Continuous authentication confidence module
US-9160730-B2 · Oct 13, 2015 · US
US9762566B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9762566-B2 |
| Application number | US-201715419447-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jan 30, 2017 |
| Priority date | Mar 15, 2013 |
| Publication date | Sep 12, 2017 |
| Grant date | Sep 12, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Technologies are provided in embodiments to manage an authentication confirmation score. Embodiments are configured to identify, in absolute session time, a beginning time and an ending time of an interval of an active user session on a client. Embodiments are also configured to determine a first value representing a first subset of a set of prior user sessions, where the prior user sessions of the first subset were active for at least as long as the beginning time. Embodiments can also determine a second value representing a second subset of the set of prior user sessions, where the prior user sessions of the second subset were active for at least as long as the ending time. Embodiments also determine, based on the first and second values, a decay rate for the authentication confidence score of the active user session. In some embodiments, the set is based on context attributes.
Opening claim text (preview).
What is claimed is: 1. At least one non-transitory machine readable storage medium comprising instructions stored thereon, the instructions when executed by at least one processor cause the at least one processor to: identify a first absolute session time and a second absolute session time associated with an active user session on a client device associated with a user, wherein the first absolute session time corresponds to an amount of time measured from a start of the active user session to a last positive authentication of the active user session, wherein the second absolute session time corresponds to another amount of time measured from the start of the active user session to a later time occurring after the last positive authentication; and calculate an updated authentication confidence score, the updated authentication confidence score corresponding to a result that equals a current authentication confidence score multiplied by a decay rate, wherein the decay rate equals a second value representing a second subset of a set of prior user sessions divided by a first value representing a first subset of the set of prior user sessions, wherein each prior user session of the first subset lasted at least as long as the first absolute session time, and wherein each prior user session of the second subset lasted at least as long as the second absolute session time. 2. The at least one non-transitory machine readable storage medium of claim 1 , wherein a session length mapping includes session length data for each prior user session of the set of prior user sessions, wherein a session length mapping includes the first value and the second value mapped to the first absolute session time and the second absolute session time, respectively. 3. The at least one non-transitory machine readable storage medium of claim 2 , wherein the instructions, when executed by the at least one processor, are to: update the session length mapping to include new session length data of the active user session based on the active user session terminating. 4. The at least one non-transitory machine readable storage medium of claim 1 , wherein one or more prior user sessions of the set are distinguished from other prior user sessions of the set by one or more context attributes. 5. The at least one non-transitory machine readable storage medium of claim 4 , wherein the one or more context attributes include at least one of: a time of day, a day of a period of days, a location of the client device, a position of the client device, a type of document being accessed, a type of application being executed, weather, ambient light, a network to which the client device is connected, or a device to which the client device is connected. 6. The at least one non-transitory machine readable storage medium of claim 1 , wherein the first and second values are percentages or absolute numbers. 7. The at least one non-transitory machine readable storage medium of claim 1 , wherein each of the prior user sessions of the set is associated with the user. 8. The at least one non-transitory machine readable storage medium of claim 1 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to detect a triggering event prior to calculating the updated authentication confidence score. 9. The at least one non-transitory machine readable storage medium of claim 8 , wherein the triggering event is based on an occurrence of: an authentication engine requesting the decay rate based on a current absolute session time of the active user session; or an expiration of a predetermined interval of time. 10. The at least one non-transitory machine readable storage medium of claim 1 , wherein the second absolute session time corresponds to a current session time of the active user session or to a future session time of the active user session. 11. The at least one non-transitory machine readable storage medium of claim 1 , wherein the last positive authentication corresponds to a last session time during the active user session at which the authentication confidence score was updated. 12. The at least one non-transitory machine readable storage medium of claim 1 , wherein the last positive authentication corresponds to a last session time during the active user session at which the authentication confidence score was at least partially restored based on other information indicating the user was present. 13. A system, the system comprising: at least one processor coupled to a memory element; and an authentication engine comprising instructions stored in the memory element that when executed by the at least one processor are to: identify a first absolute session time and a second absolute session time associated with an active user session on a client device associated with a user, wherein the first absolute session time corresponds to an amount of time measured from a start of the active user session to a last positive authentication of the active user session, wherein the second absolute session time corresponds to another amount of time measured from the start of the active user session to a later time occurring after the last positive authentication; and calculate an updated authentication confidence score, the updated authentication confidence score corresponding to a result that equals a current authentication confidence score multiplied by a decay rate, wherein the decay rate equals a second value representing a second subset of a set of prior user sessions divided by a first value representing a first subset of the set of prior user sessions, wherein each prior user session of the first subset lasted at least as long as the first absolute session time, and wherein each prior user session of the second subset lasted at least as long as the second absolute session time. 14. The system of claim 13 , wherein a session length mapping includes session length data for each prior user session of the set of prior user sessions, wherein a session length mapping includes the first value and the second value mapped to the first absolute session time and the second absolute session time, respectively. 15. The system of claim 14 , wherein the instructions, when executed by the at least one processor, are to: update the session length mapping to include new session length data of the active user session based on the active user session terminating. 16. The system of claim 13 , wherein one or more prior user sessions of the set are distinguished from other prior user sessions of the set by one or more context attributes. 17. The system of claim 13 , wherein the last positive authentication corresponds to a last session time during the active user session at which the authentication confidence score was updated. 18. A method, comprising: identifying a first absolute session time and a second absolute session time associated with an active user session on a client device associated with a user, wherein the first absolute session time corresponds to an amount of time measured from a start of the active user session to a last positive authentication of the active user session, wherein the second absolute session time corresponds to another amount of time measured from the start of the active user session to a later time occurring after the last positive authentication; and calculating an updated authentication confidence score, the updated authentication confidence score corresponding to a result that equals a current authentication confidence score multiplied by a decay rate, where
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
Time stamp · CPC title
Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title
Multi-level security, e.g. mandatory access control · CPC title
Auditing as a secondary aspect · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.