Triggering a request for an authentication

US9955349B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9955349-B1
Application numberUS-201615242277-A
CountryUS
Kind codeB1
Filing dateAug 19, 2016
Priority dateMar 30, 2015
Publication dateApr 24, 2018
Grant dateApr 24, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The present disclosure relates to multifactor-based authentication systems. Multifactor authentication occurs during a communication session in response to detecting a trigger event, such as an anomalous condition. Historical metrics, such as performance metrics (e.g., rendering speeds), behavioral metrics (e.g., click-stream behavior), environmental metrics (e.g., noise), etc., can be used as a baseline to compare against metrics for a current communication session. An anomalous condition, such as a current session metric exceeding a threshold, can result in an authentication service transmitting a multifactor authentication request.

First claim

Opening claim text (preview).

What is claimed is: 1. A method, comprising: storing historic metric data for past communication sessions between a client device and one or more server computers associated with a service provider, the historic metric data comprising one or more of the following: performance metric data, behavioral metric data, or environmental metric data; for a current communication session between the client device and the service provider, receiving a first-level authentication, including a password, from the client device; during the current communication session, receiving a request from the client device for an action to be performed by the service provider; by the service provider, in response to the request, retrieving current metric data for the current communication session; comparing the current metric data against the historic metric data; if the current metric data deviates from the historic metric data by greater than a threshold amount, requesting a second-level authentication from the client device; and responding to the request if the second-level authentication is passed. 2. The method of claim 1 , wherein the performance metric data includes a speed of the past communication sessions, wherein the retrieving of the current metric data includes determining a speed of the current communication session, and wherein the comparing includes comparing the speed of the current communication session against the speed of the past communication sessions. 3. The method of claim 1 , wherein the behavioral metric data includes one or more of the following: frequency that the client device is used to log-in to the service provider, typing frequency on the client device, or key-press duration. 4. The method of claim 1 , wherein the environmental metric data includes environmental conditions at a location of the client device including one or more of the following: a noise level, a temperature, a humidity, or a geographic location. 5. The method of claim 1 , further including comparing the action to a list of actions considered to be sensitive actions and wherein the requesting of the second-level authentication is only performed for sensitive actions. 6. The method of claim 1 , further including blocking the action from being performed unless the second-level authentication is passed. 7. The method of claim 1 , wherein the second-level authentication includes requesting knowledge-based authentication information from a user of the client device or biometric-based authentication information from the user of the client device. 8. A computer-readable storage device, which is non-transitory, including instructions thereon that upon execution cause a computer system to: receive first-level authentication information for a current communication session between a client device and a host server computer within a service provider; receive a request from the client device for an action to be performed by the service provider; in response to the request, track a metric associated with the current communication session and compare the tracked metric to a saved metric associated with the client device; and if the tracked metric deviates more than a threshold amount from the saved metric, request second-level authentication information for the current communication session to continue. 9. The computer-readable storage medium of claim 8 , wherein the saved metric comprises one or more of the following: performance metric data, behavioral metric data, or environmental metric data. 10. The computer-readable storage medium of claim 9 , wherein the performance metric data includes a speed of past communication sessions between the client device and the service provider. 11. The computer-readable storage medium of claim 9 , wherein the behavioral metric data includes one or more of the following: frequency with which the client device is used to log-in to the service provider, typing frequency on the client device, or key-press duration. 12. The computer-readable storage medium of claim 9 , wherein the environmental metric data includes environmental conditions at a location of the client device including one or more of the following: a noise level, a temperature, a humidity, or a geographic location. 13. The computer-readable storage medium of claim 8 , wherein the saved metric is associated with one or more session profiles generated using communication session metrics between the service provider and the client device. 14. The computer-readable storage medium of claim 8 , wherein the second-level authentication includes causing one or more measurement devices to be transported to a location of the client device to obtain a measurement associated with the client device. 15. The computer-readable storage medium of claim 14 , wherein the measurement device is attached to an unmanned aerial vehicle that includes a wireless access point to which the client device can connect. 16. The computer-readable storage medium of claim 14 , wherein the first-level authentication information includes a password, and the second-level authentication information is independent of the password.

Assignees

Inventors

Classifications

  • G06F21/40Primary

    by quorum, i.e. whereby two or more security principals are required · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

  • Entity profiles · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9955349B1 cover?
The present disclosure relates to multifactor-based authentication systems. Multifactor authentication occurs during a communication session in response to detecting a trigger event, such as an anomalous condition. Historical metrics, such as performance metrics (e.g., rendering speeds), behavioral metrics (e.g., click-stream behavior), environmental metrics (e.g., noise), etc., can be used as …
Who is the assignee on this patent?
Amazon Tech Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/40. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 24 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 6 related publications on this page (citations in our corpus or others sharing the same primary CPC).