Passive security enforcement
Abstract
Technology is described for enabling passive enforcement of security at computing systems. A component of a computing system can passively authenticate or authorize a user based on observations of the user's interactions with the computing system. The technology may increase or decrease an authentication or authorization level based on the observations. The level can indicate what level of access the user should be granted. When the user or a component of the computing device initiates a request, an application or service can determine whether the level is sufficient to satisfy the request. If the level is insufficient, the application or service can prompt the user for credentials so that the user is actively authenticated. The technology may enable computing systems to “trust” authentication so that two proximate devices can share authentication levels.
Claims
exact text as granted — not AI-modified1 . A method for passive authentication by a computing system, the method comprising:
receiving, by the computing system, a first attribute; passively authenticating, by the computing system, a user at a first authentication level based on comparing the first attribute to one or more first previously stored attributes; receiving, by the computing system, a second attribute; and passively updating, by the computing system, the first authentication level to a second authentication level different from the first authentication level based on comparing the second attribute to one or more second previously stored attributes, wherein the first and second attributes each comprise an event indicative of the user or a physical characteristic of the user, and wherein each previously stored attribute comprises a previously stored event, a previously stored physical characteristic, or one or more previously determined acceptable values for one or more users.
2 . A system for passive authentication, the system comprising:
one or more computer-readable media having instructions stored thereon; and one or more hardware processors coupled to the one or more computer-readable media, and configured to read instructions from the one or more computer-readable media to cause the system to perform operations comprising:
receiving, by the system, a first attribute having a first weight;
receiving, by the system, a second attribute having a second weight, wherein the first and second attributes each comprise an event indicative of the user or a physical characteristic of the user;
computing an overall weighted confidence level based upon the first attribute having the first weight and the second attribute having the second weight;
comparing the overall confidence level to a confidence level based upon previously stored attributes corresponding to the first attribute and the second attribute, wherein each previously stored attribute comprises a previously stored event, a previously stored physical characteristic, or one or more previously determined acceptable values for one or more users; and
passively authenticating, by the system, a user at an authentication level based on the comparison of the overall confidence level to the confidence level based upon the one or more previously stored attributes.
3 . A method for passive authentication by a computing system, the method comprising:
receiving, by the computing system, a first attribute having a first weight; receiving, by the computing system, a second attribute having a second weight, wherein the first and second attributes each comprise an event indicative of the user or a physical characteristic of the user; comparing the received first and second attributes to respective previously stored attributes corresponding to the first attribute and the second attribute, wherein each previously stored attribute comprises a previously stored event, a previously stored physical characteristic, or one or more previously determined acceptable values for one or more users; computing an overall weighted confidence level based upon one or more of the comparison of the received first and second attributes to the respective previously stored attributes, the first weight of the first attribute, and the second weight of the second attribute; and passively authenticating, by the computing system, a user at an authentication level based on a comparison of the overall confidence level to a threshold confidence level.
4 . A computer-readable storage device store computer-executable instructions that, when executed, perform a method of passively authenticating a user, the method comprising:
receiving, by the storage device, a first attribute having a first weight; receiving, by the storage device, a second attribute having a second weight, wherein the first attribute and second attribute each comprise an event indicative of the user or a physical characteristic of the user; computing an overall weighted confidence level based upon the first attribute having the first weight and the second attribute having the second weight; comparing the overall confidence level to a confidence level based upon previously stored attributes corresponding to the first attribute and the second attribute, wherein each previously stored attribute comprises a previously stored event, a previously stored physical characteristic, or one or more previously determined acceptable values for one or more users; and passively authenticating, by the storage device, a user at an authentication level based on the comparison of the overall confidence level to the confidence level based upon the one or more previously stored attributes.Join the waitlist — get patent alerts
Track US2019312865A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.