IP Library Granted Patent US 8,898,758
Granted Patent B2
US 8,898,758 · App. 14/088,202 · Granted Nov 25, 2014

Passive security enforcement

Inventors: David J. Steeves (Seattle, WA); Kim Cameron (Bellevue, WA); Todd L. Carpenter (Monroe, WA); David Foster (Bellevue, WA); Quentin S. Miller (Sammamish, WA)
Assignee: Microsoft Corporation
H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,898,758
App. No.
14/088,202
Granted
Nov 25, 2014
Kind
B2
Abstract

Technology is described for enabling passive enforcement of security at computing systems. A component of a computing system can passively authenticate or authorize a user based on observations of the user's interactions with the computing system. The technology may increase or decrease an authentication or authorization level based on the observations. The level can indicate what level of access the user should be granted. When the user or a component of the computing device initiates a request, an application or service can determine whether the level is sufficient to satisfy the request. If the level is insufficient, the application or service can prompt the user for credentials so that the user is actively authenticated. The technology may enable computing systems to “trust” authentication so that two proximate devices can share authentication levels.

Claims (58)

1. A method for passive authentication by a computing system, the method comprising:

receiving, by the computing system, multiple attributes of a first user, the attributes comprising a first subset of attributes comprising one or more attributes and a second subset of attributes comprising one or more attributes;

determining by the computing system, from a set of types, corresponding types for each attribute of the first subset of attributes, wherein each of the types in the set of types has a corresponding weight;

comparing by the computing system, based on the determined types for each attribute of the first subset of attributes, each attribute of the first subset of attributes to one or more previously stored attributes with a corresponding type, thereby selecting a first applicable attribute;

passively authenticating, by the computing system, the first user at a first confidence level, the first confidence level based on the weights for the types corresponding to the first applicable attribute;

determining, from the set of types, corresponding types for each attribute of the second subset of attributes;

comparing, based on the determined types for each attribute of the second subset of attributes, each attribute of the second subset of attributes to one or more of the previously stored attributes with a corresponding type, thereby selecting a second applicable attribute; and

updating, by the computing system, the first confidence level to a second confidence level, the second confidence level based on the weights for the types corresponding to the second applicable attribute;

wherein each attribute of the first subset of attributes and of the second subset of attributes comprises at least one of: an event associated with the first user and a physical characteristic of the first user; and

wherein each previously stored attribute comprises a previously stored user event, a previously stored user physical characteristic, or one or more previously determined acceptable values for the type corresponding to that stored attribute.

2. The method of claim 1 wherein the at least one of the determined types for the first subset of attributes or for the second subset of attributes comprises a location that is identifiable by the computing device.

3. The method of claim 2 wherein the at least one of the determined types for the first subset of attributes or for the second subset of attributes comprises a captured image of surroundings and a name of a data communications network.

4. The method of claim 1 wherein the second confidence level is lower than first confidence level.

5. The method of claim 4 further comprising:

determining that the second confidence level is lower than a specified threshold; and

in response to determining that the second confidence level is lower than a specified threshold, preventing the first user from accessing one or more functions of a computing device that were available to the first user when the user was authenticated at the first confidence level.

6. The method of claim 1 wherein the at least one of the determined types for the first subset of attributes or for the second subset of attributes comprises making a telephone call.

7. The method of claim 1 wherein the first confidence level and second confidence level are indications of the likelihood that the authentication is correct.

8. The method of claim 1 wherein the at least one of the determined types for the first subset of attributes or for the second subset of attributes comprises a temperature.

9. The method of claim 1 wherein the at least one of the determined types for the first subset of attributes or for the second subset of attributes comprises a motion.

10. The method of claim 1 wherein the at least one of the determined types for the first subset of attributes or for the second subset of attributes comprises a pressure.

11. The method of claim 1 wherein the at least one of the determined types for the first subset of attributes or for the second subset of attributes comprises a co-presence or absence of another device and wherein the previously stored attribute to which the co-presence or absence of another device is compared comprise one of the previously determined acceptable values equivalent to true and false.

12. The method of claim 1 wherein the at least one of the determined types for the first subset of attributes or for the second subset of attributes comprises a facial pattern.

13. The method of claim 1 further comprising receiving a request from the first user, the request comprising an identification of action to be performed by an application, wherein,

if the second confidence level is above a security level associated with the action identified in the request, the application satisfies the request; and

if the second confidence level is not above the security level associated with the action identified in the request, the application causes a component to prompt the user for authentication credentials so that the user can be actively authenticated.

14. A computer-readable storage device storing computer-executable instructions that, when executed by a computing device, cause the computing device to perform operations for passively authenticating a user, the operations comprising:

receiving multiple attributes of a first user, the attributes comprising a first subset of attributes comprising one or more attributes and a second subset of attributes comprising one or more attributes;

determining, from a set of types, corresponding types for each attribute of the first subset of attributes, wherein each of the types in the set of types has a corresponding weight;

comparing, based on the determined types for each attribute of the first subset of attributes, each attribute of the first subset of attributes of the first user to one or more previously stored attributes with a corresponding type, thereby selecting a first applicable attribute;

passively authenticating the first user at a first confidence level, the first confidence level based on the weights for the types corresponding to the first applicable attribute;

determining, from the set of types, corresponding types for each attribute of the second subset of attributes;

comparing, based on the determined types for each attribute of the second subset of attributes, each attribute of the second subset of attributes of the first user to one or more of the previously stored attributes with a corresponding type, thereby selecting a second applicable attribute; and

updating the first confidence level to a second confidence level, the second confidence level based on the weights for the types corresponding to the second applicable attribute;

wherein each attribute of the first subset of attributes and of the second subset of attributes comprises at least one of: an event associated with the first user and a physical characteristic of the first user; and

wherein each previously stored attribute comprises a previously stored user event, a previously stored user physical characteristic, or one or more previously determined acceptable values for the type corresponding to that stored attribute.

15. The computer-readable storage device of claim 14 wherein the at least one of the determined types for the first subset of attributes or for the second subset of attributes comprises a signal from a proximate computing device that has also authenticated the user, and wherein the updating comprises increasing the confidence level upon receiving a signal from the proximate computing device that has also authenticated the user.

16. The computer-readable storage device of claim 14 wherein the operations further comprise receiving a request from the first user, the request comprising an identification of action to be performed by an application, wherein,

if the second confidence level is above a security level associated with the action identified in the request, the application satisfies the request; and

if the second confidence level is not above the security level associated with the action identified in the request, the application causes a component to prompt the user for authentication credentials so that the user can be actively authenticated.

17. The computer-readable storage device of claim 14 wherein the operations further comprise:

determining that the second confidence level is lower than a specified threshold; and

in response to determining that the second confidence level is lower than a specified threshold, preventing the first user from accessing one or more functions of a computing device that were available to the first user when the user was authenticated at the first confidence level.

18. A device for passively authenticating a user, the device comprising:

a processor and memory;

an input configured to receive multiple attributes of a first user, the attributes comprising a first subset of attributes comprising one or more attributes and a second subset of attributes comprising one or more attributes;

an attribute analyzer configured to determine, from a set of types, corresponding types for each attribute of the first subset of attributes, wherein each attribute of the types in the set of types has a corresponding weight;

an attribute comparator configured to compare, based on the determined types for each attribute of the first subset of attributes, each attribute of the first subset of attributes to one or more previously stored attributes with a corresponding type, to thereby select a first applicable attribute; and

an authentication module configured to passively authenticate the first user at a first confidence level, the first confidence level based on the weights for the types corresponding to the first applicable attribute, wherein the authentication module is stored in the memory;

wherein the attribute analyzer is further configured to determine, from the set of types, corresponding types for each attribute of the second subset of attributes,

wherein the attribute comparator is further configured to compare, based on the determined types for each attribute of the second subset of attributes, each attribute of the second subset of attributes of the first user to one or more of the previously stored attributes with a corresponding type, to thereby select a second applicable attribute,

wherein the authentication module is further configured to update the first confidence level to a second confidence level, the second confidence level based on the weights for the types corresponding to the second applicable attribute,

wherein each attribute of the first subset of attributes and of the second subset of attributes comprises at least one of: an event associated with the first user and a physical characteristic of the first user, and

wherein each previously stored attribute comprises a previously stored user event, a previously stored user physical characteristic, or one or more previously determined acceptable values for the type corresponding to that stored attribute.

19. The device of claim 18 wherein the at least one of the determined types for the first subset of attributes or for the second subset of attributes comprises a facial pattern.

20. The device of claim 18 further comprising an interface configured to receive a request from the first user, the request comprising an identification of action to be performed by an application, wherein,

if the second confidence level is above a security level associated with the action identified in the request, the application satisfies the request; and

if the second confidence level is not above the security level associated with the action identified in the request, the application causes a component to prompt the user for authentication credentials so that the user can be actively authenticated.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2015
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 039025/0454 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: STEEVES, DAVID J.; CAMERON, KIM; CARPENTER, TODD L.; FOSTER, DAVID J.; MILLER, QUENTIN S.
To: MICROSOFT CORPORATION
Reel/Frame 034439/0519 →
Continuity (2)
Continuation 12359220 · Jan 23, 2009
Related Publication 20140223522A1 · Aug 7, 2014