IP Library Granted Patent US 9,396,320
Granted Patent B2
US 9,396,320 · App. 14/145,439 · Granted Jul 19, 2016

System and method for non-intrusive, privacy-preserving authentication

Inventor: Rolf Lindemann (Steele, DE)
Assignee: NOK NOK LABS, INC.
G06F21/32G06F21/577G06Q20/204G06Q20/3224G06Q20/3274G06Q20/3278G06Q20/4012G06Q20/40145G06Q20/42G06Q20/425G07F19/20H04L9/0819H04L9/0822H04L9/0841H04L9/3231H04L9/3247H04L9/3297H04L63/0492H04L63/08H04L63/083H04L63/0861H04L63/20G06F2221/2115H04L2209/805H04L2463/102H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,396,320
App. No.
14/145,439
Granted
Jul 19, 2016
Kind
B2
Abstract

A system, apparatus, method, and machine readable medium are described for non-intrusive privacy-preserving authentication. For example, one embodiment of a method comprises: entering into a legitimate user state on a client device for a time period following an explicit authentication by an end user; recording reference data related to user behavior while in the legitimate user state; measuring user behavior when outside of the legitimate user state and arriving at an authentication assurance level based on a distance between the measured user behavior and the recorded reference data; in response to an authentication request within the legitimate user state, providing an authentication assurance level at or above a defined threshold, the authentication assurance level being sufficient to authenticate the user to a relying party; and in response to an authentication request while outside of the legitimate user state, providing the authentication assurance level based on a distance between the measured user behavior and the recorded reference data.

Claims (71)

1. A method comprising:

entering into a legitimate user state on a client device for a specified time period following a first explicit authentication by an end user;

recording reference data related to user behavior while in the legitimate user state;

measuring user behavior when outside of the legitimate user state and arriving at an authentication assurance level based on a distance between the measured user behavior and the recorded reference data;

entering into a first transaction with a relying party over a network resulting in an authentication request from the relying party;

in response to receiving the authentication request within the legitimate user state, transmitting an authentication assurance level at or above a defined threshold from the client device to the relying party over the network, the authentication assurance level being sufficient to authenticate the user to the relying party, and the relying party to responsively allow the first transaction; and

in response to an authentication request while outside of the legitimate user state, transmitting the authentication assurance level based on a distance between the measured user behavior and the recorded reference data from the client device to the relying party over the network;

wherein in response to receiving the authentication assurance level, determining at the relying party whether the authentication assurance level is acceptable to complete the first transaction, wherein if the assurance level is acceptable, then the relying party to responsively allow the first transaction and wherein if the assurance level is not acceptable, then the relying party to transmit a response requesting additional authentication, the method further comprising:

performing a second explicit authentication by the end user on the client device to re-enter the legitimate user state; and

transmitting an authentication assurance level from the client device to the relying party, and the relying party to responsively allow the first transaction.

2. The method as in claim 1 wherein the first and second explicit authentications by the end user comprises the user entering a secret identification code or swiping a finger on a fingerprint authenticator on the client device.

3. The method as in claim 1 wherein recording the reference data based on user behavior comprises using sensors and associated hardware and/or software on the client device to measure gait of the user as the user is walking, the reference data defining a reference gait of the user.

4. The method as in claim 1 wherein recording the reference data based on user behavior comprises using sensors and associated hardware and/or software on the client device to measure locations of the client device while in the legitimate user state, the reference data defining a set of reference locations.

5. The method as in claim 4 wherein in addition to measuring locations of the client device while in the legitimate user state, the client device allows the user to specify certain locations as trusted regions.

6. The method as in claim 1 wherein recording the reference data based on user behavior comprises using sensors and associated hardware and/or software on the client device to measure one or more of the following variables to be used as reference data:

networks or devices to which the client device is connected;

smart watches;

Bluetooth devices;

near field communication (NFC) devices;

other computing devices;

Nymi bracelets;

Wifi networks in reach;

Wifi-enabled computers in reach;

acceleration sensor characteristics;

digital camera sensor pattern noise;

touch screen gestures of normal user interaction; and

user typing behavior from normal user interaction.

7. The method as in claim 1 further comprising:

continuing to record reference data related to user behavior for an extended window of time outside the legitimate user state.

8. The method as in claim 1 wherein the client device provides for multiple forms of explicit user authentication, wherein at least some forms of explicit user authentication will not result in a maximum assurance level.

9. The method as in claim 1 further comprising:

encrypting the assurance level using a key prior to transmitting the assurance level to the relying party.

10. The method as in claim 1 wherein the explicit authentication by the end user comprises requiring user interaction in order to trigger and/or unlock the explicit authentication.

11. The method as in claim 10 wherein the user interaction comprises selecting a button or tapping on the client device.

12. The method as in claim 1 wherein the relying party initially specifies a required assurance level for a particular transaction and the assurance level gain is selected to ensure that the required assurance level is met.

13. An client device having a memory for storing program code and a processor for processing the program code, the client device comprising:

an explicit user authenticator comprising at least one biometric sensor or keypad to perform a first explicit authentication of an end user, the explicit user authenticator to cause the client device to enter into a legitimate user state for a specified time period following the first explicit authentication; and

one or more additional sensors to collect reference data related to user behavior while in the legitimate user state, the one or more sensors in communication with the processor, the processor to perform the operations of:

recording the reference data related to user behavior while in the legitimate user state;

measuring user behavior using the one or more sensors when outside of the legitimate user state and arriving at an authentication assurance level based on a distance between the measured user behavior and the recorded reference data;

entering into a first transaction with a relying party over a network resulting in an authentication request from the relying party;

in response to receiving the authentication request within the legitimate user state, transmitting an authentication assurance level at or above a defined threshold from the client device to the relying party over the network, the authentication assurance level being sufficient to authenticate the user to the relying party, and the relying party to responsively allow the first transaction; and

in response to an authentication request while outside of the legitimate user state, transmitting the authentication assurance level based on a distance between the measured user behavior and the recorded reference data from the client device to the relying party over the network;

wherein in response to receiving the authentication assurance level, determining at the relying party whether the authentication assurance level is acceptable to complete the first transaction, wherein if the assurance level is acceptable, then the relying party to responsively allow the first transaction and wherein if the assurance level is not acceptable, then the relying party to transmit a response requesting additional authentication, the processor to perform the additional operations of:

performing a second explicit authentication by the end user on the client device to re-enter the legitimate user state; and

transmitting an authentication assurance level from the client device to the relying party, and the relying party to responsively allow the first transaction.

14. The client device as in claim 13 wherein the first and second explicit authentications by the end user comprises the user entering a secret identification code or swiping a finger on a fingerprint authenticator on the client device.

15. The client device as in claim 13 wherein recording the reference data based on user behavior comprises using sensors and associated hardware and/or software on the client device to measure gait of the user as the user is walking, the reference data defining a reference gait of the user.

16. The client device as in claim 13 wherein recording the reference data based on user behavior comprises using sensors and associated hardware and/or software on the client device to measure locations of the client device while in the legitimate user state, the reference data defining a set of reference locations.

17. The client device as in claim 16 wherein in addition to measuring locations of the client device while in the legitimate user state, the non-intrusive privacy-preserving authenticator allows the user to specify certain locations as trusted regions.

18. The client device as in claim 13 wherein recording the reference data based on user behavior comprises using sensors and associated hardware and/or software on the client device to measure one or more of the following variables to be used as reference data:

networks or devices to which the client device is connected;

smart watches;

Bluetooth devices;

near field communication (NFC) devices;

other computing devices;

Nymi bracelets;

Wifi networks in reach;

Wifi-enabled computers in reach;

acceleration sensor characteristics;

digital camera sensor pattern noise;

touch screen gestures of normal user interaction; and

user typing behavior from normal user interaction.

19. The client device as in claim 13 wherein the non-intrusive privacy-preserving authenticator continues to record reference data related to user behavior for an extended window of time outside the legitimate user state.

20. The client device as in claim 13 wherein the client device provides for multiple forms of explicit user authentication, wherein at least some forms of explicit user authentication will not result in a maximum assurance level.

21. The client device as in claim 13 further comprising:

a secure communication module to encrypt the assurance level using a key prior to transmitting the assurance level to the relying party.

22. The client device as in claim 13 wherein the explicit authentication by the end user comprises requiring user interaction in order to trigger and/or unlock the explicit authentication.

23. The client device as in claim 22 wherein the user interaction comprises selecting a button or tapping on the client device.

24. The client device as in claim 13 wherein the relying party initially specifies a required assurance level for a particular transaction and the assurance level gain is selected to ensure that the required assurance level is met.

25. The client device as in claim 24 wherein explicit user authentication is required if the calculated assurance level does not reach the required assurance level.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 71257 FRAME: 566. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2025
From: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 073057/0274 →
SECURITY INTEREST Recorded Jul 1, 2025
From: NOK NOK LABS, INC.
To: MUFG BANK, LTD.
Reel/Frame 071773/0493 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY RECORDED PATENT APPLICATION NUMBER 14488747 PREVIOUSLY RECORDED ON REEL 71273 FRAME 25. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Jun 18, 2025
From: VENTURE LENDING & LEASING IX, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071773/0352 →
RELEASE OF SECURITY INTEREST Recorded May 30, 2025
From: VENTURE LENDING & LEASING VIII, INC.; VENTURE LENDING & LEASING IX, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071273/0025 →
RELEASE OF SECURITY INTEREST Recorded May 29, 2025
From: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071257/0566 →
SECURITY INTEREST Recorded Jul 5, 2018
From: NOK NOK LABS, INC.
To: VENTURE LENDING & LEASING IX, INC.; VENTURE LENDING & LEASING VIII, INC.
Reel/Frame 046492/0870 →
SECURITY INTEREST Recorded Jan 12, 2017
From: NOK NOK LABS, INC.
To: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
Reel/Frame 041352/0867 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2014
From: LINDEMANN, ROLF
To: NOK NOK LABS, INC.
Reel/Frame 032234/0144 →
Continuity (2)
Provisional Application 61804568 · Mar 22, 2013
Related Publication 20140289819A1 · Sep 25, 2014