IP Library › Granted Patent US 12,250,216
Granted Patent B2
US 12,250,216 · App. 17/042,025 · Granted Mar 11, 2025

Method for authenticating a user at a user equipment

Inventors: Frédéric Dao (Gemenos, FR); Thomas Dandelot (Gemenos, FR); Frédéric Paillart (Gemenos, FR); Frédéric Faure (Gemenos, FR); Fabrice Delhoste (Gemenos, FR)
Assignee: THALES DIS FRANCE SAS
H04L63/0884G06N20/00G07C9/22H04W12/06H04W12/30H04W12/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,250,216
App. No.
17/042,025
Granted
Mar 11, 2025
Kind
B2
Abstract

The present invention relates to a method for authentication of a user using a user equipment, comprising an authentication engine for authenticating at least one user, said authentication engine being configured to operate with a local authentication model, wherein the method comprises the step for the user equipment of enhancing its local authentication model by at least one authentication factor, wherein said at least one authentication factor is stored in the local authentication model with a validity indication, indicating the time the authentication factor is valid for taking into account by the authentication engine, and authenticating a user by means of a match of the local authentication model with a set of user behavior indications retrieved by the user equipment through the authentication engine.

Claims (32)

1. A method for authentication of a user using a user equipment, comprising an authentication engine for authenticating at least one user, said authentication engine being configured to operate with a local authentication model, wherein the method comprises the step for the user equipment of enhancing its local authentication model by at least one authentication factor; wherein said at least one authentication factor is stored in the local authentication model with a validity indication, indicating a time the at least one authentication factor is valid for taking into account by the authentication engine, wherein the authentication engine detects temporary modification of user behavior over said predefined period from said validity indications derived from a user input, a predefined default value, and context derivation over a special time, associated with said user behavior; and authenticating a user by means of a match of the local authentication model with a set of user behavior indications retrieved by the user equipment through the authentication engine; wherein, the user equipment further comprising a communication unit for communicating with a central server comprising a central authentication model used for said authentication engine; for providing a first model update message relating to said at least one authentication factor of the local authentication model to the central server, being configured to update the central authentication model based on said first model update message;

retrieving a second model update message from the central server, relating to an update of the central authentication model, said update relating to at least one model update message provided by at least one second user equipment; and enhancing the local authentication model based on the second model update message, wherein the user equipment and the at least one second user equipment belong to the same user, and upon expiration of a predefined period, checking if a change of said local authentication model takes place in order to decide if another model updated message is about to be sent, wherein the step of checking comprises determining if said validity indication of said at least one authentication factor has expired.

2. The method according to claim 1 , comprising after expiry of the predefined period the step of searching at least one authentication factor with expired validity indication in the local authentication model, removing the at least one found authentication factor from the local authentication model.

3. The method according to claim 1 , wherein the authentication engine comprises a plurality of machine learning patterns, comprising in authenticated mode an active machine learning pattern for collecting authentication factors relating to a user interaction, and a passive machine learning pattern for collecting authentication factors by retrieving information through sensors of the user equipment.

4. The method according to claim 1 , wherein said at least one authentication factor comprises at least one out of:

one of the latest user equipment used by the user,

one of the last location the user was situated at,

one of the last persons the user interacted with,

recently determined data retrieved by at least one sensor accessible by the user equipment,

an answer to a question provided through the user equipment.

5. The method according to claim 1 ,

wherein the validity indication of said at least one authentication factor is amended in case a second authentication factor impacting the first authentication factor is determined.

6. The method according to claim 1 ,

wherein, the user equipment further comprising the communication unit for communicating with the central server comprising the central authentication model used for said authentication engine.

7. A user equipment, comprising an authentication engine for authenticating at least one user, said authentication engine being configured to operate with a local authentication model, wherein the user equipment is configured to enhance its local authentication model by at least one authentication factor,

wherein said at least one authentication factor is stored in the local authentication model with a validity indication, indicating a time the at least one authentication factor is valid for taking into account by the authentication engine,

and further the user equipment is configured to authenticate a user by means of a match of the local authentication model with a set of user behavior indications retrieved by the user equipment through the authentication engine, wherein the authentication engine detects temporary modification of user behavior over said predefined period from said validity indications derived from a user input, a predefined default value, and context derivation over a special time, associated with said user behavior:

the user equipment further comprising a communication unit for communicating with a central server comprising a central authentication model used for said authentication engine, wherein the user equipment is configured to:

provide a first model update message relating to said at least one authentication factor of the local authentication model to the central server, being configured to update the central authentication model based on said first model update message;

retrieving a second model update message from the central server, relating to an update of the central authentication model, said update relating to at least one model update message provided by at least one second user equipment;

and enhancing the local authentication model based on the second model update message;

wherein the user equipment and the at least one second user equipment belong to the same user, and upon expiration of a predefined period, checking if a change of said local authentication model takes place in order to decide if another model updated message is about to be sent, wherein the step of checking comprises determining if said validity indication of said at least one authentication factor has expired.

8. The user equipment according to claim 7 , further comprising at least one sensor,

wherein the authentication engine comprises a plurality of machine learning patterns, comprising in authenticated mode an active machine learning pattern for collecting authentication factors relating to a user interaction,

and a passive machine learning pattern for collecting authentication factors by retrieving information through said sensors of the user equipment.

9. The user equipment according to claim 8 , wherein the validity indication of said at least one authentication factor is amended in case a second authentication factor impacting the first authentication factor is determined.

10. The user equipment according to claim 7 ,

the user equipment further comprising the communication unit for communicating with the central server comprising the central authentication model used for said authentication engine.

11. The user equipment according to claim 10 , further configured after expiry of the predefined period to:

search at least one authentication factor with expired validity indication in said local authentication model,

remove said at least one found authentication factor from the local authentication model,

provide a first model update message relating to the removed authentication factor to the central server.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2022
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 058903/0188 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2021
From: DAO, FREDERIC; DANDELOT, THOMAS; PAILLART, FREDERIC; FAURE, FREDERIC; DELHOSTE, FABRICE
To: THALES DIS FRANCE SA
Reel/Frame 055456/0363 →
Priority Claims (1)
EP 18305337 · Mar 27, 2018 · regional
Continuity (1)
Related Publication 20210168141A1 · Jun 3, 2021
References Cited (11)
US 9510204B2 · Haro · 2016 [cited by examiner]
US 9554279B1 · Kremer · 2017 [cited by examiner]
US 20110202466A1 · Carter · 2011 [cited by examiner]
US 20160050308A1 · Liu · 2016 [cited by examiner]
US 20170230363A1 · Deutschmann · 2017 [cited by examiner]
US 20180198614A1 · Neumann · 2018 [cited by examiner]
US 20190061687A1 · Khalil · 2019 [cited by examiner]
EP 2928152A2 · 2015 [cited by applicant]
WO 2017005231A1 · 2017 [cited by applicant]
International Search Report (PCT/ISA/210) mailed on Jul. 31, 2019, by the European Patent Office as the International Searching Authority for International Application No. PCT/EP2019/056606. [cited by applicant]
Written Opinion (PCT/ISA/237) mailed on Jul. 31, 2019, by the European Patent Office as the International Searching Authority for International Application No. PCT/EP2019/056606. [cited by applicant]