the authentication confidence score determined based on the comparison comprises determining a statistical indication of difference between the monitored user-related activity and the one or more patterns of user-activity for the legitimate user. 4. The computing device of claim 1 , wherein the first secure computing resource comprises at least one of a credential associated with the legitimate user, sensitive data associated with the legitimate user, a financial application or service, a purchase transaction, or a security setting associated with the computing device, and wherein at least two secure computing resources in the set of secure computing resources are unrelated. 5. The computing device of claim 1 , wherein the authentication confidence score indicates the current user is likely the legitimate user if the authentication confidence score satisfies a first threshold, and wherein the authentication confidence score does not indicate that the current user is likely to be the legitimate user if the authentication confidence score does not satisfy the first threshold. 6. The computing device of claim 5 , wherein the first threshold is pre-determined based on the first secure computing resource. 7. The computing device of claim 1 , wherein the determined authentication confidence score does not indicate that the current user is likely to be the legitimate user, and wherein the computer instructions are further configured to: generate a security challenge based on the persona model corresponding to the legitimate user; cause the security challenge to be presented via the computing device; receive a response to the security challenge; evaluate the response to the security challenge; and update the authentication confidence score based on the received response. 8. The computing device of claim 7 , wherein the security challenge comprises one of a biometric challenge, requesting a password, a static security question, or two-factor authentication procedure. 9. The computing device of claim 7 , wherein the security challenge comprises a question and corresponding answer derived from the user-related activity information of the legitimate user. 10. The computing device of claim 9 , wherein the user-related activity information of the legitimate user comprises information determined from one or more legitimate-user user-sessions conducted by the legitimate user within the previous two weeks. 11. The computing device of claim 10 , wherein the user-related activity information of the legitimate user comprises at least one of: call history, location history, purchase history, browsing history, or social media activity. 12. The computing device of claim 1 , wherein the monitored user-related activity comprises user-related activity information provided by a third-party application, and wherein the determined authentication confidence score is weighted based on the third-party application. 13. The computing device of claim 1 , wherein the determined authentication confidence score indicates that the current user is likely to be the legitimate user, and wherein the computer instructions are further configured to update the persona model to include information from the monitored user-related activity for the current user-session on the computing device. 14. A computerized method for controlling access to secure computing resources, comprising: monitoring, during a current user session, ongoing user-related activity associated with at least one computing device; determining an initial authenticity score for a current user associated with the current user-session, the initial authenticity score determined based on a comparison of information from the monitored ongoing user-related activity and a persona model corresponding to a legitimate user associated with the at least one computing device, the initial authenticity score to be used when the current user attempts to access secure data, applications, or services; receiving a first indication of a request to access a first secure computing resource, the first secure computing resource having a corresponding first authenticity score threshold; determining that the initial authenticity score does not satisfy the first authenticity score threshold; providing a security challenge to the current user, wherein the security challenge is derived from user-related activity information of the legitimate user for one or more previous user sessions during which an authenticity score for the one or more previous user sessions was above a given threshold; receiving a response to the security challenge; based on an evaluation of the received response, updating the initial authenticity score to an updated authenticity score to be used to authenticate the current user; and based on a comparison of the updated authenticity score and the first authenticity score threshold, if the updated authenticity score satisfies the first authenticity score threshold, then providing access to the first secure computing resource; and if the updated authenticity score does not satisfy the first authenticity score threshold, then restricting access to the first secure computing resource. 15. The method of claim 14 , wherein the at least one computing d

Assignees

Inventors

Classifications

  • H04L63/102Primary

    Entity profiles · CPC title

  • G06F21/316Primary

    by observing the pattern of computer usage, e.g. typical user behaviour · CPC title

  • Location-sensitive, e.g. geographical location, GPS · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10187394B2 cover?
Aspects of the technology described herein provide a mechanism for controlling access to secure computing resources based on inferred user authentication. A current user may be authenticated and access to secure computing resources permitted based on a determined probability that the current user is a legitimate user associated with the secure computing resource. Legitimacy of the current user …
Who is the assignee on this patent?
Microsoft Technology Licensing Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/102. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 22 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).