IP Library › Granted Patent US 12,093,357
Granted Patent B2
US 12,093,357 · App. 17/388,592 · Granted Sep 17, 2024

Biometric authentication based on behavioral analysis

Inventors: Joseph Benjamin Castinado (North Glenn, CO); Brandon Ingram (Charlotte, NC); Naoll Addisu Merdassa (Chakopee, MN); Kevin Graham Robberts (Charlotte, NC); Ann Ta (Scottsdale, AZ)
Assignee: BANK OF AMERICA CORPORATION
G06F21/316G06F21/45G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,093,357
App. No.
17/388,592
Granted
Sep 17, 2024
Kind
B2
Abstract

A heightened level of security is provided in a computing platform by monitoring usage of applications and/or services residing on or accessible to a computing platform to determine abnormal usage patterns. In response to determining an abnormal pattern of usage, the user is required to provide biometric data, such as voice data, facial feature data, fingerprint data or the like, as a means of authenticating the user. The abnormal pattern of usage may be determined dynamically by comparing current usage patterns to known user baseline usage patterns. Alternatively, the abnormal pattern of usage is predefined, such as the resetting of passwords in a predefined number of applications and/or services over a predefined period of time.

Claims (31)

1. A system for requiring biometric user authentication, the system comprising:

a first computing platform having a first memory and at least one first processing device in communication with the first memory, wherein the first memory stores a plurality of network-accessible services;

a second computing platform having a second memory and at least one second processing device in communication with the second memory, wherein the second memory stores a plurality of applications; and

a user authentication engine stored in the first memory or the second memory and executable by the at least one first processing device or at least one second processing device and configured to:

monitor usage by a user of the plurality of applications and services, in response to the monitoring, determine a predetermined abnormal pattern of usage amongst at least two of the plurality of applications and services that is contrary to one or more normal patterns of usage of the user, wherein the predetermined abnormal pattern of usage is defined as resetting of passwords within (i) a predetermined number greater than one of the plurality of applications and services and (ii) a predetermined period of time;

in response to determining the predetermined abnormal pattern of usage amongst the at least two of the plurality of applications and services, require the user to authenticate by providing predefined biometric data to further access the plurality of applications and services.

2. The system of claim 1 , wherein the user authentication engine is further configured to:

receive the predefined biometric data and authenticate the user based on a match between the received predefined biometric data and previously stored predefined biometric data.

3. The system of claim 1 , wherein the user authentication engine is further configured to, in response to determining the predetermined abnormal pattern of usage, generate and communicate an alert to a predetermined entity.

4. The system of claim 1 , wherein the user authentication engine is further configured to allow the user to preconfigure at least one of (i) the predetermined number greater than one of the plurality of applications and services for determining the abnormal pattern of usage, and (ii) the predetermined period of time for determining the abnormal pattern of usage.

5. The system of claim 1 , wherein the user authentication engine is configured to require the user to provide predefined biometric data to further access the plurality of applications and services, wherein the predefined biometric data is chosen from the group consisting of voice data, facial feature data and fingerprint data.

6. A computer-implemented method for requiring biometric user authentication, the computer-implemented method is executable by one or more computing processor devices, the method comprising:

monitoring usage, by a user, of a plurality of applications and a plurality of services;

in response to the monitoring, determining predetermined abnormal pattern of usage amongst at least two of the plurality of applications and services that is contrary to one or more normal patterns of usage of the user, wherein the predetermined abnormal pattern of usage is defined as resetting of passwords within (i) a predetermined number greater than one of the plurality of applications and services and (ii) a predetermined period of time; and

in response to determining the predetermined abnormal pattern of usage amongst the at least two of the plurality of applications and services, requiring the user to provide predefined biometric data to further access the plurality of applications and services.

7. The computer-implemented method of claim 6 , further comprising:

receiving the predefined biometric data and authenticating the user based on a match between the received predefined biometric data and previously stored predefined biometric data.

8. The computer-implemented method of claim 6 , further comprising:

in response to determining the predetermined abnormal pattern of usage, generating and communicating an alert to a predetermined entity.

9. The computer-implemented method of claim 6 , further comprising:

providing for the user to preconfigure at least one of (i) the predetermined number greater than one of the plurality of applications and services for determining the abnormal pattern of usage, and (ii) the predetermined period of time for determining the abnormal pattern of usage.

10. The computer-implemented method of claim 6 , wherein requiring the user to provide predefined biometric data further comprises requiring the user to provide predefined biometric data, wherein the predefined biometric data is chosen from the group consisting of voice data, facial feature data and fingerprint data.

11. A computer program product including a non- transitory computer-readable medium, the non-transitory computer-readable medium comprising:

a first set of codes for causing a computer to monitor usage, by a user, of a plurality of applications and a plurality of services;

a second set of codes for causing a computer to, in response to the monitoring, determine a predetermined abnormal pattern of usage amongst at least two of the plurality of applications and services that is contrary to one or more normal patterns of usage of the user, wherein the predetermined abnormal pattern of usage is defined as resetting of passwords within (i) a predetermined number greater than one of the plurality of applications and services and (ii) a predetermined period of time; and

a third set of codes for causing a computer to, in response to determining the predetermined abnormal pattern of usage amongst the at least two of the plurality of applications and services, require the user to provide predefined biometric data to further access the plurality of applications and services.

12. The computer program product of claim 11 , wherein the computer-readable medium further comprises:

a fourth set of codes for causing a computer to receive the predefined biometric data and authenticate the user based on a match between the received predefined biometric data and previously stored predefined biometric data.

13. The computer program product of claim 11 , wherein the third set of codes is further configured to, in response to determining the predetermined abnormal pattern of usage, generate and communicate an alert to a predetermined entity.

14. The computer program product of claim 11 , further comprising a fourth set of codes for causing a computer to provide for the user to preconfigure at least one of (i) the predetermined number greater than one of the plurality of applications and services for determining the abnormal pattern of usage, and (ii) the predetermined period of time for determining the abnormal pattern of usage.

15. The computer program product of claim 11 , wherein the third set of codes is further configured to, in response to determining the predetermined abnormal pattern of usage, require the user to provide the predefined biometric data to further access the plurality of applications and services, wherein the predefined biometric data is chosen from the group consisting of voice data, facial feature data and fingerprint data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2021
From: CASTINADO, JOSEPH BENJAMIN; INGRAM, BRANDON; MERDASSA, NAOLL ADDISU; ROBBERTS, KEVIN GRAHAM; TA, ANN
To: BANK OF AMERICA CORPORATION
Reel/Frame 057022/0734 →
Continuity (1)
Related Publication 20230033954A1 · Feb 2, 2023