Processing authentication requests to secured information systems using machine-learned user-account behavior profiles

US11036838B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11036838-B2
Application numberUS-201816210062-A
CountryUS
Kind codeB2
Filing dateDec 5, 2018
Priority dateDec 5, 2018
Publication dateJun 15, 2021
Grant dateJun 15, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Aspects of the disclosure relate to processing authentication requests to secured information systems using machine-learned user-account behavior profiles. A computing platform may receive an authentication request corresponding to a request for a user of a client computing device to access one or more secured information resources associated with a user account. The computing platform may capture one or more behavioral parameters and activity data associated with one or more interactions with one or more non-authenticated pages. Then, the computing platform may evaluate the one or more behavioral parameters and the activity data using a behavioral profile associated with the user account. Based on this evaluation, the computing platform may identify the authentication request as malicious and may generate and send one or more denial-of-access commands to prevent the client computing device from accessing the one or more secured information resources associated with the user account.

First claim

Opening claim text (preview).

What is claimed is: 1. A computing platform, comprising: at least one processor; a communication interface communicatively coupled to the at least one processor; and memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, from an account portal computing platform, a first authentication request corresponding to a request for a first user of a first client computing device to access one or more secured information resources associated with a first user account in a first client portal session; based on receiving the first authentication request from the account portal computing platform, capture one or more behavioral parameters associated with the first client computing device; capture first activity data associated with one or more interactions by the first client computing device with one or more non-authenticated pages hosted by the account portal computing platform; evaluate the one or more behavioral parameters associated with the first client computing device and the first activity data based on a first behavioral profile associated with the first user account; based on evaluating the one or more behavioral parameters associated with the first client computing device and the first activity data, identify the first authentication request as malicious; based on identifying the first authentication request as malicious, generate one or more denial-of-access commands directing the account portal computing platform to prevent the first client computing device from accessing the one or more secured information resources associated with the first user account; and send, via the communication interface, to the account portal computing platform, the one or more denial-of-access commands directing the account portal computing platform to prevent the first client computing device from accessing the one or more secured information resources associated with the first user account. 2. The computing platform of claim 1 , wherein capturing the one or more behavioral parameters associated with the first client computing device comprises capturing one or more of a device identifier associated with the first client computing device, device settings information associated with the first client computing device, device location information associated with the first client computing device, or at least one network address associated with the first client computing device. 3. The computing platform of claim 1 , wherein capturing the first activity data associated with the one or more interactions by the first client computing device with the one or more non-authenticated pages hosted by the account portal computing platform comprises receiving information identifying one or more requests received from the first client computing device, information identifying an order of the one or more requests received from the first client computing device, and information identifying a timing of the one or more requests received from the first client computing device. 4. The computing platform of claim 1 , wherein evaluating the one or more behavioral parameters associated with the first client computing device and the first activity data based on the first behavioral profile associated with the first user account comprises: calculating one or more first distance values between the one or more behavioral parameters associated with the first client computing device and corresponding parameters of the first behavioral profile; calculating one or more second distance values between one or more activity parameters associated with the first activity data and corresponding parameters of the first behavioral profile; comparing the one or more first distance values to at least one predefined behavioral difference threshold; comparing the one or more second distance values to at least one predefined activity difference threshold; determining that the one or more first distance values exceed the at least one predefined behavioral difference threshold or that the one or more second distance values exceed the at least one predefined activity difference threshold; and responsive to determining that the one or more first distance values exceed the at least one predefined behavioral difference threshold or that the one or more second distance values exceed the at least one predefined activity difference threshold, determining to identify the first authentication request as malicious. 5. The computing platform of claim 1 , wherein the first behavioral profile associated with the first user account comprises channel information associated with a channels dimension of the first behavioral profile, event information associated with an events dimension of the first behavioral profile, trigger information associated with a triggers dimension of the first behavioral profile, biometric information associated with a biometrics dimension of the first behavioral profile, and external information associated with an external dimension of the first behavioral profile. 6. The computing platform of claim 5 , wherein the channel information associated with the channels dimension of the first behavioral profile comprises first channel activity information identifying actions involving the first user account across one or more internal channels and second channel activity information identifying actions involving the first user account across one or more external channels. 7. The computing platform of claim 5 , wherein the event information associated with the events dimension of the first behavioral profile identifies at least one user-specific event that is automatically executable based on at least one trigger. 8. The computing platform of claim 5 , wherein the trigger information associated with the triggers dimension of the first behavioral profile identifies at least one user-specific condition set that invokes automatic execution of at least one user-specific event. 9. The computing platform of claim 5 , wherein the biometric information associated with the biometrics dimension of the first behavioral profile comprises biometric activity information identifying biometric login actions involving the first user account. 10. The computing platform of claim 5 , wherein the external information associated with the external dimension of the first behavioral profile comprises one or more of user-specific social data or user-specific digital health data. 11. The computing platform of claim 1 , wherein identifying the first authentication request as malicious comprises initiating execution of one or more automatically triggered events defined by event information and trigger information associated with the first behavioral profile associated with the first user account. 12. The computing platform of claim 1 , wherein identifying the first authentication request as malicious comprises: comparing the one or more behavioral parameters associated with the first client computing device and the first activity data to one or more malicious-user profiles; and based on comparing the one or more behavioral parameters associated with the first client computing device and the first activity data to the one or more malicious-user profiles, selecting a malicious-user profile from the one or more malicious-user profiles as a matching profile. 13. The computing platform of claim 1 , wherein sending the one or more denial-of-access commands to the account portal computing platform causes the account portal computing platform to terminate a connection with the first client computing device. 14. Th

Assignees

Inventors

Classifications

  • Location-dependent; Proximity-dependent · CPC title

  • Entity profiles · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • using biometric data, e.g. fingerprints, iris scans or voiceprints · CPC title

  • G06F21/316Primary

    by observing the pattern of computer usage, e.g. typical user behaviour · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11036838B2 cover?
Aspects of the disclosure relate to processing authentication requests to secured information systems using machine-learned user-account behavior profiles. A computing platform may receive an authentication request corresponding to a request for a user of a client computing device to access one or more secured information resources associated with a user account. The computing platform may capt…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification H04L63/0876. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 15 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).