IP Library Granted Patent US 10,187,369
Granted Patent B2
US 10,187,369 · App. 15/464,153 · Granted Jan 22, 2019

Systems and methods to authenticate users and/or control access made by users on a computer network based on scanning elements for inspection according to changes made in a relation graph

Inventors: Jose Caldera (Palo Alto, CA); Kieran Sherlock (Palo Alto, CA); Neal Jared Reiter (San Jose, CA)
Assignee: IDM GLOBAL, INC.
H04L63/08H04L67/22H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,187,369
App. No.
15/464,153
Granted
Jan 22, 2019
Kind
B2
Abstract

A controller for user authentication and access control, configured to: store data representing a graph having: nodes representing data elements associated with accesses made using an access token; and links among the nodes representing connections between the data elements identified in details of the accesses. In response to receiving details of an access made using the access token, the controller updates the graph according to the details and identifies changes in the graph resulting from update. For each of the changes, the controller identifies a set of elements in the graph that are up to a predetermined number of degrees of separate from the change and evaluates the trustworthiness of user identities corresponding to the set of elements identified for the change. Based on the trustworthiness, the controller authenticates the user of the access and/or controls the access.

Claims (63)

1. A controller for user authentication and access control, the controller comprising:

at least one microprocessor;

a network interface controlled by the at least one microprocessor to communicate over a computer network with at least one computing site; and

memory coupled with the at least one microprocessor and storing:

graph data representing a graph having:

nodes representing data elements associated with accesses made using access tokens, including first nodes representing the access tokens and second nodes representing attributes of the accesses, and

links among the nodes representing connections between the data elements identified in collected data about the accesses, including connects between the access tokens and the attributes of the accesses;

instructions which, when executed by the at least one microprocessor, cause the controller to process an access made using an access token based on changes to the graph caused by the access, including:

receive, from the computing site, input data specifying details of the access made using the access token;

update the graph according to the input data of the access made using the access token;

identify the changes in the graph resulting from updating the graph according to the input data of the access made using the access token;

identify, for each respective change among the changes resulting from the updating of the graph caused by the access made using the access token, a first set of elements corresponding to nodes in the graph that are up to a first predetermined number of degrees of separation from the respective change;

evaluate trustworthiness of first user identities corresponding to the first set of elements, wherein the trustworthiness of the first user identities is based on a trust score;

process the access made using the access token based on the trustworthiness of the first user identities corresponding to the first set of elements; and

in response to a determination that the trustworthiness of the first user identities does not meet a predetermined requirement:

identify a second set of elements corresponding to nodes in the graph that are up to a second predetermined number of degrees of separation from the respective change, wherein the second predetermined number of degrees of separation is larger than the first predetermined number of degrees of separation;

evaluate trustworthiness of second user identities corresponding to the second set of elements; and

process the access made using the access token based at least in part on the trustworthiness of the second user identities corresponding to the second set of elements.

2. The controller of claim 1 , wherein the trustworthiness of the first user identities is evaluated by comparing the first user identities to a list to determine whether any of the first user identities is on the list.

3. The controller of claim 2 , wherein the list includes user identities of a predetermined category.

4. The controller of claim 3 , wherein the predetermined category is one of: fake, and suspicious.

5. The controller of claim 1 , wherein the second set of elements includes the first set of elements.

6. The controller of claim 1 , wherein the predetermined requirement is based on a count of a subset of the first user identities that are on a list of user identities of a predetermined category.

7. The controller of claim 6 , wherein the controller communicates with the computing site to block the access in response to a determination that a count of a subset of the second user identifies that are on the list is above a threshold.

8. The controller of claim 1 , wherein the graph is identified for update based on the access token.

9. The controller of claim 1 , wherein the graph is identified for update based on a user identity of the access.

10. The controller of claim 9 , wherein the user identity is determined based on an electronic signature generated from the input data.

11. The controller of claim 1 , wherein the graph is generated based on a cluster of access activities after identifying the cluster from a set of access activities using a statistical cluster analysis.

12. The controller of claim 1 , wherein the graph is extracted from a second graph based on a node selected according to the input data and a predetermined number of degrees of separation from the selected node.

13. The controller of claim 1 , wherein in processing the access made using the access token, the controller determines from the graph data a score representing a risk of the access being fraudulent.

14. A non-transitory computer storage medium storing instructions which when executed by a controller, cause the controller to perform a set of steps for user authentication and access control, the set of steps comprising:

storing, in the controller coupled to a network, graph data representing a graph having:

nodes representing data elements associated with accesses made using access tokens, including first nodes representing the access tokens and second nodes representing attributes of the accesses, and

links among the nodes representing connections between the data elements identified in collected data about the accesses, including connects between the access tokens and the attributes of the accesses; and

processing an access made using an access token based on changes to the graph caused by the access, by at least:

receiving, in the controller over the network from a computing site, input data specifying details of access made using access token;

updating, by the controller, the graph according to the input data of the access made using the access token;

identifying, by the controller, the changes in the graph resulting from updating the graph according to the input data of the access made using the access token;

identifying, by the controller for each respective change among the changes resulting from the updating of the graph caused by the access made using the access token, a first set of elements corresponding to nodes in the graph that are up to a first predetermined number of degrees of separation from the respective change;

evaluating, by the controller, trustworthiness of first user identities corresponding to the first set of elements, wherein the trustworthiness of the first user identities is based on a trust score;

processing, by the controller, the access made using the access token based on the trustworthiness of the first user identities corresponding to the first set of elements; and

in response to a determination that the trustworthiness of the first user identities does not meet a predetermined requirement:

identifying a second set of elements corresponding to nodes in the graph that are up to a second predetermined number of degrees of separation from the respective change, wherein the second predetermined number of degrees of separation is larger than the first predetermined number of degrees of separation;

evaluating trustworthiness of second user identities corresponding to the second set of elements; and

processing the access made using the access token based at least in part on the trustworthiness of the second user identities corresponding to the second set of elements.

15. A method for user authentication and access control, the method comprising:

storing, in a controller coupled to a network, graph data representing a graph having:

nodes representing data elements associated with accesses made using access tokens, including first nodes representing the access tokens and second nodes representing attributes of the accesses, and

links among the nodes representing connections between the data elements identified in collected data about the accesses, including connects between the access tokens and the attributes of the accesses; and

processing an access made using an access token based on changes to the graph caused by the access, by at least:

receiving, in the controller over the network from a computing site, input data specifying details of the access made using the access token;

updating, by the controller, the graph according to the input data of the access made using the access token;

identifying, by the controller, the changes in the graph resulting from updating the graph according to the input data of the access made using the access token;

identifying, by the controller for each respective change among the changes resulting from the updating of the graph caused by the access made using the access token, a first set of elements corresponding to nodes in the graph that are up to a first predetermined number of degrees of separation from the respective change;

evaluating, by the controller, trustworthiness of first user identities corresponding to the first set of elements, wherein the trustworthiness of the first user identities is based on a trust score;

processing, by the controller, the access made using the access token based on the trustworthiness of the first user identities corresponding to the first set of elements;

making a determination by the controller that the trustworthiness of the first user identities does not meet a predetermined requirement; and

in response to the determination:

identifying, by the controller, a second set of elements corresponding to nodes in the graph that are up to a second predetermined number of degrees of separation from the respective change, wherein the second predetermined number of degrees of separation is larger than the first predetermined number of degrees of separation;

evaluating trustworthiness of second user identities corresponding to the second set of elements; and

processing the access made using the access token based at least in part on the trustworthiness of the second user identities corresponding to the second set of elements.

16. The method of claim 15 , wherein the trustworthiness of the second user identities is based on a count of a subset of the second user identities that are on a list of user identities of a predetermined category.

17. The method of claim 15 , wherein the trustworthiness of the first user identities is based on presence of the first user identities on a list of user identities of a predetermined category.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CRESTLINE DIRECT FINANCE, L.P., AS COLLATERAL AGENT
To: IDENTITYMIND GLOBAL INC.
Reel/Frame 058234/0781 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2021
From: IDENTITYMIND GLOBAL, INC.
To: ACUANT, INC.
Reel/Frame 054939/0553 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2020
From: IDENTIFYMIND GLOBAL INC.
To: ACUANT INC.
Reel/Frame 054052/0499 →
SECURITY INTEREST Recorded Sep 18, 2019
From: IDENTITYMIND GLOBAL INC.
To: CRESTLINE DIRECT FINANCE, L.P., AS COLLATERAL AGENT FOR THE BENEFIT OF SECURED PARTIES
Reel/Frame 050409/0826 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2019
From: IDM GLOBAL, INC.
To: IDENTITYMIND GLOBAL, INC.
Reel/Frame 050185/0369 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2017
From: CALDERA, JOSE; SHERLOCK, KIERAN; REITER, NEAL JARED
To: IDM GLOBAL, INC.
Reel/Frame 041649/0059 →
Continuity (3)
Provisional Application 62429555 · Dec 2, 2016
Provisional Application 62402076 · Sep 30, 2016
Related Publication 20180097790A1 · Apr 5, 2018
Cited By (7)
US 12,212,581 US 12,254,435 US 12,346,487 US 12,470,593 US 12,572,846 US 12,574,399 US 12,695,752