IP Library Granted Patent US 8,806,591
Granted Patent B2
US 8,806,591 · App. 12/986,538 · Granted Aug 12, 2014

Authentication risk evaluation

Inventors: Charles Dallas (Colorado Springs, CO); Mohammad Reza Tayebnejad (Colorado Springs, CO); Ken Mckeever (Denver, CO); Vidhyaprakash Ramachandran (Richardson, TX); Paul Andrew Donfried (Richmond, MA)
Assignee: Verizon Patent and Licensing Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,806,591
App. No.
12/986,538
Granted
Aug 12, 2014
Kind
B2
Abstract

A computer is configured to receive an authentication request that identifies one or more authentication form factors, and for each form factor identified, further identifies at least one parameter. The computer is further configured to generate a risk score for the authentication request using the parameter, the risk score being based at least in part on a complexity associated with each of the one or more authentication form factors. The computer is further configured to provide the risk score to a requester.

Claims (35)

1. A system comprising:

a computer server having a processor and a memory, the server configured to:

receive an authentication request that identifies one or more authentication form factors, and for each form factor identified, further identifies at least one parameter;

generate a risk score for the authentication request using the parameter, the risk score being based at least in part on a complexity associated with each of the one or more authentication form factors and on an upper bound on a number of guesses that an attacker may make to recover a token before the attacker is locked out from additional attacks, the upper bound based on a lockout time and at least one of a token lifetime, an attempt number, or lockout strikes, the lockout time being a time period for which a lockout will apply;

provide the risk score to a requester; and

when the upper bound is based on the lockout time, token lifetime and lockout strikes, compute the upper bound by dividing a product of the token lifetime and the lockout strikes by the lockout time.

2. The system of claim 1 , the server further configured to associate the risk score with a risk level, and to provide the risk level to the requester along with the risk score.

3. The system of claim 1 , wherein the one or more authentication form factors includes at least one of one-time authentication (OTA), static knowledge-based authentication (SKBA), and user password authentication (UPA).

4. The system of claim 1 , wherein the at least one parameter includes at least one of a location identifier for a source of the authentication request, and the risk score is based at least in part on one of: a determination of geo-velocity and a history relating to the location.

5. The system of claim 1 , wherein the at least one parameter includes at least one of a number representing a number of authentication attempts that may be made before a lockout, a lockout duration, a password length, a token length, a token complexity, an answer space, an OTA pin length, an attempts rate, and a token lifetime.

6. The system of claim 1 , further comprising a computer client having a processor and a memory, the client configured to send the authentication request to the server.

7. The system of claim 1 , the server further configured to store the risk score in a data store along with an identifier or identifiers for the one or more authentication form factors and the at least one parameter.

8. A method, comprising:

receiving, in a computer having a processor and a memory, an authentication request that identifies one or more authentication form factors, and for each form factor identified, further identifies at least one parameter;

generating, in the computer, a risk score for the authentication request using the parameter, the risk score being based at least in part on a complexity associated with each of the one or more authentication form factors and on an upper bound on a number of guesses that an attacker may make to recover a token before the attacker is locked out from additional attacks, the upper bound based on a lockout time and at least one of a token lifetime, an attempt number, or lockout strikes, the lockout time being a time period for which a lockout will apply;

providing the risk score to a requester; and

when the upper bound is based on the lockout time, token lifetime and lockout strikes, compute the upper bound by dividing a product of the token lifetime and the lockout strikes by the lockout time.

9. The method of claim 8 , further comprising associating the risk score with a risk level, and providing the risk level to the requester along with the risk score.

10. The method of claim 8 , wherein the one or more authentication form factors includes at least one of one-time authentication (OTA), static knowledge-based authentication (SKBA), and user password authentication (UPA).

11. The method of claim 8 , wherein the at least one parameter includes at least one of a location identifier for a source of the authentication request, and the risk score is based at least in part on one of: a determination of geo-velocity and a history relating to the location.

12. The method of claim 8 , wherein the at least one parameter includes at least one of a number representing a number of authentication attempts that may be made before a lockout, a lockout duration, a password length, a token length, a token complexity, an answer space, an OTA pin length, an attempts rate, and a token lifetime.

13. The method of claim 8 , further comprising storing the risk score in a data store along with an identifier or identifiers for the one or more authentication form factors and the at least one parameter.

14. A non-transitory computer-readable medium tangibly embodying computer executable instructions, including instructions for:

receiving, in a computer having a processor and a memory, an authentication request that identifies one or more authentication form factors, and for each form factor identified, further identifies at least one parameter;

generating, in the computer, a risk score for the authentication request using the parameter, the risk score being based at least in part on a complexity associated with each of the one or more authentication form factors and on an upper bound on a number of guesses that an attacker may make to recover a token before the attacker is locked out from additional attacks, the upper bound based on a lockout time and at least one of a token lifetime, an attempt number, or lockout strikes, the lockout time being a time period for which a lockout will apply;

providing the risk score to a requester; and

when the upper bound is based on the lockout time, token lifetime and lockout strikes, compute the upper bound by dividing a product of the token lifetime and the lockout strikes by the lockout time.

15. The medium of claim 14 , further comprising instructions for associating the risk score with a risk level, and providing the risk level to the requester along with the risk score.

16. The medium of claim 14 , wherein the one or more authentication form factors includes at least one of one-time authentication (OTA), static knowledge-based authentication (SKBA), and user password authentication (UPA).

17. The medium of claim 14 , wherein the at least one parameter includes at least one of a location identifier for a source of the authentication request, and the risk score is based at least in part on one of: a determination of geo-velocity and a history relating to the location.

18. The medium of claim 14 , wherein the at least one parameter includes at least one of a number representing a number of authentication attempts that may be made before a lockout, a lockout duration, a password length, a token length, a token complexity, an answer space, an OTA pin length, an attempts rate, and a token lifetime.

19. The medium of claim 14 , further comprising instructions for storing the risk score in a data store along with an identifier or identifiers for the one or more authentication form factors and the at least one parameter.

20. The system of claim 1 , wherein the complexity associated with each authentication form factor is an entropy complexity.

21. The system of claim 20 , wherein the entropy complexity associated with each authentication form factor is configured to include a number of combinations of characters in a token that could be presented.

22. The system of claim 1 , wherein when the authentication request identifies multiple authentication form factors, the complexity is a combination of each complexity of each authentication form factor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2011
From: DALLAS, CHARLES; TAYEBNEJAD, MOHAMMAD REZA; MCKEEVER, KEN; RAMACHANDRAN, VIDHYAPRAKASH; DONFRIED, PAUL ANDREW
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 025605/0914 →
Continuity (1)
Related Publication 20120180124A1 · Jul 12, 2012