Behavioral profiling method and system to authenticate a user

US9516035B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9516035-B1
Application numberUS-201514855532-A
CountryUS
Kind codeB1
Filing dateSep 16, 2015
Priority dateMar 20, 2012
Publication dateDec 6, 2016
Grant dateDec 6, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for behavioral profiling, and in particular, utilizing crowd-managed data architectures to store and manage that profile, are described. In some embodiments, a method includes observing behavioral characteristics of user interactions during a current session with the user through one of a plurality of channels. Variations between the behavioral characteristics of the user interactions observed during the current session and a behavioral profile previously developed based on prior usage patterns of the user through the plurality of channels are identified, in real-time or near real-time.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method of user verification comprising: observing, by a computer processor, behavioral characteristics of user interactions during a current session with a user through a channel; identifying, in real-time or near real-time, variations between the behavioral characteristics of the user interactions observed during the current session and a behavioral profile previously developed based on prior usage patterns of the user through the channel, wherein the behavioral profile is based on clicktrail data and authentication logs; implementing, by the computer processor, a challenge to proceed in the current session, the challenge based on the variations between the behavioral characteristics and the behavioral profile and on a risk level of requested activities of the current session; and when the challenge to proceed in the current session disallows the user to continue in the current session: analyzing, by the computer processor, behavioral biometrics of the user, comparing, by the computer processor, the behavioral biometrics of the user with one or more previous samples of the behavioral biometrics of the user, and when the comparison of the behavioral biometrics of the user with the one or more previous samples of the behavioral biometrics of the user is within a tolerance, allowing, by the computer processor, the current session to proceed. 2. The method of claim 1 , further comprising receiving current device information, and wherein identifying the variations between the behavioral characteristics and the behavioral profile includes comparing the current device information with historical device information stored in the behavioral profile. 3. The method of claim 2 , wherein the current device information includes at least one of the following: device location, device identification, channel usage on a current device, language, network, or internet service provider. 4. The method of claim 1 , wherein identifying the variations includes estimating a distance between the behavioral characteristics in the current session and the behavioral profile, wherein the behavioral profile was further developed based on website behaviors specific to a generation of the user. 5. The method of claim 1 , the method further comprising: developing the behavioral profile by identifying typical usage patterns of behavior of the user from historical usage data; calculating a distance between the behavioral characteristics in the current session and the behavioral profile; and validating the behavioral profile during the current session when the behavioral characteristics in the current session are within a predetermined distance from the typical usage patterns of behavior of the user. 6. The method of claim 1 , wherein the challenge requires the user to actively provide a response. 7. The method of claim 1 , wherein the challenge comprises receiving current device information without the user actively providing a response. 8. The method of claim 1 , wherein the risk level of requested activities is based, at least, on the type of activity, wherein the type of activity comprises at least one of: a deposit activity, a transfer activity, or a logon request activity. 9. The method of claim 8 , wherein the behavioral profile is initially created using demographic data of users similar to the user. 10. The method of claim 9 , the method further comprising: removing or deemphasizing at least a portion of the demographic data from the behavioral profile as the behavioral profile of the user is adapted with the behavioral characteristics of the user interactions observed during the current session. 11. The method of claim 1 , wherein the behavioral biometrics comprises at least one of: a cadence of typing, a temporal spacing between key presses, or a duration of each key press. 12. The method of claim 11 , wherein the challenge includes at least one of: allowing the user to proceed with the current session, collecting identifying information, noting suspicious activity, or disallowing the user to proceed with the current session. 13. The method of claim 1 , wherein the variations are indicative of a second user, and wherein the method further comprises: determining that the second user is authorized by the user; and developing a behavioral profile for the second user. 14. The method of claim 1 , the method further comprising: adapting the behavior profile based on the identified variations between the behavior characteristics of the user interactions observed during the current session and the behavior profile. 15. The method of claim 1 , wherein the channel comprises at least one of: an internet portal, face-to-face contact, a mobile application, or an instant messaging system. 16. The method of claim 1 , wherein the challenge is further based on a security characteristic, the security characteristic pertaining to at least one of: a physical security event, an IP address from which an attack has previously been received, an IP address associated with a known fraudulent user, a system or network known to contain mal-ware, or a risk score associated with an IP address or network. 17. A computer-implemented method of fraud prediction comprising: passively identifying a user interacting through a channel during a current session; retrieving, from a database, a predictive behavioral profile associated with the user, wherein the predictive behavioral profile receives current user interactions with the channel and estimates a distance from prior usage patterns of the user, and wherein the predictive behavioral profile is based on clicktrail data and authentication logs; identifying, by a computer processor, in real-time or near real-time, variations between current usage patterns of the user and the predictive behavioral profile; calculating similarity or distance measures between the current session of the user and the predictive behavioral profile; translating a set of the calculated similarity or distance measures into a single confidence measure; implementing a challenge to proceed in the current session, wherein the challenge is based on a risk level of requested activities of the current session; and when the challenge to proceed in the current session disallows the user to continue in the current session: analyzing, by the computer processor, behavioral biometrics of the user, comparing, by the computer processor, the behavioral biometrics of the user with one or more previous samples of the behavioral biometrics of the user, and when the comparison of the behavioral biometrics of the user with the one or more previous samples of the behavioral biometrics of the user is within a tolerance, allowing, by the computer processor, the current session to proceed. 18. The computer-implemented method of claim 17 , further comprising developing the predictive behavioral profile using at least one of the following: Bayesian network, statistical-based anomaly detection techniques, one or more Markov models, knowledge-based techniques, neural networks, clustering and outlier detection, demographic analysis, genetic algorithms, or fuzzy logic techniques. 19. A system for authenticating a user, the system comprising: a memory; and a processor in communication with the memory, the processor configured to execute software modules, the software modules comprising: a channel communication module configured to engage in one or more sessions with a user via a channel; an information gathering module configured to: moni

Assignees

Inventors

Classifications

  • using biometrical features, e.g. fingerprint, retina-scan (cryptographic mechanisms or cryptographic arrangements for entity authentication using biological data H04L9/3231) · CPC title

  • H04L63/102Primary

    Entity profiles · CPC title

  • User profiles · CPC title

  • Tracking the activity of the user (network monitoring arrangements H04L43/00; recording of computer activity G06F11/34) · CPC title

  • H04L63/08Primary

    for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9516035B1 cover?
Methods and systems for behavioral profiling, and in particular, utilizing crowd-managed data architectures to store and manage that profile, are described. In some embodiments, a method includes observing behavioral characteristics of user interactions during a current session with the user through one of a plurality of channels. Variations between the behavioral characteristics of the user in…
Who is the assignee on this patent?
United Services Automobile Ass (Usaa), Usaa
What technology area does this patent fall under?
Primary CPC classification H04L63/102. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 06 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).