Just In Time Polymorphic Authentication

US2016259931A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016259931-A1
Application numberUS-201615157506-A
CountryUS
Kind codeA1
Filing dateMay 18, 2016
Priority dateAug 27, 2014
Publication dateSep 8, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods, systems, apparatuses, and computer-readable media for utilizing just-in-time polymorphic authentication techniques to secure information are presented. In one or more embodiments, a computing platform may receive, from a computing device, a request to access a user account. In response to receiving the request to access the user account, the computing platform may dynamically select, based on one or more polymorphic authentication factors, an authentication method for authenticating a user of the computing device, and the authentication method may be selected from a plurality of predefined authentication methods. Subsequently, the computing platform may generate one or more authentication prompts based on the selected authentication method. The computing platform then may provide the one or more authentication prompts to the user of the computing device. The authentication prompts that are selected for and presented to a particular user during a given access attempt may vary across different attempts.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method, comprising: at a computing platform comprising at least one processor, memory, and a communication interface: receiving, by the at least one processor, via the communication interface, and from a first computing device, a request to access a first user account; in response to receiving the request to access the first user account, dynamically selecting, by the at least one processor, based on one or more polymorphic authentication factors, a first authentication method for authenticating a user of the first computing device, the first authentication method being selected from a plurality of predefined authentication methods; generating, by the at least one processor, one or more authentication prompts based on the first authentication method selected for authenticating the user of the first computing device; and providing, by the at least one processor, the one or more authentication prompts to the user of the first computing device. 2 . The method of claim 1 , wherein the one or more polymorphic authentication factors comprise one or more time-based factors. 3 . The method of claim 1 , wherein the one or more polymorphic authentication factors comprise one or more counter-based factors. 4 . The method of claim 1 , wherein the one or more polymorphic authentication factors comprise one or more external risk factors. 5 . The method of claim 1 , wherein the one or more polymorphic authentication factors comprise one or more geographic factors. 6 . The method of claim 1 , wherein the one or more polymorphic authentication factors comprise one or more event-based factors. 7 . The method of claim 1 , wherein the one or more polymorphic authentication factors comprise one or more user-specific factors. 8 . The method of claim 1 , wherein providing the one or more authentication prompts to the user of the first computing device comprises: generating at least one user interface configured to receive one or more authentication credentials; and causing the at least one user interface to be presented by the first computing device. 9 . The method of claim 1 , wherein providing the one or more authentication prompts to the user of the first computing device comprises requesting the user of the first computing device to provide password input. 10 . The method of claim 1 , wherein providing the one or more authentication prompts to the user of the first computing device comprises requesting the user of the first computing device to provide one-time passcode input. 11 . The method of claim 1 , wherein providing the one or more authentication prompts to the user of the first computing device comprises requesting the user of the first computing device to provide biometric input. 12 . The method of claim 1 , wherein providing the one or more authentication prompts to the user of the first computing device comprises causing at least two authentication prompts to be presented to the user of the first computing device in a specific order determined based on the one or more polymorphic authentication factors. 13 . The method of claim 1 , comprising: receiving, by the at least one processor, via the communication interface, and from a second computing device different from the first computing device, a request to access a second user account different from the first user account; in response to receiving the request to access the second user account, dynamically selecting, by the at least one processor, based on the one or more polymorphic authentication factors, a second authentication method for authenticating a user of the second computing device, the second authentication method being selected from the plurality of predefined authentication methods; generating, by the at least one processor, one or more second authentication prompts based on the second authentication method selected for authenticating the user of the second computing device; and providing, by the at least one processor, the one or more second authentication prompts to the user of the second computing device. 14 . The method of claim 13 , wherein the second authentication method for authenticating the user of the second computing device is different from the first authentication method for authenticating the user of the first computing device. 15 . The method of claim 14 , wherein providing the one or more second authentication prompts to the user of the second computing device comprises providing at least one authentication prompt to the user of the second computing device that was not provided to the user of the first computing device. 16 . The method of claim 14 , wherein the first user account is associated with a customer portal provided by the computing platform, and wherein the second user account is associated with the customer portal provided by the computing platform. 17 . The method of claim 16 , wherein the customer portal provided by the computing platform comprises at least one online banking user interface. 18 . A system, comprising: at least one processor; a communication interface communicatively coupled to the at least one processor; and memory storing computer-readable instructions that, when executed by the at least one processor, cause the system to: receive, via the communication interface, and from a first computing device, a request to access a first user account; in response to receiving the request to access the first user account, dynamically select, based on one or more polymorphic authentication factors, a first authentication method for authenticating a user of the first computing device, the first authentication method being selected from a plurality of predefined authentication methods; generate one or more authentication prompts based on the first authentication method selected for authenticating the user of the first computing device; and provide the one or more authentication prompts to the user of the first computing device. 19 . The system of claim 18 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the system to: receive, via the communication interface, and from a second computing device different from the first computing device, a request to access a second user account different from the first user account; in response to receiving the request to access the second user account, dynamically select, based on the one or more polymorphic authentication factors, a second authentication method for authenticating a user of the second computing device, the second authentication method being selected from the plurality of predefined authentication methods; generate one or more second authentication prompts based on the second authentication method selected for authenticating the user of the second computing device; and provide the one or more second authentication prompts to the user of the second computing device. 20 . One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, memory, and a communication interface, cause the computing platform to: receive, via the communication interface, and from a first computing device, a request to access a first user account; in response to receiving the request to access the first user account, dynamically select, based on one or more polymorphic authentication factors, a first authentication method for authenticating a user of th

Assignees

Inventors

Classifications

  • Multi-level security, e.g. mandatory access control · CPC title

  • using biometric data, e.g. fingerprints, iris scans or voiceprints · CPC title

  • User authentication · CPC title

  • Structures or tools for the administration of authentication · CPC title

  • when the policy decisions are valid for a limited amount of time · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016259931A1 cover?
Methods, systems, apparatuses, and computer-readable media for utilizing just-in-time polymorphic authentication techniques to secure information are presented. In one or more embodiments, a computing platform may receive, from a computing device, a request to access a user account. In response to receiving the request to access the user account, the computing platform may dynamically select, b…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification G06F21/36. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Sep 08 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).