Method for automatic possession-factor authentication

US9801066B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9801066-B1
Application numberUS-201715586148-A
CountryUS
Kind codeB1
Filing dateMay 3, 2017
Priority dateJun 2, 2016
Publication dateOct 24, 2017
Grant dateOct 24, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods are provided that include: accessing implicit authentication data from a possession factor associated with an authorized user; at the possession factor or at an authentication platform: generating a possession confidence level using the implicit authentication data, the possession confidence level being one of a plurality of possession confidence levels, the possession confidence level indicating a likelihood that the possession factor is possessed by the authorized user; identifying, among a plurality of varying authentication requirements, an authentication requirement for the transaction based on the possession confidence level, the authentication requirement defines a process or action to prove authority to perform the transaction or a process or action to prove an identity of a user attempting to perform the transaction; and implementing the authentication requirement for the transaction.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for performing authentication using implicit authentication data provided by a possession factor, the system comprising: a possession factor comprising one of a smartphone or a mobile electronic device having a capability to parse implicit authentication data for use in the implicit authentication for a transaction involving a user and a service provider; an authentication platform comprising a remote Internet server, wherein at the authentication platform: receiving, via a communication network, an implicit authentication request for initiating the authentication for the transaction based on the possession factor that is associated with the user; transmitting, via the communication network, to the possession factor a query to the possession factor requesting implicit authentication data, the implicit authentication data comprising data collected or generated by the possession factor without user intervention and that enables authentication for the transaction; in response to transmitting the query, receiving, via the communication network, from the possession factor implicit authentication data from the possession factor; generating a possession confidence level using the implicit authentication data, the possession confidence level being one of a plurality of possession confidence levels, the possession confidence level indicating a likelihood that the possession factor is possessed by the authorized user; generating authentication requirements based on the possession confidence level, wherein the authentication requirements define a process or an action for performing authentication for the transaction, wherein generating the authentication requirements includes: (i) selecting a first of a plurality of different, predefined authentication requirements when the possession confidence level satisfies a first confidence threshold, or (ii) selecting a second of the plurality of different, predefined authentication requirements when the possession confidence level satisfies a second confidence threshold; and performing authentication for the transaction in accordance with the selected predefined authentication requirements. 2. The system of claim 1 , wherein further at the authentication platform: wherein receiving the implicit authentication request is triggered by a transmission indicating a successful primary authentication for the transaction, wherein the primary authentication is: (i) performed independent of the authentication using the implicit authentication data and (ii) performed by the service provider, the service provider being independent of the authentication platform. 3. The system of claim 1 , wherein further at the authentication platform: wherein receiving the implicit authentication request is initialized by a transmission provided midstream of a primary authentication, the transmission indicating that a primary authentication is being performed for authenticating the transaction wherein the primary authentication is: (i) performed independent of the authentication using the implicit authentication data and (ii) performed by the service provider, the service provider being independent of the authentication platform. 4. The system of claim 1 , wherein further at the authentication platform: generating a likelihood of possession of the possession factor by the user, wherein the likelihood of possession comprises a probability value indicating a probability that the possession factor is possessed by the user, wherein the generating the likelihood of possession includes: (i) parsing determinative data indicating a potential possession or indicating a potential lack of possession of the possession factor by the user from the implicit authentication data thereby generating a subset of the implicit authentication data, (ii) applying one or more analysis techniques or transformation techniques to the subset of implicit authentication data to determine possession insights relating to a possession or lack of possession of the possession factor, and (iii) calculating a value for the likelihood of possession using the implicit authentication data and the possession insights. 5. A method for performing implicit authentication for a transaction based on a possession factor, the method comprising: receiving, via a remote Internet server, a transaction request; responsive to receiving the transaction request, accessing implicit authentication data from a possession factor associated with an authorized user, the implicit authentication data comprising data that is captured automatically by the possession factor and relating to one or more of an operation of one or more sensors of the possession factor and a usage of the possession factor, at the possession factor or at an authentication platform, wherein the possession factor comprises a mobile computing device, and wherein the authentication platform comprises a remote computing server: generating a possession confidence level using the implicit authentication data, the possession confidence level being one of a plurality of possession confidence levels, the possession confidence level indicating a likelihood that the possession factor is possessed by the authorized user; identifying, among a plurality of varying authentication requirements, an authentication requirement for the transaction based on the possession confidence level, the authentication requirement defines a process or action to prove authority to perform the transaction or a process or action to prove an identity of a user attempting to perform the transaction, wherein identifying the authentication requirement for the transaction includes: (i) selecting a first of a plurality of different, predefined authentication requirements when the possession confidence level satisfies a first confidence threshold, or (ii) selecting a second of the plurality of different, predefined authentication requirements when the possession confidence level satisfies a second confidence threshold; and implementing the selected predefined authentication requirements for the transaction. 6. The method of claim 5 , further comprising: receiving a possession-factor authentication request, the receipt of the possession-factor authentication request triggering an initialization of the implicit authentication based on the possession factor. 7. The method of claim 6 , wherein the possession-factor authentication request comprises an indication that a primary authentication separate from the implicit authentication was performed successfully or is being performed on a basis of authentication data provided expressly by a party. 8. The method of claim 6 , wherein the possession factor comprises a query able to be submitted to the possession factor, wherein the query comprises a request for implicit authentication data from the possession factor. 9. The method of claim 5 , further comprising: querying the possession factor for the implicit authentication data and analysis of the implicit authentication data, wherein the analysis provides one or more indications to determine if the possession factor is possessed by the authorized user. 10. The method of claim 9 , wherein the possession factor comprises a smartphone or a mobile electronic device that includes a mechanism native to an operating system thereof that generates the analysis of the implicit authentication data captured or generated one or more of device sensors and computing resources of the smartphone or the mobile electronic device. 11. The method of claim 5 , further comprising: identifying or selecting a decay rate to apply to a data subset of the implicit authentication data, where

Assignees

Inventors

Classifications

  • Probabilistic graphical models, e.g. probabilistic networks · CPC title

  • using biometric data, e.g. fingerprints, iris scans or voice recognition · CPC title

  • in combination with an identity check · CPC title

  • involving automatic teller machines [ATMs] · CPC title

  • Establishing or using transaction specific rules · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9801066B1 cover?
Systems and methods are provided that include: accessing implicit authentication data from a possession factor associated with an authorized user; at the possession factor or at an authentication platform: generating a possession confidence level using the implicit authentication data, the possession confidence level being one of a plurality of possession confidence levels, the possession confi…
Who is the assignee on this patent?
Duo Security Inc
What technology area does this patent fall under?
Primary CPC classification H04W12/06. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 24 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 9 related publications on this page (citations in our corpus or others sharing the same primary CPC).