Processing authentication requests to secured information systems based on machine-learned event profiles

US11120109B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11120109-B2
Application numberUS-201816210028-A
CountryUS
Kind codeB2
Filing dateDec 5, 2018
Priority dateDec 5, 2018
Publication dateSep 14, 2021
Grant dateSep 14, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Aspects of the disclosure relate to processing authentication requests to secured information systems based on machine-learned event profiles. A computing platform may receive an authentication request corresponding to a request for a user of a client computing device to access one or more secured information resources associated with a user account in a client portal session. The computing platform may capture one or more behavioral parameters and may generate one or more authentication prompts. Thereafter, the computing platform may receive one or more authentication prompt responses and may evaluate an event pattern. Based on evaluating the event pattern and validating the one or more authentication prompt responses, the computing platform may generate and send one or more authentication commands directing an account portal computing platform to allow access to the one or more secured information resources associated with the user account in the client portal session.

First claim

Opening claim text (preview).

What is claimed is: 1. A computing platform, comprising: at least one hardware processor; a communication interface communicatively coupled to the at least one hardware processor; and non-transitory memory storing computer-readable instructions that, when executed by the at least one hardware processor, cause the computing platform to: receive, via the communication interface, from an account portal computing platform, a first authentication request corresponding to a request for a first user of a first client computing device to access one or more secured information resources associated with a first user account in a first client portal session; based on receiving the first authentication request from the account portal computing platform, capture one or more behavioral parameters associated with the first client computing device; generate one or more authentication prompts associated with the first authentication request; receive one or more authentication prompt responses corresponding to the one or more authentication prompts associated with the first authentication request; evaluate a first event pattern associated with the first authentication request; based on evaluating the first event pattern associated with the first authentication request and validating the one or more authentication prompt responses corresponding to the one or more authentication prompts associated with the first authentication request, generate one or more authentication commands directing the account portal computing platform to allow access to the one or more secured information resources associated with the first user account in the first client portal session; send, via the communication interface, to the account portal computing platform, the one or more authentication commands directing the account portal computing platform to allow access to the one or more secured information resources associated with the first user account in the first client portal session; update a valid event pattern associated with the first user account upon sending the one or more authentication commands to the account portal computing platform; and update valid population-level authentication data maintained by the computing platform upon sending the one or more authentication commands to the account portal computing platform. 2. The computing platform of claim 1 , wherein capturing the one or more behavioral parameters associated with the first client computing device comprises logging order information identifying an order of one or more computing events associated with the first authentication request, timing information identifying a timing of the one or more computing events associated with the first authentication request, and device information identifying a device used in connection with the one or more computing events associated with the first authentication request. 3. The computing platform of claim 1 , wherein generating the one or more authentication prompts associated with the first authentication request comprises sending at least one authentication prompt to the account portal computing platform. 4. The computing platform of claim 1 , wherein generating the one or more authentication prompts associated with the first authentication request comprises sending at least one authentication prompt to at least one user device registered to the first user account. 5. The computing platform of claim 1 , wherein evaluating the first event pattern associated with the first authentication request comprises determining that the first event pattern associated with the first authentication request is a closer match to a predetermined valid event pattern than a predetermined malicious event pattern. 6. The computing platform of claim 5 , wherein the predetermined valid event pattern is generated by the computing platform based on at least one previous successful login occurrence associated with the first user account. 7. The computing platform of claim 6 , wherein the predetermined valid event pattern comprises valid order data, valid timing data, and valid device data associated with the at least one previous successful login occurrence associated with the first user account. 8. The computing platform of claim 6 , wherein the predetermined valid event pattern is generated by the computing platform based on the valid population-level authentication data. 9. The computing platform of claim 8 , wherein the predetermined malicious event pattern is generated by the computing platform based on malicious population-level authentication data. 10. The computing platform of claim 1 , wherein the non-transitory memory stores additional computer-readable instructions that, when executed by the at least one hardware processor, cause the computing platform to: prior to receiving the first authentication request from the account portal computing platform: create a first user account profile corresponding to the first user account; and register one or more user devices as being linked to the first user account. 11. The computing platform of claim 10 , wherein the non-transitory memory stores additional computer-readable instructions that, when executed by the at least one hardware processor, cause the computing platform to: prior to receiving the first authentication request from the account portal computing platform: update the first user account profile to include a valid event pattern based on a successful login occurrence associated with the first user account. 12. The computing platform of claim 11 , wherein the non-transitory memory stores additional computer-readable instructions that, when executed by the at least one hardware processor, cause the computing platform to: prior to receiving the first authentication request from the account portal computing platform: update the valid population-level authentication data maintained by the computing platform based on the successful login occurrence associated with the first user account. 13. The computing platform of claim 1 , wherein the non-transitory memory stores additional computer-readable instructions that, when executed by the at least one hardware processor, cause the computing platform to: capture activity data associated with the first client portal session; and evaluate the captured activity data using baseline activity data. 14. The computing platform of claim 13 , wherein the non-transitory memory stores additional computer-readable instructions that, when executed by the at least one hardware processor, cause the computing platform to: based on evaluating the captured activity data using the baseline activity data, continue to allow access to the one or more secured information resources associated with the first user account in the first client portal session. 15. The computing platform of claim 13 , wherein the non-transitory memory stores additional computer-readable instructions that, when executed by the at least one hardware processor, cause the computing platform to: based on evaluating the captured activity data using the baseline activity data, halt access to the one or more secured information resources associated with the first user account in the first client portal session. 16. The computing platform of claim 1 , wherein the non-transitory memory stores additional computer-readable instructions that, when executed by the at least one hardware processor, cause the computing platform to: receive, via the communication interface, from the account portal computing platform, a second authentication request corresponding to a request for a secon

Assignees

Inventors

Classifications

  • User profiles · CPC title

  • by using authentication-authorization-accounting [AAA] servers or protocols · CPC title

  • where a single sign-on provides access to a plurality of computers · CPC title

  • using biometrical features, e.g. fingerprint, retina-scan (cryptographic mechanisms or cryptographic arrangements for entity authentication using biological data H04L9/3231) · CPC title

  • Entity profiles · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11120109B2 cover?
Aspects of the disclosure relate to processing authentication requests to secured information systems based on machine-learned event profiles. A computing platform may receive an authentication request corresponding to a request for a user of a client computing device to access one or more secured information resources associated with a user account in a client portal session. The computing pla…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification G06F21/316. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Sep 14 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).