US2019312865A1PendingUtilityA1

Passive security enforcement

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Jan 23, 2009Filed: Jun 20, 2019Published: Oct 10, 2019
Est. expiryJan 23, 2029(~2.5 yrs left)· nominal 20-yr term from priority
G06F 21/316G06F 21/32H04L 2463/082H04L 67/10H04L 63/0492H04L 63/08H04W 12/06H04L 63/0861H04W 12/40H04W 12/065
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Technology is described for enabling passive enforcement of security at computing systems. A component of a computing system can passively authenticate or authorize a user based on observations of the user's interactions with the computing system. The technology may increase or decrease an authentication or authorization level based on the observations. The level can indicate what level of access the user should be granted. When the user or a component of the computing device initiates a request, an application or service can determine whether the level is sufficient to satisfy the request. If the level is insufficient, the application or service can prompt the user for credentials so that the user is actively authenticated. The technology may enable computing systems to “trust” authentication so that two proximate devices can share authentication levels.

Claims

exact text as granted — not AI-modified
1 . A method for passive authentication by a computing system, the method comprising:
 receiving, by the computing system, a first attribute;   passively authenticating, by the computing system, a user at a first authentication level based on comparing the first attribute to one or more first previously stored attributes;   receiving, by the computing system, a second attribute; and   passively updating, by the computing system, the first authentication level to a second authentication level different from the first authentication level based on comparing the second attribute to one or more second previously stored attributes,   wherein the first and second attributes each comprise an event indicative of the user or a physical characteristic of the user, and   wherein each previously stored attribute comprises a previously stored event, a previously stored physical characteristic, or one or more previously determined acceptable values for one or more users.   
     
     
         2 . A system for passive authentication, the system comprising:
 one or more computer-readable media having instructions stored thereon; and   one or more hardware processors coupled to the one or more computer-readable media, and configured to read instructions from the one or more computer-readable media to cause the system to perform operations comprising:
 receiving, by the system, a first attribute having a first weight; 
 receiving, by the system, a second attribute having a second weight, wherein the first and second attributes each comprise an event indicative of the user or a physical characteristic of the user; 
 computing an overall weighted confidence level based upon the first attribute having the first weight and the second attribute having the second weight; 
 comparing the overall confidence level to a confidence level based upon previously stored attributes corresponding to the first attribute and the second attribute, wherein each previously stored attribute comprises a previously stored event, a previously stored physical characteristic, or one or more previously determined acceptable values for one or more users; and 
 passively authenticating, by the system, a user at an authentication level based on the comparison of the overall confidence level to the confidence level based upon the one or more previously stored attributes. 
   
     
     
         3 . A method for passive authentication by a computing system, the method comprising:
 receiving, by the computing system, a first attribute having a first weight;   receiving, by the computing system, a second attribute having a second weight, wherein the first and second attributes each comprise an event indicative of the user or a physical characteristic of the user;   comparing the received first and second attributes to respective previously stored attributes corresponding to the first attribute and the second attribute, wherein each previously stored attribute comprises a previously stored event, a previously stored physical characteristic, or one or more previously determined acceptable values for one or more users;   computing an overall weighted confidence level based upon one or more of the comparison of the received first and second attributes to the respective previously stored attributes, the first weight of the first attribute, and the second weight of the second attribute; and   passively authenticating, by the computing system, a user at an authentication level based on a comparison of the overall confidence level to a threshold confidence level.   
     
     
         4 . A computer-readable storage device store computer-executable instructions that, when executed, perform a method of passively authenticating a user, the method comprising:
 receiving, by the storage device, a first attribute having a first weight;   receiving, by the storage device, a second attribute having a second weight, wherein the first attribute and second attribute each comprise an event indicative of the user or a physical characteristic of the user;   computing an overall weighted confidence level based upon the first attribute having the first weight and the second attribute having the second weight;   comparing the overall confidence level to a confidence level based upon previously stored attributes corresponding to the first attribute and the second attribute, wherein each previously stored attribute comprises a previously stored event, a previously stored physical characteristic, or one or more previously determined acceptable values for one or more users; and   passively authenticating, by the storage device, a user at an authentication level based on the comparison of the overall confidence level to the confidence level based upon the one or more previously stored attributes.

Join the waitlist — get patent alerts

Track US2019312865A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.