IP Library Granted Patent US 8,533,486
Granted Patent B1
US 8,533,486 · App. 12/365,103 · Granted Sep 10, 2013

Incorporating false reject data into a template for user authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,533,486
App. No.
12/365,103
Granted
Sep 10, 2013
Kind
B1
Abstract

Access to a resource may be denied in response to a score value being below a threshold value. The score value may be based on timing information of key-press and key-release events. After denying access to the resource, the timing information of key-press and key-release events may be incorporated into the keystroke dynamics template.

Claims (64)

1. A method comprising:

denying access to a resource in response to a score value of a legitimate user, based on timing information of key-press and key-release events entered by the legitimate user being below a threshold value of a keystroke dynamics template of the legitimate user, wherein the events are presses and releases of keys of a keyboard by one person; then

as a result of denying, identifying the key-press and key-release events entered by the legitimate user as key-press and key-release events entered by an imposter; then

as a result of denying, applying a non-biometric secondary type of authentication after denying access to the resource based on the score value; then

as a result of applying, granting access to the resource based only on the non-biometric secondary type of authentication authenticating the legitimate user; and then

incorporating the timing information of key-press and key-release events entered by the legitimate user and identified as key-press and key-release events entered by an imposter, into the keystroke dynamics template of the legitimate user after denying access to the resource.

2. The method of claim 1 further comprising:

collecting previously measured timing information of key-press and key-release events detected during keyboard entry of a phrase entered by the legitimate user during another user session, prior to denying; and

wherein the keystroke dynamics template includes the previously measured timing information of key-press and key-release events entered by the legitimate user, and the timing information of key-press and key-release events identified as key-press and key-release events entered by an imposter.

3. The method of claim 1 , wherein the incorporated timing information of key-press and keyrelease events includes data representing key dwell times and key flight times.

4. The method of claim 1 , wherein incorporating the timing information of key-press and keyrelease events mitigates a false reject rate for a user, the false reject rate for indicating an amount of erroneous denial of access for the keystroke dynamics template.

5. The method of claim 1 , wherein incorporating the timing information of key-press and key-release events into the keystroke dynamics template comprises:

including the timing information into a vector containing scalar quantities corresponding to collected timing information of key-press and key-release events entered by the legitimate user and identified as key-press and key-release events entered by an imposter.

6. The method of claim 5 , further comprising:

calculating a mean value from the included timing information and other scalar quantities in the vector; and

calculating a standard deviation based on the mean value.

7. A method comprising:

collecting timing information of key-press and key-release events detected during keyboard entry of a phrase by a legitimate user;

retrieving a keystroke dynamics template of the legitimate user, the template formed from data including previously measured keypress and key-release times for the user during another user session;

calculating a score value of the legitimate user based on a comparison of the collected timing information of key-press and key-release events with the keystroke dynamics template;

denying access to a resource in response to the score value being below a threshold value related to the template;

applying a non-biometric secondary type of authentication to identify the user after denying access in response to the score value; and

incorporating the timing information of key-press and key-release events entered by the legitimate user and identified as key-press and key-release events entered by an imposter, into the keystroke dynamics template of the legitimate user after denying access to the resource.

8. The method of claim 7 , wherein denying access to the resource is an indicator of the timing information of key-press and key-release events failing authentication based on the keystroke dynamics template.

9. The method of claim 7 , wherein applying the secondary type of authentication occurs after a predetermined number of attempts of authentication based on the keystroke dynamics template.

10. The method of claim 7 , wherein incorporating the timing information occurs alter a false reject for a user.

11. The method of claim 10 , wherein the false reject is an occurrence of erroneous denial of access of the user.

12. A non-transitory computer-readable medium storing data and instructions to cause a programmable processor to perform operations comprising:

denying access to a resource in response to a score value of a legitimate user, based on timing information of key-press and key-release events entered by the legitimate user being below a threshold value of a keystroke dynamics template of the legitimate user, wherein the events are presses and releases of keys of a keyboard by one person; then

as a result of denying, identifying the key-press and key-release events entered by the legitimate user as key-press and key-release events entered by an imposter; then

as a result of denying, applying a non-biometric secondary type of authentication after denying access to the resource based on the score value; then

as a result of applying, granting access to the resource based only on the non-biometric secondary type of authentication authenticating the legitimate user; and then

incorporating the timing information of key-press and key-release events entered by the legitimate user and identified key-press and key-release events entered by an imposter, into the keystroke dynamics template of the legitimate user after denying access to the resource.

13. The computer-readable medium of claim 12 , including further operations comprising:

collecting previously measured timing information of key-press and key-release events detected during keyboard entry of a phrase entered by the legitimate user during another user session, prior to denying; and

wherein the keystroke dynamics template includes the previously measured timing information of key-press and key-release events entered by the legitimate user, and the timing information of key-press and key-release events identified as key-press and key-release events entered by an imposter.

14. The computer-readable medium of claim 12 , wherein the incorporated timing information of key-press and key-release events includes data representing key dwell times and key flight times.

15. The computer-readable medium of claim 12 , wherein incorporating the timing information of key-press and key-release events mitigates a false reject rate for a user, the false reject rate for indicating an amount of errroneous denial of access of the user corresponding to the keystroke dynamics template.

16. The computer-readable medium of claim 12 , wherein incorporating the timing information of key-press and key-release events into the keystroke dynamics template comprises:

including the timing information into a vector containing scalar quantities corresponding to collect timing information of key-press and key-release events entered by the legitimate user and identified as key-press and key-release events entered by an imposter.

17. The computer-readable medium of claim 16 including further operations comprising:

calculating a mean value from the included timing information and other scalar quantities in the vector; and

calculating a standard deviation based on the mean value.

18. The method of claim 1 , wherein the non-biometric secondary type of authentication comprises a one-time password or a knowledge-based authentication;

wherein the legitimate user and the imposter are the one person;

wherein the timing information of key-press and key-release events entered by the legitimate user are detected during keyboard entry of a phrase entered by the legitimate user; and

wherein the non-biometric secondary type of authentication authenticating the legitimate user is not based on the phrases.

19. The method of claim 7 , wherein the non-biometric secondary type of authentication comprises a one-time password or a knowledge-based authentication;

wherein the legitimate user and the imposter are the one person;

wherein the timing information of key-press and key-release events entered by the legitimate user are detected during keyboard entry of a phrase entered by the legitimate user; and

wherein the non-biometric secondary type of authentication authenticating the legitimate user is not based on the phrases.

20. The computer-readable medium of the claim 12 , wherein the non-biometric secondary type of authentication comprises a one-time password or a knowledge-based authentication;

wherein the legitimate user and the imposter are the one person;

wherein the timing information of key-press and key-release events entered by the legitimate user are detected during keyboard entry of a phrase entered by the legitimate user; and

wherein the non-biometric secondary type of authentication authenticating the legitimate user is not based on the phrases.

21. The method of claim 1 , wherein the non-biometric secondary type of authentication comprises a one-time password or a knowledge-based authentication;

wherein granting access to the resource based only on the non-biometric secondary type of authentication authenticating the legitimate user includes granting access to the resource regardless of the timing information of key-press and key-release events entered by the legitimate user; and

wherein incorporating includes combining the timing information of key-press and key-release events entered by the legitimate user and identified as key-press and key-release events entered by an imposter, into the keystroke dynamics template of the legitimate user.

22. The method of claim 7 , wherein the non-biometric secondary type of authentication comprises a one-time password or a knowledge-based authentication;

wherein granting access to the resource based only on the non-biometric secondary type of authentication authenticating the legitimate user includes granting access to the resource regardless of the timing information of key-press and key-release events entered by the legitimate user; and

wherein incorporating includes combining the timing information of key-press and key-release events entered by the legitimate user and identified as key-press and key-release events entered by an imposter, into the keystroke dynamics template of the legitimate user.

23. The computer-readable medium of claim 12 , wherein the non-biometric secondary type of authentication comprises a one-time password or a knowledge-based authentication;

wherein granting access to the resource based only on the non-biometric secondary type of authentication authenticating the legitimate user includes granting access to the resource regardless of the timing information of key-press and key-release events entered by the legitimate user; and

wherein incorporating includes combining the timing information of key-press and key-release events entered by the legitimate user and identified as key-press and key-release events entered by an imposter, into the keystroke dynamics template of the legitimate user.

Assignments (13)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 21, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: CONCENTRIX SREV, INC.
Reel/Frame 063424/0684 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2022
From: JPMORGAN CHASE BANK, NATIONAL ASSOCIATION
To: SCOUT ANALYTICS, INC.
Reel/Frame 061603/0019 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Oct 28, 2022
From: CONCENTRIX SREV, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 061799/0811 →
MERGER Recorded Oct 5, 2022
From: SERVICESOURCE INTERNATIONAL, INC.; CONCENTRIX MERGER SUB, INC.
To: CONCENTRIX SERVICESOURCE INC.
Reel/Frame 061319/0788 →
CHANGE OF NAME Recorded Oct 5, 2022
From: CONCENTRIX SERVICESOURCE INC.
To: CONCENTRIX SREV, INC.
Reel/Frame 061323/0405 →
MERGER Recorded Oct 4, 2022
From: SCOUT ANALYTICS, INC.
To: SERVICESOURCE INTERNATIONAL, INC.
Reel/Frame 061306/0137 →
RELEASE OF SECURITY INTEREST Recorded Sep 19, 2022
From: BANK OF AMERICA, N.A.
To: SERVICESOURCE INTERNATIONAL, INC.
Reel/Frame 061133/0274 →
SECURITY INTEREST Recorded Jul 23, 2021
From: SERVICESOURCE INTERNATIONAL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 056960/0874 →
SECURITY AGREEMENT Recorded Feb 21, 2014
From: SCOUT ANALYTICS, INC.
To: JPMORGAN CHASE BANK, NATIONAL ASSOCIATION
Reel/Frame 032323/0468 →
SECURITY AGREEMENT Recorded Jan 28, 2013
From: SCOUT ANALYTICS, INC.
To: BENAROYA CAPITAL COMPANY, L.L.C.
Reel/Frame 029709/0695 →
CHANGE OF NAME Recorded Feb 11, 2011
From: ADMITONE SECURITY, INC.
To: SCOUT ANALYTICS, INC.
Reel/Frame 025799/0258 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE TITLE OF THE ASSIGNEE TO BE ADMITONE SECURITY, INC. INSTEAD OF ADMIT ONE SECURITY, INC. PREVIOUSLY RECORDED ON REEL 022721 FRAME 0112. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF THE ENTIRE RIGHT, TITLE AND INTEREST IN THE SUBJECT APPLICATION.. Recorded Jul 31, 2009
From: STARK, YVONNE J.; KELLAS-DICKS, MECHTHILD REGINA
To: ADMITONE SECURITY, INC.
Reel/Frame 023042/0968 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2009
From: STARK, YVONNE J.; KELLAS-DICKS, MECHTHILD R.
To: ADMIT ONE SECURITY, INC.
Reel/Frame 022721/0112 →