Reducing authentication confidence over time based on user history

US9762566B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9762566-B2
Application numberUS-201715419447-A
CountryUS
Kind codeB2
Filing dateJan 30, 2017
Priority dateMar 15, 2013
Publication dateSep 12, 2017
Grant dateSep 12, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Technologies are provided in embodiments to manage an authentication confirmation score. Embodiments are configured to identify, in absolute session time, a beginning time and an ending time of an interval of an active user session on a client. Embodiments are also configured to determine a first value representing a first subset of a set of prior user sessions, where the prior user sessions of the first subset were active for at least as long as the beginning time. Embodiments can also determine a second value representing a second subset of the set of prior user sessions, where the prior user sessions of the second subset were active for at least as long as the ending time. Embodiments also determine, based on the first and second values, a decay rate for the authentication confidence score of the active user session. In some embodiments, the set is based on context attributes.

First claim

Opening claim text (preview).

What is claimed is: 1. At least one non-transitory machine readable storage medium comprising instructions stored thereon, the instructions when executed by at least one processor cause the at least one processor to: identify a first absolute session time and a second absolute session time associated with an active user session on a client device associated with a user, wherein the first absolute session time corresponds to an amount of time measured from a start of the active user session to a last positive authentication of the active user session, wherein the second absolute session time corresponds to another amount of time measured from the start of the active user session to a later time occurring after the last positive authentication; and calculate an updated authentication confidence score, the updated authentication confidence score corresponding to a result that equals a current authentication confidence score multiplied by a decay rate, wherein the decay rate equals a second value representing a second subset of a set of prior user sessions divided by a first value representing a first subset of the set of prior user sessions, wherein each prior user session of the first subset lasted at least as long as the first absolute session time, and wherein each prior user session of the second subset lasted at least as long as the second absolute session time. 2. The at least one non-transitory machine readable storage medium of claim 1 , wherein a session length mapping includes session length data for each prior user session of the set of prior user sessions, wherein a session length mapping includes the first value and the second value mapped to the first absolute session time and the second absolute session time, respectively. 3. The at least one non-transitory machine readable storage medium of claim 2 , wherein the instructions, when executed by the at least one processor, are to: update the session length mapping to include new session length data of the active user session based on the active user session terminating. 4. The at least one non-transitory machine readable storage medium of claim 1 , wherein one or more prior user sessions of the set are distinguished from other prior user sessions of the set by one or more context attributes. 5. The at least one non-transitory machine readable storage medium of claim 4 , wherein the one or more context attributes include at least one of: a time of day, a day of a period of days, a location of the client device, a position of the client device, a type of document being accessed, a type of application being executed, weather, ambient light, a network to which the client device is connected, or a device to which the client device is connected. 6. The at least one non-transitory machine readable storage medium of claim 1 , wherein the first and second values are percentages or absolute numbers. 7. The at least one non-transitory machine readable storage medium of claim 1 , wherein each of the prior user sessions of the set is associated with the user. 8. The at least one non-transitory machine readable storage medium of claim 1 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to detect a triggering event prior to calculating the updated authentication confidence score. 9. The at least one non-transitory machine readable storage medium of claim 8 , wherein the triggering event is based on an occurrence of: an authentication engine requesting the decay rate based on a current absolute session time of the active user session; or an expiration of a predetermined interval of time. 10. The at least one non-transitory machine readable storage medium of claim 1 , wherein the second absolute session time corresponds to a current session time of the active user session or to a future session time of the active user session. 11. The at least one non-transitory machine readable storage medium of claim 1 , wherein the last positive authentication corresponds to a last session time during the active user session at which the authentication confidence score was updated. 12. The at least one non-transitory machine readable storage medium of claim 1 , wherein the last positive authentication corresponds to a last session time during the active user session at which the authentication confidence score was at least partially restored based on other information indicating the user was present. 13. A system, the system comprising: at least one processor coupled to a memory element; and an authentication engine comprising instructions stored in the memory element that when executed by the at least one processor are to: identify a first absolute session time and a second absolute session time associated with an active user session on a client device associated with a user, wherein the first absolute session time corresponds to an amount of time measured from a start of the active user session to a last positive authentication of the active user session, wherein the second absolute session time corresponds to another amount of time measured from the start of the active user session to a later time occurring after the last positive authentication; and calculate an updated authentication confidence score, the updated authentication confidence score corresponding to a result that equals a current authentication confidence score multiplied by a decay rate, wherein the decay rate equals a second value representing a second subset of a set of prior user sessions divided by a first value representing a first subset of the set of prior user sessions, wherein each prior user session of the first subset lasted at least as long as the first absolute session time, and wherein each prior user session of the second subset lasted at least as long as the second absolute session time. 14. The system of claim 13 , wherein a session length mapping includes session length data for each prior user session of the set of prior user sessions, wherein a session length mapping includes the first value and the second value mapped to the first absolute session time and the second absolute session time, respectively. 15. The system of claim 14 , wherein the instructions, when executed by the at least one processor, are to: update the session length mapping to include new session length data of the active user session based on the active user session terminating. 16. The system of claim 13 , wherein one or more prior user sessions of the set are distinguished from other prior user sessions of the set by one or more context attributes. 17. The system of claim 13 , wherein the last positive authentication corresponds to a last session time during the active user session at which the authentication confidence score was updated. 18. A method, comprising: identifying a first absolute session time and a second absolute session time associated with an active user session on a client device associated with a user, wherein the first absolute session time corresponds to an amount of time measured from a start of the active user session to a last positive authentication of the active user session, wherein the second absolute session time corresponds to another amount of time measured from the start of the active user session to a later time occurring after the last positive authentication; and calculating an updated authentication confidence score, the updated authentication confidence score corresponding to a result that equals a current authentication confidence score multiplied by a decay rate, where

Assignees

Inventors

Classifications

  • H04L63/08Primary

    for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • Time stamp · CPC title

  • Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title

  • Multi-level security, e.g. mandatory access control · CPC title

  • Auditing as a secondary aspect · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9762566B2 cover?
Technologies are provided in embodiments to manage an authentication confirmation score. Embodiments are configured to identify, in absolute session time, a beginning time and an ending time of an interval of an active user session on a client. Embodiments are also configured to determine a first value representing a first subset of a set of prior user sessions, where the prior user sessions of…
Who is the assignee on this patent?
Intel Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/08. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 12 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).