Method for automatic possession-factor authentication

US10708776B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10708776-B2
Application numberUS-201715707095-A
CountryUS
Kind codeB2
Filing dateSep 18, 2017
Priority dateJun 2, 2016
Publication dateJul 7, 2020
Grant dateJul 7, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods are provided that include: accessing implicit authentication data from a possession factor associated with an authorized user; at the possession factor or at an authentication platform: generating a possession confidence level using the implicit authentication data, the possession confidence level being one of a plurality of possession confidence levels, the possession confidence level indicating a likelihood that the possession factor is possessed by the authorized user; identifying, among a plurality of varying authentication requirements, an authentication requirement for the transaction based on the possession confidence level, the authentication requirement defines a process or action to prove authority to perform the transaction or a process or action to prove an identity of a user attempting to perform the transaction; and implementing the authentication requirement for the transaction.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for authentication using implicit authentication data, the system comprising: an authentication platform comprising a remote hardware computing server comprising one or more computing processors and one or more non-transitory storage media storing computer instructions that, when executed by the one or more computing processors perform: receiving, via one or more communication networks, an authentication request that initiates an implicit authentication process for a transaction requiring authentication, wherein the authentication request is generated by a service provider, separate from the authentication platform, in response to receipt of an access request from an unauthorized device, and wherein the implicit authentication process includes passively authenticating a user based on whether implicit authentication data obtained from a possession factor indicates a calculated likelihood that the user has possession of the possession factor, wherein the possession factor comprises one or more user authentication credentials; receiving, via the one or more communication networks, implicit authentication data from the possession factor, wherein the implicit authentication data includes data relating to activities involving the possession factor and/or a present state of the possession factor that enables a determination of whether the possession factor is currently or was recently in possession of the user, wherein the implicit authentication data is generated or provided without intervention by the user of the possession factor; using the implicit authentication data from the possession factor to determine a likelihood of possession of the possession factor by the user based on a possession factor continuum that informs authentication requirements for authenticating the user, the possession factor continuum comprising a plurality of possession confidence thresholds, wherein each of the plurality of possession confidence thresholds corresponds to a different authentication requirement for authenticating the user, and wherein one or more of the possession confidence thresholds relate to unsuccessful access attempts; and implicitly authenticating the user if the likelihood of possession satisfies a possession confidence threshold of the possession factor continuum that enables implicit authentication of the user, wherein the implicit authentication of the user does not require an explicit authentication response from the user. 2. The system of claim 1 , further at the authentication platform: wherein if it is determined that the user is not currently or was not recently in possession of the possession factor, selectively changing from the implicit authentication to an express authentication requiring user-interactive authentication at the possession factor that requires receiving user authentication input interaction with the possession factor and an explicit authentication response from the user. 3. The system of claim 1 , wherein further at the authentication platform: generating a likelihood of possession of the possession factor by the user, wherein the likelihood of possession comprises a probability value or a confidence level indicating a probability or confidence that the possession factor is possessed by the user, wherein the generating the likelihood of possession includes: (i) selectively parsing, by the authentication platform, determinative data from the implicit authentication data that indicates a likely possession or that indicates a potential lack of possession of the possession factor by the user from the implicit authentication data thereby generating a subset of the implicit authentication data, (ii) applying one or more analysis techniques or transformation techniques to the subset of the implicit authentication data to determine possession insights relating to the likely possession or the lack of possession of the possession factor, and (iii) calculating the probability value or the confidence level for the likelihood of possession using the subset of the implicit authentication data and the possession insights. 4. The system of claim 1 , wherein further at the authentication platform: wherein receiving the implicit authentication request is initialized by a transmission provided midstream of a primary authentication, the transmission indicating that a primary authentication is being performed at a service provider for authenticating the transaction wherein the primary authentication is: (i) performed independent of the implicit authentication process using the implicit authentication data and (ii) performed by the service provider, the service provider being independent of the authentication platform. 5. A method for performing authentication, the method comprising: receiving, via one or more communication networks, an implicit authentication request, wherein the implicit authentication request is generated by a service provider in response to an access request from an unauthorized device; responsive to receiving the implicit authentication request, accessing, by a remote computing server, implicit authentication data from a possession factor associated with an authorized user of the possession factor, the implicit authentication data comprising data that is automatically collected or automatically generated by the possession factor, without user intervention, and that relates to a calculated likelihood of the user performing one or more activities involving an operation and/or a usage of the possession factor, wherein the possession factor comprises one or more user authentication credentials; at the remote computing server: using only the implicit authentication data to determine a likelihood of possession of the possession factor by the authorized user based on a possession factor continuum that informs authentication requirements for authenticating the user, the possession factor continuum comprising a plurality of possession confidence thresholds, wherein each of the plurality of possession confidence thresholds corresponds to a different authentication requirement for authenticating the user, and wherein one or more of the possession confidence thresholds relate to unsuccessful access attempts; and automatically authenticate the authorized user if the determined likelihood of possession satisfies a possession confidence threshold of the possession factor continuum that enables implicit authentication of the user. 6. The method of claim 5 , further comprising: receiving a possession-factor authentication request, the receiving of the possession-factor authentication request triggering an initialization of the implicit authentication based on the possession factor. 7. The method of claim 6 , wherein the possession-factor authentication request comprises an indication that a primary authentication separate from the implicit authentication was performed successfully or is being performed on a basis of authentication data provided expressly by the user. 8. The method of claim 5 , further comprising: generating a likelihood of possession of the possession factor by the user, wherein the likelihood of possession comprises a probability value or a confidence level indicating a probability or confidence that the possession factor is possessed by the user, wherein the generating the likelihood of possession includes: (i) selectively parsing determinative data from the implicit authentication data that indicates a likely possession or that indicates a potential lack of possession of the possession factor by the user from the implicit authentication data thereby generating a subset of the implicit authentication data, (ii) applying one or more analysis techniques or transformation techniques to the

Assignees

Inventors

Classifications

  • Probabilistic graphical models, e.g. probabilistic networks · CPC title

  • using geofenced areas · CPC title

  • Gesture-dependent or behaviour-dependent · CPC title

  • Location-dependent; Proximity-dependent · CPC title

  • Establishing or using transaction specific rules · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10708776B2 cover?
Systems and methods are provided that include: accessing implicit authentication data from a possession factor associated with an authorized user; at the possession factor or at an authentication platform: generating a possession confidence level using the implicit authentication data, the possession confidence level being one of a plurality of possession confidence levels, the possession confi…
Who is the assignee on this patent?
Duo Security Inc
What technology area does this patent fall under?
Primary CPC classification H04W12/06. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 07 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).