IP Library Granted Patent US 10,965,667
Granted Patent B2
US 10,965,667 · App. 16/708,270 · Granted Mar 30, 2021

Protection from unfamiliar login locations

Inventors: David Steeves (Seattle, WA); Luke Abrams (Seattle, WA); Hersh Dangayach (White Plains, NY); Eric Fleischman (Redmond, WA); Prabu Raju (Issaquah, WA); Krishna Vitaldevara (Fremont, CA); Niyantha Shekar (Bellevue, WA); Payoj Baral (Redmond, WA); Meenakshi Ramaswamy (Bellevue, WA); Winfred Wong (Redmond, WA); Yordan Rouskov (Kirkland, WA); Ramesh Manne (Redmond, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/083G06F21/31G06F21/316H04L61/609H04L63/08H04L67/22H04L67/306H04W4/029G06F2221/2111
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,965,667
App. No.
16/708,270
Granted
Mar 30, 2021
Kind
B2
Abstract

In one embodiment, a user authentication server may use geo-location tracking to determine whether to present an enhanced identity challenge. A communication interface 180 may receive a user login attempt by a user and a current location of the user login attempt. A data storage 150 may store a user location profile of the user. A processor 120 may execute a comparison of the current location to the user location profile. The communication interface 180 may present the user with an enhanced identity challenge before allowing user access based on the comparison.

Claims (43)

1. A user authentication server, comprising:

a communication interface configured to receive a user login attempt by a user and a current location of the user login attempt;

a data storage configured to store a user location profile of the user identifying a familiar location based on a login location history describing a location for a verified user login attempt, wherein the familiar location is removed from the user location profile after a time according to a defined condition based on a temporal status of the familiar location described in the login location history; and

a processor device configured to:

execute a comparison of the current location of the user login attempt to the familiar location of the user location profile,

based at least on the current location of the user login attempt being within the familiar location, not present an enhanced identity challenge during the user login attempt;

based at least on the current location being outside the familiar location and the user login attempt being made via an untrusted device, present the enhanced identity challenge for answering by the user before allowing user access, and

based at least on the current location being outside the familiar location while the user login attempt being made via a trusted device, not present the enhanced identity challenge.

2. The user authentication server of claim 1 , wherein the data storage is configured to update the user location profile to store the current location as a new familiar location upon successful response to the enhanced identity challenge.

3. The user authentication server of claim 1 , wherein the data storage is configured to track in the user location profile a previous location of the user.

4. The user authentication server of claim 1 , wherein the processor is configured to determine whether an immediately previous location is within traveling distance of the current location and to select a challenge level for the enhanced identity challenge based on whether the current location is within traveling distance.

5. The user authentication server of claim 1 , wherein the communication interface is configured to send the user a high difficulty identity challenge as an enhanced identity challenge if the current location is not within traveling distance.

6. The user authentication server of claim 1 , wherein the data storage is configured to mark a user account as a compromised account upon a failed response to the enhanced identity challenge.

7. The user authentication server of claim 6 , wherein the data storage is further configured to clear a familiar location list upon the failed response to the enhanced identity challenge.

8. The user authentication server of claim 1 , wherein the communication interface is configured to collect a low difficulty identity challenge response and a high difficulty identity challenge response.

9. The user authentication server of claim 1 , wherein the processor is configured to determine a home region based on the login location history.

10. The user authentication server of claim 1 , wherein the processor is configured to resize the home region based on at least one of user activity and system configuration.

11. The user authentication server of claim 1 , wherein the processor is configured to present the user with the enhanced identity challenge when an unfamiliar login location counter exceeds an unfamiliar login location threshold.

12. The user authentication server of claim 1 , further comprising:

an unfamiliar login location counter configured to decrement upon successful response to the enhanced identity challenge.

13. A computing device being configured to:

store in a memory a user location profile of a user identifying a familiar location based on a login location history describing a location for a verified user login attempt, wherein the familiar location is removed from the user location profile after a time according to a defined condition based on a temporal status of the familiar location described in the login location history,

recognize a current location of a user login attempt to a user service,

execute a comparison of the current location of the user login attempt to the familiar location of the user location profile,

based at least on the current location of the user login attempt being within the familiar location, not present an enhanced identity challenge during the user login attempt;

based at least on the current location being outside the familiar location and the user login attempt being made via an untrusted device, present a user with the enhanced identity challenge for answering by the user before allowing user access, and

based at least on the current location being outside the familiar location while the user login attempt being made via a trusted device, not present the enhanced identity challenge.

14. The computing device of claim 13 , wherein the computing device is further configured to mark a user account as a compromised account upon a failed response to the enhanced identity challenge.

15. The computing device of claim 13 , wherein the computing device is further configured to clear a familiar location list of a compromised account.

16. The computing device of claim 13 , wherein the computing device is further configured to factor whether the user login attempt is from a trusted device into a determination to present the enhanced identity challenge.

17. The computing device of claim 13 , wherein the computing device is further configured to select a challenge level for the enhanced identity challenge based on whether the current location is a fraud hotspot.

18. A machine-implemented method for authenticating a user session, comprising:

storing in a memory a user location profile of a user identifying a familiar location describing a location for a verified user login attempt, wherein the familiar location is removed from the user location profile after a time according to a defined condition based on a temporal status of the familiar location described in the user location profile of the user in the memory;

recognizing a current location of a user login attempt to a user service over a communication interface;

using at least one hardware processor to implement:

executing a comparison of the current location to the familiar location of the user location profile;

based at least on the current location of the user login attempt being within the familiar location, not present an enhanced identity challenge during the user login attempt;

based at least on the current location being outside of the familiar location and the user login attempt being made via an untrusted device, presenting the user with a higher difficulty enhanced identity challenge for answering by the user before allowing user access; and

based at least on the current location being outside the familiar location while the user login attempt being made via a trusted device, not presenting the higher difficulty enhanced identity challenge.

19. The method of claim 18 , further comprising:

marking a user account as a compromised account upon a failed response to the enhanced identity challenge.

20. The method of claim 18 , further comprising:

based at least on the current location being outside the familiar location while the user login attempt being made via a trusted device, presenting a lower difficulty enhanced identity challenge.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2019
From: STEEVES, DAVID; ABRAMS, LUKE; DANGAYACH, HERSH; FLEISCHMAN, ERIC; RAJU, PRABU; VITALDEVARA, KRISHNA; SHEKAR, NIYANTHA; BARAL, PAYOJ; RAMASWAMY, MEENAKSHI; WONG, WINFRED; ROUSKOV, YORDAN; MANNE, RAMESH
To: MICROSOFT CORPORATION
Reel/Frame 051222/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2019
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 051222/0546 →