IP Library Granted Patent US 9,912,657
Granted Patent B2
US 9,912,657 · App. 14/968,676 · Granted Mar 6, 2018

Adaptive multi-factor authentication system

Inventors: Dipankar Dasgupta (Germantown, TN); Abhijit Kumar Nag (Memphis, TN); Arunava Roy (Memphis, TN)
H04L63/083G06F21/316G06F21/32G06F21/36G06F21/40G06F21/45H04L63/08H04L63/0861H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,912,657
App. No.
14/968,676
Filed
Dec 14, 2015
Granted
Mar 6, 2018
Kind
B2
Examiner
SONG, HOSUK
Art Unit
2435
USPC
726/7
Abstract

A system and methodology for adaptive selection of multiple modalities for authentication in different operating environments, thereby making authentication strategy unpredictable so to significantly reduce the risk of exploitation by authentication-guessing attacks. The system calculates trustworthiness values of different authentication factors under various environmental settings, and combines a trust-based adaptive, robust and scalable software-hardware framework for the selection of authentication factors for continuous and triggered authentication with optimal algorithms to determine the security parameters of each of the authentication factors. A subset of authentication factors thus are determined for application at triggering events on-the-fly, thereby leaving no exploitable a priori pattern or clue for hackers to exploit.

Claims (16)

1. A machine for improved secure access to computing devices, systems, resources, or services, comprising:

one or more computer servers with authentication modality data stored thereon for a plurality of authentication modalities, wherein the authentication modality data for each authentication modality comprises a trustworthiness factor for each of one or more user input devices, a trustworthiness factor for each of one or more user connection media, and a computational complexity cost factor; and

a processor or microprocessor, wherein the processor or microprocessor is programmed to determine one or more of said authentication modalities to use for an authentication verification event by:

determining the objective trustworthiness value for each modality based on device trustworthiness factors and connection media trustworthiness factors for said modality;

determining a penalty value for each modality based on the computation complexity cost factor for said modality and the previous selection history of said modality for previous authentication verification events;

ranking the authentication modalities based on the objective trustworthiness value and the penalty value; and

applying one or more authentication modalities in order of ranking.

2. The machine of claim 1 , wherein the user input devices comprise fixed devices, mobile devices, hand-held devices, or combinations thereof.

3. The machine of claim 1 , wherein the user media environments comprise wired, wireless, cellular, or combinations thereof.

4. The machine of claim 1 , wherein authentication modality data for each authentication modality comprises a list of features applicable to that authentication modality.

5. The machine of claim 4 , wherein one or more features from said list of features are selected for an authentication modality for determining the objective trustworthiness value for that modality.

6. The machine of claim 1 , wherein said authentication modalities comprise one or more of the following modalities: facial recognition, fingerprint recognition, password, CAPTCHA, voice recognition, and keystroke analysis.

7. The machine of claim 1 , wherein the plurality of authentication modalities comprises seven modalities: facial recognition, fingerprint recognition, password, CAPTCHA, voice recognition, and keystroke analysis.

8. The machine of claim 1 , wherein the processor or microprocessor further is programmed to modify one or more trustworthiness factors.

9. The machine of claim 1 , wherein the authentication verification event is an initial request by a user using a user input device to access a computer device, system, resource, or service.

10. The machine of claim 1 , wherein the authentication verification event is an automatic determination of whether to allow a user using a user input device to continue having access a computer device, system, resource, or service.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2022
From: UNIVERSITY OF MEMPHIS
To: UNIVERSITY OF MEMPHIS RESEARCH FOUNDATION
Reel/Frame 059249/0328 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2021
From: UNIVERSITY OF MEMPHIS
To: UNIVERSITY OF MEMPHIS
Reel/Frame 058067/0479 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2021
From: NAG, ABHIJIT KUMAR
To: UNIVERSITY OF MEMPHIS
Reel/Frame 055224/0044 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2021
From: ROY, ARUNANVA
To: UNIVERSITY OF MEMPHIS
Reel/Frame 055224/0100 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2019
From: DASGUPTA, DIPANKAR
To: UNIVERSITY OF MEMPHIS
Reel/Frame 049864/0525 →
Continuity (3)
Provisional Application 62169991 · Jun 2, 2015
Provisional Application 62262626 · Dec 3, 2015
Related Publication 20160359838A1 · Dec 8, 2016