Systems and methods for cloud-based continuous multifactor authentication

US11334658B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11334658-B2
Application numberUS-202016747080-A
CountryUS
Kind codeB2
Filing dateJan 20, 2020
Priority dateJan 20, 2020
Publication dateMay 17, 2022
Grant dateMay 17, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Disclosed is an apparatus performing a method including: receiving, from an apparatus including a housing arranged to hold a personal communication device used by a user, a notification indicating a first authentication score of the user is below a first pre-determined threshold, providing a challenge to the personal communication device. In some embodiments, the challenge is selected based on one or more sensor data obtained by at least one of the apparatus or the personal communication device. In some embodiments, the method includes calculating a second authentication score based on a response to the challenge, and causing the apparatus, to gate electronic access to the personal communication device based on whether the second authentication score is above a second pre-determined threshold.

First claim

Opening claim text (preview).

What is claimed is: 1. A system comprising: an apparatus including a housing arranged to hold a personal communication device; a plurality of sensors, at least partially supported by the housing, operable to receive trait data of a user of the personal communication device; and a server, in communication with the apparatus, operable to: receive, from the apparatus, a notification indicating a first authentication score of the user is below a first pre-determined threshold; provide a challenge to the personal communication device, wherein the challenge is selected based on one or more sensor data obtained by at least one of the apparatus or the personal communication device; calculate a second authentication score based on a response to the challenge; and cause the apparatus to gate electronic access to resources associated with the personal communication device based on whether the second authentication score is above a second pre-determined threshold. 2. The system of claim 1 , wherein the server is further operable to: assign a set of weights to the response, wherein the response includes a set of trait data; and calculate the second authentication score based on the set of trait data and the set of weights. 3. The system of claim 2 , wherein the set of weights is assigned based on at least one of a context, a sensor data, and aggregated data from a plurality of apparatuses, and wherein each of the plurality of apparatuses includes a respective housing arranged to hold a respective personal communication device. 4. The system of claim 3 , wherein the at least one of the context or the sensor data is at least one of whether the user is moving, a proximity between the user and the personal communication device, and a proximity between the user and the housing. 5. The system of claim 1 , wherein the server is further operable to: establish a local communication channel to the personal communication device; and obtain the response from the personal communication device via the local communication channel, wherein the local communication channel is a secure channel. 6. The system of claim 1 , wherein the challenge is selected based on at least one of a random challenge selected from a plurality of pre-defined challenges, a challenge selected based on a context, or a pre-configured challenge. 7. The system of claim 1 , wherein the server is further operable to obtain the one or more sensor data from one or more of a plurality of sensors, and wherein the plurality of sensors is located at least on one of: the apparatus, a backpack attached to the apparatus, or the personal communication device. 8. The system of claim 1 , wherein the server is further operable to gate electronic access by at least one of allowing full access to the personal communication device, or allowing access to pre-determined parts of the personal communication device. 9. A method comprising: receiving, from an apparatus including a housing arranged to hold a personal communication device used by a user, a notification indicating a first authentication score of the user is below a first pre-determined threshold; providing a challenge to the personal communication device, wherein the challenge is selected based on one or more sensor data obtained by at least one of the apparatus or the personal communication device; calculating a second authentication score based on a response to the challenge; and causing the apparatus, to gate electronic access to resources associated with the personal communication device based on whether the second authentication score is above a second pre-determined threshold. 10. The method of claim 9 , further comprising: assigning a set of weights to a set of trait data included in the response; and calculating the second authentication score based on the set of trait data and the set of weights. 11. The method of claim 10 , wherein the set of weights is assigned based on at least one of a context, a sensor data, or aggregated data from a plurality of apparatuses, and wherein each of the plurality of apparatuses includes a respective housing arranged to hold a respective personal communication device. 12. The method of claim 11 , wherein the at least one of the context or the sensor data is at least one of whether the user is moving, a proximity between the user and the personal communication device, or a proximity between the user and the housing. 13. The method of claim 9 , wherein the notification is received via a secure communication channel. 14. The method of claim 9 , further comprising: establishing a local communication channel to the personal communication device; and obtaining a set of the trait data from the personal communication device via the local communication channel. 15. The method of claim 9 , wherein the challenge is generated by at least one of the housing, or a secure server in communication with the apparatus, and wherein the generated challenge is sent through a secure communication channel. 16. The method of claim 9 , wherein the challenge is selected based on at least one of a random challenge selected from a plurality of pre-defined challenges, a challenge selected based on a context, or a pre-configured challenge. 17. The method of claim 9 , wherein the one or more sensor data are obtained from one or more of a plurality of sensors, and wherein the plurality of sensors is located at least on one of: the housing, a backpack attached to the apparatus, or the personal communication device. 18. The method of claim 9 , wherein the first pre-determined threshold is different from the second pre-determined threshold. 19. The method of claim 9 , wherein the first pre-determined threshold is same as the second pre-determined threshold. 20. The method of claim 9 , wherein gating the electronic access includes at least one of allowing full access to the personal communication device, or allowing access to pre-determined parts of the personal communication device.

Assignees

Inventors

Classifications

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • Challenge-response · CPC title

  • G06F21/43Primary

    wireless channels · CPC title

  • communicating wirelessly · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11334658B2 cover?
Disclosed is an apparatus performing a method including: receiving, from an apparatus including a housing arranged to hold a personal communication device used by a user, a notification indicating a first authentication score of the user is below a first pre-determined threshold, providing a challenge to the personal communication device. In some embodiments, the challenge is selected based on …
Who is the assignee on this patent?
Ppip Llc
What technology area does this patent fall under?
Primary CPC classification G06F21/43. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 17 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).