IP Library Granted Patent US 12,147,512
Granted Patent B2
US 12,147,512 · App. 17/826,654 · Granted Nov 19, 2024

Generating authentication template filters using one or more machine-learned models

Inventor: William Charles Suski (Mount Pleasant, SC)
Assignee: Applied Engineering Concepts, Inc.
G06F21/31G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,147,512
App. No.
17/826,654
Granted
Nov 19, 2024
Kind
B2
Abstract

Systems and methods for computing device authentication can involve template matching with an authentication filter. Authentication filters can be generated by using an authentication model to determine or generate templates for authenticated classes. For example, simulated signal data sets can be input into the authentication model until an authenticated class classification is output. The successful simulated signal data set may then be used to generate or update an authentication filter that uses the template for template matching authentication classification.

Claims (60)

1. A computer-implemented method, the method comprising:

obtaining, by a computing system comprising one or more processors, a trained authentication model, wherein the trained authentication model is trained to classify a computing device based on signal data;

determining, by the computing system, an input that the trained authentication model classifies as an authenticated class, wherein the authenticated class is descriptive of authenticated signal data associated with an authenticated computing device, wherein determining, by the computing system, the input that the trained authentication model classifies as the authenticated class comprises: generating, by the computing system, example signal data with an input model, wherein the input model is trained by:

generating, by the computing system, training signal data with the input model;

processing, by the computing system, the training signal data with the trained authentication model to generate an authentication classification;

evaluating, by the computing system, a loss function that evaluates a difference between the authentication classification and the authentication class; and

adjusting, by the computing system, one or more parameters of the input model based at least in part on the loss function;

generating, by the computing system, an authentication filter based on the input; and

storing, by the computing system, the authentication filter for classification.

2. The computer-implemented method of claim 1 , further comprising:

processing, by the computing system, input signal data with the authentication filter to determine an authentication classification for the input signal data.

3. The computer-implemented method of claim 2 , further comprising:

adjusting, by the computing system, network access for a computing device based on the authentication classification, wherein the input signal data is generated by the computing device.

4. The computer-implemented method of claim 1 , wherein the trained authentication model is trained based on labeled signal data.

5. The computer-implemented method of claim 1 , wherein the input model comprises generative neural network.

6. The computer-implemented method of claim 1 , wherein the input model comprises an autoencoder.

7. The computer-implemented method of claim 1 , wherein the input model comprises a long short-term memory model.

8. The computer-implemented method of claim 1 , wherein the input model is trained to:

determine one or more features the trained authentication model uses for authentication classification; and

generate the input based on the one or more features.

9. The computer-implemented method of claim 1 , wherein determining, by the computing system, the input that the trained authentication model classifies as the authenticated class comprises at least one of black box optimization, randomized signal generation, training a machine-learned model, or a genetic algorithm.

10. A computing system for network authentication, the system comprising:

one or more sensors configured to collect a plurality of physical signal samples associated with physical communication signals of a device on a network;

one or more non-transitory computer-readable media that collectively store:

an authentication filter generated based on one or more classification parameters for a trained authentication model, wherein the authentication filter comprises data descriptive of authenticated signal data;

wherein the authentication filter is configured to determine an authentication classification, wherein the authentication classification is determined based at least in part on if obtained signal data is associated with one or more authenticated computing devices;

wherein the authentication filter was generated based at least in part on example signal data generated with an input model, wherein the input model was trained by:

determining an input that a trained authentication model classifies as an authenticated class

generating training signal data with the input model;

processing the training signal data with the trained authentication model to generate the authentication classification;

evaluating a loss function that evaluates a difference between the authentication classification and the authentication class; and

adjusting one or more parameters of the input model based at least in part on the loss function; and

a controller configured to control one or more ports of a network switch or router of the network based on the authentication classification for the device.

11. The computing system of claim 10 , wherein the one or more non-transitory computer-readable media further store:

a second authentication filter generated based on one or more second classification parameters for the trained authentication model, wherein the second authentication filter comprises data descriptive of second authenticated signal data; and

wherein the second authentication filter is configured to determine if obtained signal data is associated with one or more second authenticated computing devices.

12. The computing system of claim 10 , wherein the authenticated signal data comprises data with one or more features determined to match one or more authenticated features of the one or more authenticated computing devices.

13. One or more non-transitory computer readable media that collectively store instructions that, when executed by one or more processors, cause a computing system to perform operations, the operations comprising:

obtaining a trained authentication model, wherein the trained authentication model is trained to classify a computing device based on signal data;

generating training signal data with an input model;

processing the training signal data with the trained authentication model to generate an authentication classification;

evaluating a loss function that evaluates a difference between the authentication classification and an authenticated class, wherein the authenticated class is associated with authenticated signal data generated by an authenticated computing device;

adjusting one or more parameters of the input model based at least in part on the loss function;

determining an input that the trained authentication model classifies as the authenticated class, wherein the authenticated class is descriptive of the authenticated signal data associated with the authenticated computing device; and

generating an authentication filter based on the input.

14. The one or more non-transitory computer readable media of claim 13 , wherein the operations further comprise:

storing the authentication filter for classification.

15. The one or more non-transitory computer readable media of claim 14 , wherein a plurality of authentication filters are generated for an input; and

wherein the operations further comprise:

determining an average filter for the plurality of authentication filters; and

storing the average filter for classification.

16. The one or more non-transitory computer readable media of claim 14 , wherein the trained authentication model comprises:

a first machine-learned model configured to process a plurality of physical signal samples to generate a device fingerprint for a device based at least in part on the plurality of physical signal samples; and

a second machine-learned model configured to process the device fingerprint to generate the authentication classification for the device based at least in part on the device fingerprint.

17. The one or more non-transitory computer readable media of claim 14 , wherein the operations further comprise:

obtaining signal data, wherein the signal data is descriptive of a computing device;

processing the signal data with an encoder model to generate encoded signal data;

determining a signal authentication classification for the encoded signal data based on the authentication filter; and

adjusting network access for the computing device based on the signal authentication classification.

18. The one or more non-transitory computer readable media of claim 13 , wherein the trained authentication model comprises a trained classification model.

Assignments (2)
CONFIRMATORY LICENSE Recorded May 9, 2023
From: APPLIED ENGINEERING CONCEPTS, INCORPORATED
To: UNITED STATES DEPARTMENT OF ENERGY
Reel/Frame 063588/0747 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2022
From: SUSKI, WILLIAM CHARLES
To: APPLIED ENGINEERING CONCEPTS, INC.
Reel/Frame 060865/0207 →
Continuity (2)
Provisional Application 63227712 · Jul 30, 2021
Related Publication 20230035291A1 · Feb 2, 2023