IP Library Granted Patent US 9,251,464
Granted Patent B1
US 9,251,464 · App. 13/621,254 · Granted Feb 2, 2016

Account sharing detection

Inventors: Mechthild Regina Kellas-Dicks (Coquitlam, CA); Yvonne J. Stark (North Bend, WA)
Assignee: ServiceSource International, Inc.
G06N5/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,251,464
App. No.
13/621,254
Granted
Feb 2, 2016
Kind
B1
Abstract

Apparatus and methods are described for detecting sharing of electronic or online accounts based on grouping of data samples that include keyboard input timing factors and optionally secondary factors. The data samples can be received from various computers having various keyboards of a certain type and may be input by more than one user. The data samples are grouped based on distances and ratios of mathematical combinations of distances between input timing of key events such as dwell and flight time, as well as optionally based on at least one secondary factor related to the keyboard input timing factors. Example secondary factors include a time of day of the input; and/or a machine identification, location, and IP address of the computer used to input the sample.

Claims (46)

1. A method comprising:

receiving a plurality of data samples from two computers having two keyboards, each data sample including feature set data of one character string input on the two keyboards by two users;

calculating distance data between data point vectors of feature set data of each pair of samples;

calculating ratios of mathematical combinations of distances between pairs of data point vectors of the feature set data in each of two clusters of the data point pairs; and

determining that the data samples are from two users based on the distance data and the ratios.

2. The method of claim 1 wherein each data sample includes at least one secondary factor from each of the two computers and related to the keyboard input timing factors; and

wherein determining that the data samples are from two users is also based on the secondary factors.

3. The method of claim 2 wherein the keyboard input timing factors include key press timing data and key release timing data; wherein the secondary factors include non-keyboard timing data automatically sent from the computer or generated without the user's knowledge or control; and wherein the secondary different factors include at least one of a time of day during input of the data sample, a machine identification of the computer, a geographic location of the computer, and an Internet protocol (IP) address.

4. The method of claim 1 wherein each data sample includes: (1) keyboard input timing factors of one character string input on the two keyboards by two users, and (2) at least one secondary factor from each of the two computers and related to the keyboard input timing factors.

5. The method of claim 4 wherein the secondary different factors include at least one of a time of day during input of the data sample, a machine identification of the computer, a geographic location of the computer, or an Internet protocol (IP) address.

6. The method of claim 5 wherein the keyboard input timing factors include key press timing data and key release timing data, and wherein the secondary factors include non-keyboard timing data automatically sent from the computer or generated without the user's knowledge or control.

7. The method of claim 6 wherein determining comprises:

calculating feature set data of each pair of the samples using the keyboard input timing factor data and the non-keyboard factor data; and

comparing the feature set data of each pair of samples to at least one threshold to group the samples into at least one cluster.

8. The method of claim 7 wherein comparing comprises:

calculating distance data between each pair of data point vectors of the feature set data of each pair of samples;

calculating ratios of mathematical combinations of distances between a plurality of subsets, each subset including a plurality of the data point vectors of the feature set data; and

identifying the existence of at least one cluster of the feature set data by comparing the ratio data to a ratio threshold and by comparing the distance data to a distance threshold.

9. The method of claim 8 further comprising, prior to calculating distance data, identifying and discarding at least one outlier data point pair in each pair of data point vectors of the feature set data of each pair of samples.

10. The method of claim 8 , wherein calculating distance data comprises calculating time difference measurements between pairs of data points of keyboard input timing factors;

wherein calculating ratio data comprises calculating ratios of mathematical combinations of the average time difference measurements between inter-cluster and intra-cluster pairs of data points of feature sets of pairs of samples; and

wherein identifying the existence of at least one cluster comprises at least one of completely removing a cluster, merging two clusters, and identifying as distinct a cluster based on (1) comparing the distance data to a distance threshold, and (2) comparing the ratios to a ratio threshold.

11. The method of claim 6 , wherein determining comprises:

using keystroke dynamics and another factor to identify and count patterns of the data samples that can be linked to distinct persons using an account; wherein identifying comprises using cluster analysis to group keystroke patterns into groups of similar samples and separate dissimilar samples; and wherein grouping comprises using multiple distance measure merge criteria and discarding outliers.

12. The method of claim 11 , wherein using multiple distance measure merge criteria includes:

using outlier tolerant distance calculations in connection with feature-specific distances, where outlier tolerance is achieved by eliminating a percentage q of pairs of matching data points from each pair of samples;

using a mathematical combination of inter-cluster distances of two clusters to be compared as a primary measure; and

using as a secondary measure a mathematical ratio function based on the intra-cluster distances of each of the clusters and the intra-cluster distances of the union of the two clusters.

13. The method of claim 12 , further comprising prior to calculating distances between dwell time and flight time data points, identifying and discarding outliers of the dwell time and flight time data points of each pair of samples.

14. The method of claim 6 wherein determining comprises:

calculating a plurality of dwell time data points and flight time data points for each sample;

calculating distances between dwell time and flight time data points of each pair of samples;

calculating ratios of (1) mathematical combinations of distances between the pairs of data point vectors within each cluster of the first set of clusters and (2) mathematical combinations of distances between the pairs of data point vectors within a union of two clusters of the first set of clusters;

calculating distances between data points of the secondary factors of each pair of samples within each cluster of the set of clusters; and

comparing the distances to a first threshold, comparing the ratios to a second threshold, and comparing the distances of the secondary factors to a third threshold to identify a set of clusters.

15. A specialized computer server system comprising:

a network communication input device receiving a plurality of data samples;

a database of the computer server system storing the plurality of data samples received from at least one computer, each data sample including: (1) keyboard input timing factors of a plurality of characters of one username and password combination input on at least one keyboard of one type of keyboard of the at least one computer by at least one user, and (2) at least one secondary factor from each of the at least one computers and related to the keyboard input timing factors;

a share detect engine of the computer server system to determine whether the samples are from more than one user based on the keyboard input timing factors and based on the secondary factors, wherein the share detect engine further comprises an authentication model to:

identify and discard outlier data point pairs of the feature set data of each pair of samples;

calculate distance data between each non-discarded data point pair of the feature set data of each pair of samples;

identify the existence of two clusters of the feature set data by comparing the distance data to a distance threshold;

based on the distance data, calculate a first ratio of (1) an average distance between the combinations of all inter-cluster distances of data point pairs of the feature set data in both of the two clusters, and (2) an average distance between the combinations of all intra-cluster distance of data point pairs of the feature set data in a first of the two clusters;

based on the distance data, calculate a second ratio of (1) the average distance between the combinations of all inter-cluster distances of data point pairs of the feature set data in both of the two clusters, and (2) an average distance between the combinations of all intra-cluster distance of data point pairs of the feature set data in a second of the two clusters;

one of (a) merging the first and second cluster, (b) discarding the first or second cluster, and (c) identify the first or second cluster as distinct by comparing the first and second ratio to a ratio threshold; and

one of a display, a network communication output, and a printer to display a warning identifying that the samples are from more than one user.

Assignments (6)
MERGER Recorded Oct 5, 2022
From: SERVICESOURCE INTERNATIONAL, INC.; CONCENTRIX MERGER SUB, INC.
To: CONCENTRIX SERVICESOURCE INC.
Reel/Frame 061319/0788 →
CHANGE OF NAME Recorded Oct 5, 2022
From: CONCENTRIX SERVICESOURCE INC.
To: CONCENTRIX SREV, INC.
Reel/Frame 061323/0405 →
MERGER Recorded Oct 4, 2022
From: SCOUT ANALYTICS, INC.
To: SERVICESOURCE INTERNATIONAL, INC.
Reel/Frame 061306/0137 →
RELEASE OF SECURITY INTEREST Recorded Sep 19, 2022
From: BANK OF AMERICA, N.A.
To: SERVICESOURCE INTERNATIONAL, INC.
Reel/Frame 061133/0274 →
SECURITY INTEREST Recorded Jul 23, 2021
From: SERVICESOURCE INTERNATIONAL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 056960/0874 →
SECURITY AGREEMENT Recorded Jan 28, 2013
From: SCOUT ANALYTICS, INC.
To: BENAROYA CAPITAL COMPANY, L.L.C.
Reel/Frame 029709/0695 →
Continuity (1)
Continuation 12547423 · Aug 25, 2009