IP Library › Granted Patent US 12,130,898
Granted Patent B2
US 12,130,898 · App. 17/486,069 · Granted Oct 29, 2024

Systems and methods for verifying user identity based on a chain of events

Inventors: Alexander Tormasov (Moscow, RU); Noam Herold (Raanana, IL); Yury Averkiev (Singapore, SG); Serguei Beloussov (Costa del Sol, SG); Stanislav Protasov (Singapore, SG)
Assignee: Acronis International GmbH
G06F21/316G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,130,898
App. No.
17/486,069
Granted
Oct 29, 2024
Kind
B2
Abstract

Disclosed herein are systems and method for verifying user identity. In one exemplary aspect, a method comprises receiving sensor data from at least one sensor and parsing the sensor data to determine a plurality of identifiers of a user authorized to access data via a computing device. The method comprises generating, for each identifier, an event including the user. The method comprises intercepting, on the computing device, a data access request including an identifier of the user. The method comprises verifying whether the data access request is from the user authorized to access data by generating a chain of events including the user for a period of time preceding the data access request, determining a deviation of the chain of events from a target chain of events, and in response to determining the deviation is less than a threshold deviation value, granting the data access request.

Claims (57)

1. A method for verifying user identity based on a chain of events, the method comprising:

receiving sensor data from at least one sensor in an environment;

parsing the sensor data to determine a plurality of identifiers of a user authorized to access data via a computing device;

generating, for each identifier of the plurality of identifiers, an event including the user, wherein each event includes an action performed at a particular location during a respective timestamp and a sensor identifier of a sensor that detected the action;

intercepting a data access request on the computing device, wherein the data access request includes an identifier of the user authorized to access the data;

verifying whether the data access request is from the user authorized to access data by:

generating a chain of events for a period of time preceding the data access request, wherein the chain of events includes generated events including the user ordered based on each respective timestamp;

determining a deviation of the chain of events from a target chain of events that is indicative of verified access by the user;

determining whether the chain of events is illogical such that an order in which events occur is not physically possible; and

in response to determining the deviation is less than a threshold deviation value and that the chain of events is not illogical, verifying that the data access request is from the user and granting the data access request.

2. The method of claim 1 , further comprising:

in response to determining that the deviation is not less than the threshold deviation value, not verifying that the data access request is from the user and blocking the data access request.

3. The method of claim 1 , wherein the data access request is of a first type of data access from a plurality of types, further comprising:

identifying the target chain of events by determining that the target chain of events is of the first type of data access.

4. The method of claim 3 , wherein the first type of data access is access from a computing device fixed at a particular location, wherein the target chain of events indicates a progression of the user entering the particular location and accessing the computing device.

5. The method of claim 3 , wherein the first type of data access is access from a computing device that is portable, wherein the target chain of events indicates a progression of the user performing actions on the computing device to initiate the data access request.

6. The method of claim 1 , wherein the deviation is a function of an order of events and an amount of time allocated for each event.

7. The method of claim 6 , wherein each respective event in the target chain of events is assigned a weight indicative of an importance of the respective event.

8. The method of claim 1 , wherein the target chain of events is a historic chain of events performed by the user prior to a previous data access.

9. The method of claim 1 , further comprising:

identifying a discrepancy in a sequence of the chain of events, wherein the discrepancy indicates that the user cannot physically access the computing device; and

not verifying the data access request and blocking the data access request.

10. A system for verifying user identity based on a chain of events, the system comprising:

a hardware processor configured to:

receive sensor data from at least one sensor in an environment;

parse the sensor data to determine a plurality of identifiers of a user authorized to access data via a computing device;

generate, for each identifier of the plurality of identifiers, an event including the user, wherein each event includes an action performed at a particular location during a respective timestamp and a sensor identifier of a sensor that detected the action;

intercept a data access request on the computing device, wherein the data access request includes an identifier of the user authorized to access the data;

verify whether the data access request is from the user authorized to access data by:

generating a chain of events for a period of time preceding the data access request, wherein the chain of events includes generated events including the user ordered based on each respective timestamp;

determining a deviation of the chain of events from a target chain of events that is indicative of verified access by the user;

determining whether the chain of events is illogical such that an order in which events occur is not physically possible; and

in response to determining the deviation is less than a threshold deviation value and that the chain of events is not illogical, verifying that the data access request is from the user and granting the data access request.

11. The system of claim 10 , wherein the hardware processor is further configured to:

in response to determining that the deviation is not less than the threshold deviation value, not verify that the data access request is from the user and block the data access request.

12. The system of claim 10 , wherein the data access request is of a first type of data access from a plurality of types, wherein the hardware processor is further configured to:

identify the target chain of events by determining that the target chain of events is of the first type of data access.

13. The system of claim 12 , wherein the first type of data access is access from a computing device fixed at a particular location, wherein the target chain of events indicates a progression of the user entering the particular location and accessing the computing device.

14. The system of claim 12 , wherein the first type of data access is access from a computing device that is portable, wherein the target chain of events indicates a progression of the user performing actions on the computing device to initiate the data access request.

15. The system of claim 10 , wherein the deviation is a function of an order of events and an amount of time allocated for each event.

16. The system of claim 15 , wherein each respective event in the target chain of events is assigned a weight indicative of an importance of the respective event.

17. The system of claim 10 , wherein the target chain of events is a historic chain of events performed by the user prior to a previous data access.

18. The system of claim 10 , wherein the hardware processor is further configured to:

identify a discrepancy in a sequence of the chain of events, wherein the discrepancy indicates that the user cannot physically access the computing device; and

not verify the data access request and block the data access request.

19. A non-transitory computer readable medium storing thereon computer executable instructions for verifying user identity based on a chain of events, including instructions for:

receiving sensor data from at least one sensor in an environment;

parsing the sensor data to determine a plurality of identifiers of a user authorized to access data via a computing device;

generating, for each identifier of the plurality of identifiers, an event including the user, wherein each event includes an action performed at a particular location during a respective timestamp and a sensor identifier of a sensor that detected the action;

intercepting a data access request on the computing device, wherein the data access request includes an identifier of the user authorized to access the data;

verifying whether the data access request is from the user authorized to access data by:

generating a chain of events for a period of time preceding the data access request, wherein the chain of events includes generated events including the user ordered based on each respective timestamp;

determining a deviation of the chain of events from a target chain of events that is indicative of verified access by the user;

determining whether the chain of events is illogical such that an order in which events occur is not physically possible; and

in response to determining the deviation is less than a threshold deviation value and that the chain of events is not illogical, verifying that the data access request is from the user and granting the data access request.

20. The non-transitory computer readable medium of claim 19 , further comprising instructions for:

in response to determining that the deviation is not less than the threshold deviation value, not verifying that the data access request is from the user and blocking the data access request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2024
From: TORMASOV, ALEXANDER; HEROLD, NOAM; AVERKIEV, YURY; BELOUSSOV, SERGUEI; PROTASOV, STANISLAV
To: ACRONIS INTERNATIONAL GMBH
Reel/Frame 068687/0664 →
Continuity (1)
Related Publication 20230117755A1 · Apr 20, 2023