System for assessing network authentication requirements based on situational instance

US9749308B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9749308-B2
Application numberUS-201614987577-A
CountryUS
Kind codeB2
Filing dateJan 4, 2016
Priority dateJan 4, 2016
Publication dateAug 29, 2017
Grant dateAug 29, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Embodiments of the invention are directed to a system, method, or computer program product for assessing network authentication requirements based on situational instance. In this regard, the invention dynamically determines specific user authentication requirements for accessing a service or executing an activity based on the determining the user's network connections, geographic location, and applications, in real-time. The invention provides a novel method for employing activity data provided by a plurality of users associated with historical activity information to vary the authentication requirements dynamically. Another aspect of the invention is directed to constructing geographic maps with predefined physical areas and overlaying graphical representations of activity data on the maps, in real-time.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for assessing network authentication requirements based on situational instance, wherein the system provides a dynamic platform for determining authentication requirements in real-time, the system comprising: at least one memory device; at least one communication device connected to a distributed network; at least one processing device communicatively coupled to the at least one memory device; and a module stored in the at least one memory device comprising executable instructions that when executed by the at least one processing device, cause the at least one processing device to: establish a communication link with a mobile device associated with a user; receive, from the mobile device, a request to execute a user activity, wherein the user activity requires validation of one or more authentication credentials; monitor user network connections, user location, and user applications associated with the mobile device; determine device information associated with the mobile device; identify at least one local network associated with the mobile device based on the device information, wherein the mobile device is in communication with the at least one local network; determine one or more local devices in communication with the at least one local network; extract activity data regarding historical exposure events, wherein the activity data is received from a plurality of users associated with the historical exposure events; compare the user network connections, the user location and the user applications with the activity data; escalate, in real-time, a level of authentication required for the user to execute the user activity based on determining that the at least one local network and/or the one or more local devices are associated with a historical exposure event; present the escalated authentication requirement to the user via the mobile device; lock a display of the mobile device until (i) the user network connections, the user location and the user applications are not associated with the historical exposure event or (ii) a positive authentication response is received; and enable the user to execute the user activity based on receiving the positive authentication response. 2. The system of claim 1 , wherein the module further comprises instructions that cause the at least one processing device to: retrieve, via the communication link, application information from the mobile device; determine one or more applications associated with the mobile device, wherein the one or more applications comprise applications stored on the mobile device, applications that are currently active and/or applications that are not currently active; and escalate the level of authentication required for the user activity based on determining that at least one of the one or more applications is associated with the historical exposure event. 3. The system of claim 1 , wherein the module further comprises instructions that cause the at least one processing device to: determine whether current user security features meet the escalated authentication requirement for the user activity; determine one or more types of new security features that meet the escalated authentication requirement; and enable the user to modify the current user security features based on the determined new security features. 4. The system of claim 1 , wherein the module further comprises instructions that cause the at least one processing device to: establish communication links with a plurality of secondary user devices associated with a plurality of secondary users; receive, via the communication links, activity data associated with a plurality of historical exposure events; determine, for each historical exposure event of the plurality of historical exposure events, an event geographic area; construct a dynamic exposure map for display on the mobile device, the map comprising geographic areas associated with the historical exposure events; overlay, for each historical exposure event, a physical graphical element on the dynamic exposure map proximate to the event geographic area; modify, in real-time, one or more display attributes associated with the physical graphical element based on the activity data; and initiate a presentation of the dynamic exposure map on a display associated with the mobile device. 5. The system of claim 4 , wherein modifying the one or more display attributes further comprises, for each physical graphical element, modifying the physical graphical element based on a frequency of historical exposure events at the event geographic area associated with the physical graphical element, based on a type of exposure event at the event geographic area associated with the physical graphical element and/or based on a number of exposure events in a predetermined period of time preceding the current time at the event geographic area associated with the physical graphical element. 6. The system of claim 4 , wherein the module further comprises instructions that cause the at least one processing device to: determine that the user is currently proximate to the event geographic area associated with the historical exposure event; initiate a presentation of the dynamic exposure map on the mobile device, wherein the dynamic exposure map comprises an overlay of the physical graphical element associated with the historical exposure event; and modify one or more display attributes associated with the physical graphical element. 7. A computer program product for assessing network authentication requirements based on situational instance, whereby the system provides a dynamic platform for determining authentication requirements in real-time, wherein the computer program product is embodied on a non-transitory computer-readable storage medium having computer-executable instructions to: establish a communication link with a mobile device associated with a user; receive, from the mobile device, a request to execute a user activity, wherein the user activity requires validation of one or more authentication credentials; monitor user network connections, user location, and user applications associated with the mobile device; determine device information associated with the mobile device; identify at least one local network associated with the mobile device based on the device information, wherein the mobile device is in communication with the at least one local network; determine one or more local devices in communication with the at least one local network; extract activity data regarding historical exposure events, wherein the activity data is received from a plurality of users associated with the historical exposure events; compare the user network connections, the user location and the user applications with the activity data; escalate, in real-time, a level of authentication required for the user to execute the user activity based on determining that the at least one local network and/or the one or more local devices are associated with a historical exposure event; present the escalated authentication requirement to the user via the mobile device; lock a display of the mobile device until (i) the user network connections, the user location and the user applications are not associated with the historical exposure event or (ii) a positive authentication response is received; and enable the user to execute the user activity based on receiving the positive authentication response. 8. The computer program product of claim 7 , wherein the non-transitory computer-readable storage medium further comprises computer-executable instructions to: retrieve, via the communication link, application information from the mobile device;

Assignees

Inventors

Classifications

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • Multiple levels of security · CPC title

  • H04L63/08Primary

    for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • Entity profiles · CPC title

  • Risk-dependent, e.g. selecting a security level depending on risk profiles · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9749308B2 cover?
Embodiments of the invention are directed to a system, method, or computer program product for assessing network authentication requirements based on situational instance. In this regard, the invention dynamically determines specific user authentication requirements for accessing a service or executing an activity based on the determining the user's network connections, geographic location, and…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification H04L63/08. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 29 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 9 related publications on this page (citations in our corpus or others sharing the same primary CPC).