IP Library › Granted Patent US 12,346,426
Granted Patent B2
US 12,346,426 · App. 17/947,667 · Granted Jul 1, 2025

Computer authentication using knowledge of former devices

Inventors: Abdelkader M'hamed Benkreira (Washington, DC); Joshua Edwards (Philadelphia, PA); Michael Mossoba (Great Falls, VA)
Assignee: Capital One Services, LLC
G06F21/34G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,346,426
App. No.
17/947,667
Granted
Jul 1, 2025
Kind
B2
Abstract

Methods, systems, and apparatuses are described herein for improving computer authentication processes through computer-based authentication in a manner that uses knowledge of former devices. A computing device may train a machine learning model to output an indication of device reliability data associated with a particular device. The computing device may receive a request for access to an account from a user. The computing device may receive account data and provide the account data to the trained machine learning model. The computing device may receive data indicating device reliability for a set of devices from the machine learning model. The computing device may generate a modified set of device choices for the user by excluding devices having reliability levels below a threshold value. An authentication question may be generated, and access to the account may be provided based on a response to the authentication question.

Claims (86)

1. A computing device comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the computing device to:

train, using training data comprising account records from a plurality of different users, a first machine learning model to output, for a particular device, an indication of device reliability data associated with the particular device, wherein the account records are associated with a plurality of devices used by the plurality of different users to access one or more accounts in the account records;

receive, from a user device, a request for access to an account associated with a user;

receive, from one or more databases, account data corresponding to the account,

wherein the account data indicates one or more logins originated from the user;

determine, based on the account data, device history comprising a set of devices used by the user to login to the account within a predetermined period of time;

provide, as input to the trained first machine learning model, the account data;

receive, from the trained first machine learning model, data indicating device reliability for the set of devices;

determining, based on the device history, one or more false devices that the user has not used to access the account for the predetermined period of time;

generate, based on the data indicating device reliability for the set of devices, a set of modified device choices by excluding one or more devices having corresponding reliability levels below a threshold value, from the set of devices, wherein the set of modified device choices comprise the one or more false devices;

generate an authentication question comprising at least one device choice from the modified set of device choices;

generate, based on the account data and the modified set of device choices, a correct answer to the authentication question;

provide the authentication question to the user device;

receive, from the user device, a response to the authentication question;

compare the response to the authentication question to the correct answer; and

grant the user device access to the account based on the response to the authentication question matching the correct answer.

2. The computing device of claim 1 , wherein the training data comprises device information for the plurality of devices used by the plurality of different users comprising:

a frequency of use for each device of the plurality of devices,

a duration of use for each device of the plurality of devices, and

a time lapsed since a last use for each device of the plurality of devices.

3. The computing device of claim 1 wherein the training data comprises web browser information corresponding to a web browser executed by the plurality of devices used by the plurality of different users.

4. The computing device of claim 1 , wherein the training data comprises account information comprising:

one or more questions previously presented to the plurality of different users, and

responses from the plurality of different users.

5. The computing device of claim 1 , wherein the training data comprises transaction information indicating whether transactions conducted by the plurality of devices were fraudulent.

6. The computing device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

train, based on second training data comprising a history of authentication records, a second machine learning model to determine recommended reliability thresholds, wherein the history of authentication records comprise authentication questions and responses associated with different type of devices used by the plurality of different users and the corresponding scoring schemes;

provide, as input to the trained second machine learning model, input data comprising the authentication question and the response to the authentication question from the user; and

receive, as output from the trained second machine learning model, output data indicating a recommended threshold value associated with the user.

7. The computing device of claim 6 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

receive user feedback information indicating whether the set of devices associated with the account data were valid candidates; and

based on the user feedback information, re-train the second machine learning model to modify the recommended threshold value associated with the set of devices.

8. The computing device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

generate the authentication question comprising a first device from the modified set of device choices and a second device that is not included in the set of devices, wherein the first device and the second device are associated with a same device manufacturer.

9. The computing device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

generate the authentication question comprising a first device from the modified set of device choices and a second device that is not included in the set of devices, wherein the first device and the second device are associated with a similar price point.

10. The computing device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

generate the authentication question comprising a first device from the modified set of device choices and a second device that is not included in the set of devices, wherein the first device and the second device are available at a same period of time.

11. The computing device of claim 1 , wherein the set of modified device choices comprise one or more real devices that the user has used to access the account for the predetermined period of time.

12. A method comprising:

training, using training data comprising account records from a plurality of different users, a first machine learning model to output, for a particular device, an indication of device reliability data associated with the particular device, wherein the account records are associated with a plurality of devices used by the plurality of different users to access one or more accounts in the account records;

receiving, from a user device, a request for access to an account associated with a user;

receiving, from one or more databases, account data corresponding to the account,

wherein the account data indicates one or more logins originated from the user;

determining, based on the account data, device history comprising a set of devices used by the user to login to the account within a predetermined period of time;

providing, as input to the trained first machine learning model, the account data;

receiving, from the trained first machine learning model, data indicating device reliability of the set of devices;

determining, based on the device history, one or more false devices that the user has not used to access the account for the predetermined period of time;

generating, based on the data indicating device reliability of the set of devices, a set of modified device choices by excluding one or more devices having corresponding confidence levels below a threshold value, from the set of devices, wherein the set of modified device choices comprise the one or more false devices;

generating an authentication question comprising at least one device choice from the modified set of device choices;

generating, based on the account data and the modified set of device choices, a correct answer to the authentication question;

providing the authentication question to the user device;

receiving, from the user device, a response to the authentication question;

comparing the response to the authentication question to the correct answer; and

granting the user device access to the account based on the response to the authentication question matching the correct answer.

13. The method of claim 12 , wherein the training data comprises device information for the plurality of devices used by the plurality of different users comprising:

a frequency of use for each device of the plurality of devices,

a duration of use for each device of the plurality of devices, and

a time lapsed since a last use for each device of the plurality of devices.

14. The method of claim 12 , wherein the training data comprises web browser information corresponding to a web browser executed by the plurality of devices used by the plurality of different users.

15. The method of claim 12 , wherein the training data comprises account information comprising:

one or more questions previously presented to the plurality of different users, and responses from the plurality of different users.

16. The method of claim 12 , wherein the training data comprises transaction information indicating whether transactions conducted by the plurality of devices were fraudulent.

17. One or more non-transitory computer-readable media storing instructions that, when executed by one or more processors, cause a computing device to:

train, using training data comprising account records from a plurality of different users, a first machine learning model to output, for a particular device, an indication of device reliability data associated with the particular device, wherein the account records are associated with a plurality of devices used by the plurality of different users to access one or more accounts in the account records;

receive, from a user device, a request for access to an account associated with a user;

receive, from one or more databases, account data corresponding to the account, wherein the account data indicates one or more logins originated from the user;

determine, based on the account data, device history comprising a set of devices used by the user to login to the account within a predetermined period of time;

provide, as input to the trained first machine learning model, the account data;

receive, from the trained first machine learning model, data indicating device reliability of the set of devices;

determining, based on the device history, one or more false devices that the user has not used to access the account for the predetermined period of time;

generate, based on the data indicating device reliability of the set of devices, a set of modified device choices by excluding one or more devices having corresponding confidence levels below a threshold value, from the set of devices, wherein the set of modified device choices comprise the one or more false devices;

generate an authentication question comprising at least one device choice from the modified set of device choices;

generate, based on the account data and the modified set of device choices, a correct answer to the authentication question;

provide the authentication question to the user device;

receive, from the user device, a response to the authentication question;

compare the response to the authentication question to the correct answer; and

grant the user device access to the account based on the response to the authentication question matching the correct answer.

18. The computer-readable media of claim 17 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

generate the authentication question comprising a first device from the modified set of device choices and a second device that is not included in the set of devices, wherein the first device and the second device are associated with a same device manufacturer.

19. The computer-readable media of claim 17 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

generate the authentication question comprising a first device from the modified set of device choices and a second device that is not included in the set of devices, wherein the first device and the second device are associated with a similar price point.

20. The computer-readable media of claim 17 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

generate the authentication question comprising a first device from the modified set of device choices and a second device that is not included in the set of devices, wherein the first device and the second device are available at a same period of time.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2022
From: BENKREIRA, ABDELKADER M'HAMED; EDWARDS, JOSHUA; MOSSOBA, MICHAEL
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 061284/0506 →
Continuity (1)
Related Publication 20240095327A1 · Mar 21, 2024
References Cited (11)
US 10572653B1 · Semichev · 2020 [cited by examiner]
US 11743330B1 · Gilbert · 2023 [cited by examiner]
US 20170012785A1 · Haga et al. · 2017 [cited by applicant]
US 20200245142A1 · Manepalli et al. · 2020 [cited by applicant]
US 20220286300A1 · Draper · 2022 [cited by examiner]
US 20230196210A1 · Bustelo-Killam · 2023 [cited by examiner]
“Dynamic Knowledge-Based Authentication Asks Customers Out-of-Wallet Questions to Verify Identity & Deter Cybersecurity Fraud,” Idology, a GBC Company, retrieved from: https://www.idology.com/dynamic-kba [Jun. 7, 2021 2… [cited by applicant]
Baukes, Mike, “Everybody Knows: How Knowledge-Based Authentication Died,” Forbes Technology Councel, Jan. 22, 2018, retrieved from: https://www.forbes.com/sites/forebestechcouncil/2018/01/22/everybody-know-how-knowledge… [cited by applicant]
Cole, Bryan, “Dynamic KBA—The Best Security Questions,” retrieved from: https://www.identropy.com/blog/iam-blog/bid/110793/dynamic-kba-the-best-security-questions [Jun. 7, 2021 2:39:34 PM], pp. 1-4. [cited by applicant]
Dwivedi, Prasoon, et al., “Challenges and Best Practices in KBA Schemes,” EMC Proven Professional Knowledge Sharing, 2015. pp. 1-17. [cited by applicant]
Hearn, Chalres, “Answering My Own Authentication Questions Prove That They're Useless,” Aug. 29, 2018, retrieved from: https://alloy.co/blog/answering-my-own-authentication-questions-prove-that-theyre-usless [Jun. 7, 20… [cited by applicant]