Device, system, and method of user authentication based on user-specific characteristics of task performance

US2020045044A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2020045044-A1
Application numberUS-201916597860-A
CountryUS
Kind codeA1
Filing dateOct 10, 2019
Priority dateNov 29, 2010
Publication dateFeb 6, 2020
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Devices, systems, and methods of detecting user identity, authenticating a user to a computerized service or to an electronic device, differentiating between users of a computerized service, and detecting possible attackers or possible fraudulent transactions. A method includes: generating a user authentication session that requires a user to enter a secret by performing a task; monitoring the user interactions during task performance; extracting a user-specific behavioral characteristic, and utilizing it as a factor in user authentication. The task requires the user to perform on-screen operations via a touch-screen or touchpad or mouse or other input unit of the electronic device, or to move in space or tilt in space the entirety of the electronic device in a way that causes inputting of the secret data-item.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: (a) storing a representation of a secret data-item of a particular user, wherein said secret data-item is one of: a password, a Personal Identification Number (PIN); (b) generating a user authentication session that requires said particular user to enter said secret data-item by performing a task comprised of on-screen operations in which said user drags or moves on-screen objects to input said secret data-item; (c) during said user authentication session, monitoring user gestures of user performance of said task; and extracting from said user gestures a behavioral characteristic that characterizes user performance of said task; (d1) determining whether or not said user gestures correspond to correct entry of said secret data-item; (d2) determining whether or not the behavioral characteristic that was extracted in step (c), matches a previously-stored reference behavioral characteristic that was extracted from past on-screen operations that were previously associated with said particular user during previous log-in sessions; (e) if the determining of step (d1) is negative or the determining of step (d2) is negative, then: generating a notification that user authentication is rejected. 2 . The method of claim 1 , wherein said task excludes and does not require typing of characters via a physical keyboard or via an on-screen keyboard. 3 . The method of claim 1 , wherein said task excludes and does not require typing of characters via a physical keypad or via an on-screen keypad. 4 . The method of claim 1 , wherein said task comprises: requiring the user to rotate on-screen reels, each reel indicating at least letters and digits, each reel corresponding to one character of said secret data-item. 5 . The method of claim 4 , wherein monitoring user gestures of performance of said task, comprises: monitoring a rotation speed in which each of said reels is rotated by the user, and utilizing said rotation speed as a user-specific characteristic for user authentication. 6 . The method of claim 4 , wherein monitoring user gestures of performance of said task, comprises: monitoring a rotation direction in which each of said reels is rotated by the user, and utilizing said rotation direction as a user-specific characteristic for user authentication. 7 . The method of claim 1 , wherein said task comprises: generating an on-screen arrangement of digits and letters; requiring the user to input said secret data-item by drawing on-screen lines among consecutive characters of said secret data-item; determining a curvature level of said lines, and utilizing said curvature level of said lines as a user-specific characteristic for user authentication. 8 . The method of claim 1 , wherein the method comprises authenticating said user, or rejecting authentication of said user, based on a cumulative assessment that takes into account (i) the secret data-item that the user knows, and (ii) the specific behavioral way in which the user interacted with the electronic device to input said secret data-item. 9 . The method of claim 1 , wherein said task is performed via a touch-screen of an electronic device, and requires said user to drag or move on-screen objects in order to convey said secret data-item. 10 . The method of claim 1 , wherein said task is performed via a touch-screen of an electronic device, and requires said user to connect on-screen objects with on-screen lines. 11 . The method of claim 1 , wherein said secret data-item is a password represented by a particular two-dimensional drawing, wherein said task is performed via a touch-screen of an electronic device, and requires said user to draw said particular two-dimensional drawing on said touch-screen. 12 . The method of claim 1 , wherein the method authenticates, or rejects authentication, of a user that attempts to log-in via an electronic device to an online account managed by a remote server. 13 . The method of claim 1 , wherein the task requires said user to convey the secret data-item via a touch-screen of an electronic device, without typing said secret data-item on a physical keyboard or on an on-screen keyboard. 14 . The method of claim 1 , wherein said task comprises: generating an on-screen arrangement of digits and letters; requiring the user to input said secret data-item by drawing on-screen lines among consecutive characters of said secret data-item; determining a speed of task completion of said user drawing lines, and utilizing said speed of task completion as a user-specific characteristic for user authentication. 15 . The method of claim 1 , wherein said task requires said particular user to perform steps by on-screen dragging operations or on-screen moving operations, that are performed via a touch-screen of an electronic device of said particular user; wherein the step of monitoring user gestures comprises monitoring touch-screen gestures via said touch-screen; wherein the step of extracting comprises extracting said behavioral characteristic from said touch-screen gestures. 16 . The method of claim 1 , wherein said task requires said particular user to perform steps by on-screen dragging operations or on-screen moving operations, that are performed via a touchpad of an electronic device of said particular user; wherein the step of monitoring user gestures comprises monitoring touch gestures inputted via said touchpad; wherein the step of extracting comprises extracting said behavioral characteristic from said touchpad gestures. 17 . The method of claim 1 , wherein said task requires said particular user to perform steps by on-screen dragging operations or on-screen moving operations, that are performed via a computer mouse of an electronic device of said particular user; wherein the step of monitoring user gestures comprises monitoring computer mouse gestures; wherein the step of extracting comprises extracting said behavioral characteristic from said computer mouse gestures. 18 . A process comprising: (a) storing a representation of a secret data-item of a particular user, wherein said secret data-item is one of: a password, a Personal Identification Number (PIN); (b) generating a user authentication session that requires said particular user to enter said secret data-item by performing a task comprised of spatially moving an entirety of an electronic device, wherein spatial movements of the entirety of the electronic device cause inputting of consecutive characters of said secret-item; (c) during said user authentication session, monitoring spatial properties of the electronic device; and extracting from said spatial properties a behavioral characteristic that characterizes user performance of said task; (d1) determining whether or not said spatial movements correspond to correct entry of said secret data-item; (d2) determining whether or not the behavioral characteristic that was extracted in step (c), matches a previously-stored reference behavioral characteristic that was extracted from previous log-in sessions in which said user had inputted the secret data-item via a set of spatial movements of the entirety of the electronic device; (e) if the determining of step (d1) is negative or the determining of step (d2) is negative, then: generating a notification that user authentication is rejected. 19 . The process of claim 18 , wherein the task is performed by the user utilizing a portable electronic device; wherein ste

Assignees

Inventors

Classifications

  • using biometrical features, e.g. fingerprint, retina-scan (cryptographic mechanisms or cryptographic arrangements for entity authentication using biological data H04L9/3231) · CPC title

  • Authentication · CPC title

  • applying multi-factor authentication · CPC title

  • with detection of the device orientation or free movement in a three-dimensional [3D] space, e.g. 3D mice, 6-DOF [six degrees of freedom] pointers using gyroscopes, accelerometers or tilt-sensors · CPC title

  • Gesture based interaction, e.g. based on a set of recognized hand gestures (interaction based on gestures traced on a digitiser G06F3/04883) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2020045044A1 cover?
Devices, systems, and methods of detecting user identity, authenticating a user to a computerized service or to an electronic device, differentiating between users of a computerized service, and detecting possible attackers or possible fraudulent transactions. A method includes: generating a user authentication session that requires a user to enter a secret by performing a task; monitoring the …
Who is the assignee on this patent?
Biocatch Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/0861. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Feb 06 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).