Device, system, and method of password-less user authentication and password-less detection of user identity

US10476873B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10476873-B2
Application numberUS-201615051700-A
CountryUS
Kind codeB2
Filing dateFeb 24, 2016
Priority dateNov 29, 2010
Publication dateNov 12, 2019
Grant dateNov 12, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting possible attackers; as well as password-less user authentication, and password-less detection of user identity. A system or a computing device requires a user to perform a particular unique non-user-defined task, the task optionally being an on-screen connect-the-dots task. The system monitors user interactions, extracts user-specific features that characterizes the manner in which the user performs the tasks; and subsequently relies on such user-specific features as a means for user authentication, optionally without utilizing a password or passphrase. Optionally, a user interface anomaly or interference is intentionally introduced in order to elicit the user to perform corrective gestures, which are optionally used for extraction of additional user-specific features.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: differentiating between a first human user and a second human user of a computerized service via a password-less user-authentication process, by performing: (a) selecting, from a pool of task attributes, a particular set of task attributes; wherein the set of task attributes comprises at least: (i) a particular shape for on-screen tracing, and (ii) at least one other task attribute; and automatically generating on-the-fly a particular unique and non-user-defined task, that is intended to be repeatedly performed by a specific user via an input unit of an electronic device; (b) generating the unique and non-user-defined task, in which said specific user is requested to perform gestures that correspond to said task, wherein said generating comprises presenting to said specific user instructions on how to complete said task without requiring said user to remember or memorize any data-item or password or Personal Identification Number (PIN); and collecting user interactions data via the input unit while the user is performing the task; (c) repeating step (b) for at least N iterations for said specific user, wherein said same unique and non-user-defined task is repeated in each one of said iterations, wherein N is a positive integer; and wherein said same unique and non-user-defined task is consistently repeated across multiple log-in sessions of said specific user; (d) during step (b) and during step (c), determining from said user interactions data a user-specific cognitive behavioral biometric profile that characterizes a cognitive behavioral manner in which said user repeatedly performs said same unique and non-user-defined task across said N iterations; (e) storing the user-specific cognitive behavioral profile in a repository, indicating that said user-specific cognitive behavioral profile is associated with at least one of: (i) said specific user, (ii) said electronic device; (f) subsequently, generating said same unique and non-user-defined task again upon a subsequent request of a user to access said computerized service, and collecting fresh user interactions data from fresh performance of said task; (g) if the fresh user interactions data that was collected from said fresh performance of said same unique and non-user-defined task, does not match the previously-stored user-specific cognitive behavioral biometric profile, then un-authorizing access of the user to the computerized service. 2. The method of claim 1 , wherein the task is unique to said user relative to all other users of the computerized service; wherein in step (g), for user authentication, the method takes into account a manner of performance of said specific task in conjunction with analysis of a captured photo of the user during said fresh performance of said task. 3. The method of claim 1 , wherein the task is unique to said electronic device relative to all other electronic devices that access the computerized service. 4. The method of claim 1 , wherein the task is both (i) unique to said electronic device relative to all other electronic devices that access the computerized service, and (ii) unique to said user relative to all other users of the computerized service. 5. The method of claim 1 , wherein the task comprises an on-screen dot-connecting task; wherein the method comprises: detecting that a first user connected a first dot with a second dot in said task via a straight line; detecting that a second user connected the first dot with the second dot in said task via a curved line; and based on said detecting operations, distinguishing between said first user and said second user. 6. The method of claim 1 , wherein the task comprises an on-screen dot-connecting task in which all dots are visible to the user immediately upon commencement of the task; wherein the method comprises: detecting that a first user completed said task in T1 seconds; detecting that a second user completed said task in T2 seconds; and based on said detecting operations, distinguishing between said first user and said second user. 7. The method of claim 1 , wherein the task comprises an on-screen dot-connecting task in which only a single dot is visible to the user immediately upon commencement of the task, and each subsequent dot is exposed to the user gradually as the user connects each dot that was exposed to him. 8. The method of claim 1 , wherein the task is generated by selecting at least: a particular shape from a pool of available shapes, a particular scale from a pool of available scales, a particular number of dots from a number-of-dots pool. 9. The method of claim 1 , comprising: while the user is performing the task, introducing an input/output interference that triggers the user to perform corrective gestures; extracting one or more user-specific features from said corrective gestures; taking into account said one or more user-specific features, that were extracted from said corrective gestures, during at least one of these steps: (i) during constructing the reference user-specific behavioral signature; (ii) during constructing the fresh user-specific behavioral signature. 10. The method of claim 1 , comprising: during a first K usage-sessions of the user with the computerized service, wherein K is a positive integer: (a) requiring the user to both enter a password and to perform the task; (b) relying on the password for user authentication towards the computerized service; (c) not-relying on the task for user authentication towards the computerized service; starting at the K+1 usage-session of the user with the computerized service: enabling the user to authenticate towards the computerized service without entering any password, if the user performs the task in a manner that matches the reference user-specific behavioral profile. 11. The method of claim 1 , comprising: during a first K usage-sessions of the user with the computerized service, wherein K is a positive integer: (a) requiring the user to both enter a password and to perform the task; (b) relying on the password for user authentication towards the computerized service; (c) not-relying on the task for user authentication towards the computerized service; upon completion of the first K usage-sessions, discarding the password; starting at the K+1 usage-session of the user with the computerized service: enabling the user to authenticate towards the computerized service without entering any password, if the user performs the task in a manner that matches the reference user-specific behavioral profile. 12. The method of claim 1 , wherein said task is utilized for user authentication in addition to requiring the user to manually enter a password. 13. The method of claim 1 , wherein said task is utilized for user authentication instead of requiring the user to manually enter a password. 14. The method of claim 1 , wherein said task is utilized for user authentication as a condition for granting access to the user to a physical location. 15. The method of claim 1 , wherein said task is utilized for user authentication as a condition for granting access to the user to a vehicle. 16. The method of claim 1 , wherein said task is utilized for user authentication as part of a multi-factor authentication process. 17. The method of claim 1 , wherein said task is utilized as a secret question that the user is required to successfully perform in order to reset user credentials. 18. The method of claim 1 , wherein collecting the user interactions dat

Assignees

Inventors

Classifications

  • by observing the pattern of computer usage, e.g. typical user behaviour · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • User authentication · CPC title

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • Verifying human interaction, e.g., Captcha · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10476873B2 cover?
Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting possible attackers; as well as password-less user authentication, and password-less detection of user identity. A system or a computing device requires a user to perform a particular unique non-user-defined task, the task optionally being an on-screen connect-the-dots…
Who is the assignee on this patent?
Biocatch Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/0861. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 12 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).