Methods and apparatus for dynamic user authentication using customizable context-dependent interaction across multiple verification objects
Abstract
An authentication framework is provided which enables dynamic user authentication that combines multiple authentication objects using a shared context and that permits customizable interaction design to suit varying user preferences and transaction/application requirements. Such a framework provides a high degree of flexibility, accuracy, convenience and robustness. In one illustrative aspect of the invention, an automated technique for user authentication comprises the following steps/operations. First, user input is obtained. At least a portion of the user input is associated with two or more verification objects. Then, the user is verified based on the two or more verification objects in accordance with at least one verification policy operating on a context shared across the two or more verification objects. The user authentication technique of the invention may preferably be implemented in a flexible, distributed architecture comprising at least one client device coupled to at least one verification server. The client device and the verification server may operate together to perform the user authentication techniques of the invention.
Claims
exact text as granted — not AI-modified1 . An automated method of user authentication implemented by at least one processor, the method comprising the steps of:
obtaining user input, wherein at least a portion of the user input is associated with two or more verification objects; and verifying the user based on the two or more verification objects in accordance with at least one verification policy operating on a context shared across the two or more verification objects.
2 . The method of claim 1 , wherein the user verification step is performed in accordance with two or more verification engines which are respectively responsive to the two or more verification objects.
3 . The method of claim 2 , wherein the two or more verification engines respectively compare the two or more verification objects to at least one user model.
4 . The method of claim 3 , wherein the at least one user model is shared across the two or more verification objects.
5 . The method of claim 3 , wherein the at least one user model is previously generated based on data obtained in accordance with a user enrollment session.
6 . The method of claim 1 , wherein the context comprises one or more variables associated with the user verification step.
7 . The method of claim 6 , wherein the one or more context variables represent one or more of: (i) a user name; (ii) a current state in the at least one verification policy; (iii) a history pertaining to the two or more verification objects; (iv) application-specific requirements; (v) user-specific requirements; and (vi) physical or logical variables.
8 . The method of claim 1 , wherein the two or more verification objects represent at least one of an object type that may be used to verify identity of the user, knowledge of the user, and possessions of the user.
9 . The method of claim 1 , further comprising the step of accepting at least one of the addition of, the modification of, and the deletion of at least one of a verification policy, a verification object type, a user model, and a variable associated with the context, for subsequent use in the user verification operation.
10 . The method of claim 1 , wherein the context comprises a finite state machine defining state transitions for the user input associated with two or more verification objects and the results associated with the user verification operation in accordance with the at least one verification policy.
11 . An article of manufacture for use in user authentication, comprising a machine readable medium containing one or more programs which when executed implement the steps of claim 1 .
12 . The article of claim 11 , wherein the user verification step is performed in accordance with two or more verification engines which are respectively responsive to the two or more verification objects.
13 . The article of claim 12 , wherein the two or more verification engines respectively compare the two or more verification objects to at least one user model.
14 . The article of claim 11 , wherein the at least one user model is shared across the two or more verification objects.
15 . The article of claim 14 , wherein the at least one user model is previously generated based on data obtained in accordance with a user enrollment session.
16 . The article of claim 11 , wherein the context comprises one or more variables associated with the user verification step.
17 . The article of claim 16 , wherein the one or more context variables represent one or more of: (i) a user name; (ii) a current state in the at least one verification policy; (iii) a history pertaining to the two or more verification objects; (iv) application-specific requirements; (v) user-specific requirements; and (vi) physical or logical variables.
18 . The article of claim 11 , wherein the two or more verification objects represent at least one of an object type that may be used to verify identity of the user, knowledge of the user, and possessions of the user.
19 . The article of claim 11 , further comprising the step of accepting at least one of the addition of, the modification of, and the deletion of at least one of a verification policy, a verification object type, a user model, and a variable associated with the context, for subsequent use in the user verification operation.
20 . An automated method of authenticating a user implemented by an authentication system, the method comprising the steps of:
verifying the user in accordance with the verification means; and customizing the user verification means for subsequent user verification.
21 . An automated method of authenticating a user implemented by an authentication system, the method comprising the steps of:
obtaining user input; and verifying the user based on at least a portion of the user input in accordance with at least one verification policy, wherein the at least one verification policy is implementable as a state machine.
22 . The method of claim 21 , wherein the verifying step further comprises outputting at least one of an intermediate decision and a terminal decision.
23 . An automated method of authenticating a user implemented by an authentication system, the method comprising the steps of:
obtaining user input, wherein at least a portion of the user input is associated with at least one verification object; and verifying the user in accordance with the at least one verification object, wherein the at least one verification object is at least one of: (i) usable for verification without the use of an associated verification engine; (ii) not required to be previously enrolled with user data relating to the at least one verification object; (iii) dynamic; (iv) implicit; (v) able to inherit at least one property from another object; (vi) characterized by multiple inputs; (vii) weighted; and (viii) able to be manipulated.
24 . An automated method of authenticating a user implemented by an authentication system, the method comprising the steps of:
obtaining at least one user model; and verifying a user in accordance with the at least one user model, wherein the at least one user model is at least one of: (i) representative of one or more user preferences; and (ii) able to be modified for use in subsequent user verification.
25 . An automated method of authenticating a user implemented by an authentication system, the method comprising the steps of:
obtaining at least one verification policy; and verifying a user in accordance with the at least one verification policy, wherein the at least one verification policy is based on a verification object, one or more context variables and external source data.Join the waitlist — get patent alerts
Track US2008005788A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.