IP Library Granted Patent US 9,202,173
Granted Patent B1
US 9,202,173 · App. 13/628,642 · Granted Dec 1, 2015

Using link analysis in adversarial knowledge-based authentication model

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,202,173
App. No.
13/628,642
Granted
Dec 1, 2015
Kind
B1
Abstract

An improved technique involves adjusting the operation of a KBA system based on facts that may contain information known to an adversary. Along these lines, the KBA system may receive an alert concerning an adversary that may know the answers to some of the KBA questions used by the KBA system in authenticating users. In response to alert, the KBA system may alter operations in order to account for the adversary. Subsequently, when a user requests authentication, the KBA system selects KBA questions based on adjustments made to the KBA system in order to avoid presenting the adversary with KBA questions derived from facts (s)he knows.

Claims (95)

1. A method of performing knowledge-based authentication (KBA), the method comprising:

receiving an adversary alert which identifies an adversary having knowledge of certain facts utilized by a KBA system to construct KBA questions;

in response to the adversary alert, altering operation of the KBA system to account for the adversary having knowledge of the certain facts; and

after the operation of the KBA system has been altered to account for the adversary having knowledge of the certain facts, selecting KBA questions from the KBA system to authenticate users, the KBA questions being selected based on adjustments made within the KBA system in response to the adversary alert;

wherein the method further comprises generating a link table that includes a set of entries, each entry of the set of entries including (i) a fact identifier identifying a fact of a set of facts and (ii) a user identifier identifying a user to whom the fact has a reference; and

wherein altering the operation of the KBA system includes:

finding a particular entry of the set of entries of the link table, the particular entry including a user identifier identifying the adversary, and

filtering, from the set of facts, the fact identified by the fact identifier of the particular entry to form a set of secure facts, a secure fact of the set of secure facts being utilized by the KBA system to construct a secure KBA question that the adversary is unlikely to answer correctly.

2. A method as in claim 1 ,

wherein finding the particular entry including the user identifier identifying the adversary includes:

for each fact of the facts utilized by the KBA system, producing a link strength that represents the number of users of the group of users in the link table;

identifying the fact as an unsecure fact when the link strength is greater than a threshold link strength; and

identifying the fact as a secure fact when the link strength is less than the threshold link strength.

3. A method as in claim 2 ,

wherein the KBA system includes a questions database in which the KBA questions are stored;

wherein the method further comprises:

removing, from the questions database, KBA questions that had been generated from unsecure facts.

4. A method as in claim 3 ,

wherein a minimum number of questions in the questions database is based on the threshold link strength;

wherein removing KBA questions from the questions database includes:

stopping removal of questions when the number of questions in the database is less than the minimum number of questions in the questions database.

5. A method as in claim 1 ,

wherein the particular entry including the user identifier identifying the adversary includes:

for each fact of the facts utilized by the KBA system, using a force-based algorithm to produce a set of nodes of a graph representing the users of the group of users in the link table; and

identifying the fact as a secure fact when a minimum distance between nodes representing users of the group of users and other nodes is less than an external distance threshold.

6. A method as in claim 1 ,

wherein altering the operation of the KBA system further includes:

identifying unsecure KBA questions of the KBA questions from the KBA system;

wherein selecting the KBA questions includes:

providing the KBA questions from the KBA system to a user requesting authentication; and

wherein the method further comprises:

receiving a set of answers, each answer of the set of answers corresponding to a KBA question from the KBA system, and

filtering answers of the set of answers that correspond to the unsecure KBA questions to form a set of secure answers.

7. A method as in claim 6 ,

wherein the method further comprises:

generating a risk score from the set of secure answers, the risk score being based on a number of answers of the set of secure answers that are correct, and

providing or denying authentication to the user based on a value of the risk score.

8. A method as in claim 7 ,

wherein generating the risk score includes:

increasing the value of the risk score in response to an answer of the set of answers being incorrect, and

decreasing the value of the risk score in response to an answer of the set of answers being correct.

9. A method as in claim 8 ,

wherein providing or denying authentication to the user based on a value of the risk score includes:

providing authentication to the user when the value of the risk score is below a risk score threshold value, and

denying authentication to the user when the value of the risk score is above a risk score threshold value.

10. A KBA system constructed and arranged to perform a KBA operation, the KBA system comprising:

a network interface;

memory; and

a controller including controlling circuitry, the controlling circuitry being constructed and arranged to:

receive an adversary alert which identifies an adversary who (i) is not authorized to access a resource and (ii) has knowledge of certain facts utilized by a KBA system to construct KBA questions;

in response to the adversary alert, perform an adjustment operation on the KBA system to produce an adjustment to the KBA system, the adjustment to the KBA system accounting for the adversary having knowledge of the certain facts; and

after performing the adjustment operation on the KBA system, select KBA questions from the KBA system to authenticate users, the KBA questions being selected based on the adjustment to the KBA system so that the adversary may be prevented from accessing the resource;

wherein the controlling circuitry is further constructed and arranged to generate a link table that includes a set of entries, each entry of the set of entries including (i) a fact identifier identifying a fact of a set of facts and (ii) a user identifier identifying a user to whom the fact has a reference; and

wherein the controlling circuitry constructed and arranged to alter the operation of the KBA system is further constructed and arranged to:

find a particular entry of the set of entries of the link table, the particular entry including a user identifier identifying the adversary, and

filter, from the set of facts, the fact identified by the fact identifier of the particular entry to form a set of secure facts, a secure fact of the set of secure facts being utilized by the KBA system to construct a secure KBA question that the adversary is unlikely to answer correctly.

11. A KBA system as in claim 10 ,

wherein the controlling circuitry constructed and arranged to perform the adjustment operation on the KBA system is further constructed and arranged to:

identify unsecure KBA questions of the KBA questions from the KBA system;

wherein the controlling circuitry constructed and arranged to select the KBA questions is further constructed and arranged to:

provide the KBA questions from the KBA system; and

wherein the controlling circuitry is further constructed and arranged to:

receive a set of answers, each answer of the set of answers corresponding to a KBA question from the KBA system, and

filter answers of the set of answers that correspond to the unsecure KBA questions to form a set of secure answers.

12. A KBA system as in claim 11 ,

wherein the controlling circuitry is further constructed and arranged to:

generate a risk score from the set of secure answers, the risk score being based on a number of answers of the set of secure answers that are correct, and

provide or deny authentication to the user based on a value of the risk score.

13. A KBA system as in claim 12 ,

wherein the controlling circuitry constructed and arranged to generate the risk score is further constructed and arranged to:

increase the value of the risk score in response to an answer of the set of answers being incorrect, and

decrease the value of the risk score in response to an answer of the set of answers being correct.

14. A KBA system as in claim 13 ,

wherein the controlling circuitry constructed and arranged to provide or deny authentication to the user based on a value of the risk score is further constructed and arranged to:

provide authentication to the user when the value of the risk score is below a risk score threshold value, and

deny authentication to the user when the value of the risk score is above a risk score threshold value.

15. A computer program product having a non-transitory,

computer-readable storage medium which stores code to perform KBA, the code including instructions to:

receive an adversary alert which identifies an adversary having knowledge of certain facts utilized by a KBA system to construct KBA questions;

in response to the adversary alert, alter operation of the KBA system to account for the adversary having knowledge of the certain facts; and

after the operation of the KBA system has been altered to account for the adversary having knowledge of the certain facts, select KBA questions from the KBA system to authenticate users, the KBA questions being selected based on adjustments made within the KBA system in response to the adversary alert;

wherein code further includes instructions to generate a link table that includes a set of entries, each entry of the set of entries including (i) a fact identifier identifying a fact of a set of facts and (ii) a user identifier identifying a user to whom the fact has a reference; and

wherein altering the operation of the KBA system includes:

finding a particular entry of the set of entries of the link table, the particular entry including a user identifier identifying the adversary, and

filtering, from the set of facts, the fact identified by the fact identifier of the particular entry to form a set of secure facts, a secure fact of the set of secure facts being utilized by the KBA system to construct a secure KBA question that the adversary is unlikely to answer correctly.

16. A method of performing knowledge-based authentication (KBA), the method comprising:

receiving an adversary alert which identifies an adversary having knowledge of certain facts utilized by a KBA system to construct KBA questions;

in response to the adversary alert, altering operation of the KBA system to account for the adversary having knowledge of the certain facts; and

after the operation of the KBA system has been altered to account for the adversary having knowledge of the certain facts, selecting KBA questions from the KBA system to authenticate users, the KBA questions being selected based on adjustments made within the KBA system in response to the adversary alert;

wherein the KBA system utilizes a plurality of facts to construct the KBA questions;

wherein altering the operation of the KBA system includes filtering the certain facts from the plurality of facts to form a set of secure facts;

wherein selecting the KBA questions from the KBA system to authenticate the users includes transmitting data representing an unsecure KBA question and a secure KBA question to a user requesting access to a resource, the unsecure KBA question having been constructed by the KBA system utilizing a certain fact, the secure KBA question having been constructed by the KBA system utilizing a secure fact of the set of secure facts; and

wherein the method further comprises:

after data representing an incorrect answer to the unsecure KBA question is received from the user, generating a first risk score; and

after data representing an incorrect answer to the secure KBA question is received from the user, generating a second risk score, the second risk score being greater than the first risk score, the first risk score and the second risk score each indicating a likelihood that the user is not authorized to access the resource, a larger risk score indicating a larger likelihood that the user is not authorized to access the resource.

Assignments (18)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2012
From: DOTAN, YEDIDYA; FRIEDMAN, LAWRENCE N.; ELIEZER, AYELET
To: EMC CORPORATION
Reel/Frame 029224/0263 →