IP Library Granted Patent US 12,306,929
Granted Patent B2
US 12,306,929 · App. 18/105,094 · Granted May 20, 2025

Graphic pattern-based authentication with adjustable challenge level

Inventor: Mark Henrik Sandstrom (Alexandria, VA)
Assignee: ThroughPuter, Inc.
G06F21/45G06F21/36G06F2221/2103
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,306,929
App. No.
18/105,094
Filed
Feb 2, 2023
Granted
May 20, 2025
Kind
B2
Art Unit
2409
USPC
726/6
Abstract

Online user account access control includes adjustable authentication challenge levels based on a level of match between observed attributes of a present login attempt and corresponding recorded attributes for the authentic user for the entered user identifier (UID). Login candidates whose attributes sufficiently closely match the recorded attributes for the entered UID are allowed to select an authentication graphic pattern registered for the UID from a set of alternatives, with the degree of complexity of such selection based authentication increasing according to the degree of difference between the observed attributes of the present login attempt and the corresponding recorded values for the UID, while by default, login candidates may be required to produce the registered authentication graphic pattern from blank slate. Accordingly, authentic, but only authentic, users are able to login with high convenience, with underlying graphic pattern-based passcode protected against dictionary-based and brute-force attacks, or capture, by unauthorized parties.

Claims (54)

1. A user authentication system comprising:

a login feature collection interface to collect a plurality of observable characteristics for a current login attempt by a login candidate, the current login attempt requesting a login for a given user identifier (UID) of a group of UIDs for a login domain, the plurality of observable characteristics including information characterizing

the login candidate's interaction with a login interface of the login domain, and

at least one additional aspect of the current login attempt;

a login feature data store to maintain, for each UID in the group of UIDs, information indicative of collected observable characteristics from one or more past authenticated login attempts to that UID;

a trained artificial intelligence (AI) risk assessor to, based on the plurality of observable characteristics collected via the login feature collection interface and information maintained in the login feature data store indicative of collected observable characteristics from one or more past authenticated login attempts for the given UID, form an assessment of risk that the login candidate is unauthentic;

variable-challenge-level authentication challenge logic to interact with the login candidate, the variable-challenge-level challenge logic configured to

 set, from among a plurality of different challenge levels, a difficulty of challenge level, based at least in part on the assessment of risk formed by the trained AI risk assessor for the current login attempt, and

 interact with the login candidate to obtain one or more authentication responses corresponding to the set difficulty of challenge level to determine whether the login candidate is authentic for the given UID; and

an authentication data store to maintain, for each UID of the group of UIDs, at least one registered authentication item created for that UID from input from a respective authentic user of that UID, wherein

the at least one registered authentication item for the given UID comprises a registered graphic pattern, and

the plurality of different challenge levels comprise

a first challenge level that directs the login candidate to reproduce, from a set of basic elements, the registered graphic pattern for the given UID, and

a second challenge level that instructs the login candidate to select, from an array of alternative graphic patterns that excludes the registered graphic pattern, a pattern that is within a threshold difference of matching the registered graphic pattern.

2. The user authentication system of claim 1 , wherein the information characterizing the login candidate's interaction with the login interface comprises device interface input timing and/or movement values collected proximate in time to the current login attempt.

3. The user authentication system of claim 1 , wherein the at least one additional aspect of the current login attempt comprises at least one of hardware specifics for a computing device associated with the current login attempt, operating system specifics for the computing device, web browser identification, network address information, one or more network communication attributes, or browsing history.

4. The user authentication system of claim 1 , wherein:

the information indicative of collected observable characteristics from one or more past authenticated login attempts comprises information from up to a selected threshold number of past authenticated login attempts for each of the group of UIDs; and

the user authentication system is configured to, upon successful authentication by the login candidate for the current login attempt, save information from the collected plurality of observable characteristics to the login feature data store for the given UID.

5. The user authentication system of claim 4 , further configured to, upon unsuccessful authentication by the login candidate for the current login attempt, save information from the collected plurality of observable characteristics to the login feature data store for the given UID along with an indication that the saved information corresponds to an invalid login attempt.

6. The user authentication system of claim 5 , wherein the trained AI risk assessor is configured to form the assessment of risk based further on invalid login attempt information saved for the given UID in the login feature data store.

7. The user authentication system of claim 1 , wherein the at least one registered authentication item comprises one or more graphic patterns.

8. The user authentication system of claim 7 , wherein each respective graphic pattern of the one or more graphic patterns comprises a configuration of plural spatially arranged elements, each of the spatially arranged elements having a color or other distinguishing feature selected from among a plurality of possible colors or other distinguishing features by the respective authentic user when creating the respective graphic pattern.

9. The user authentication system of claim 1 , wherein the at least one registered authentication item comprises a hashed and/or encrypted passcode.

10. The user authentication system of claim 9 , wherein the hashed and/or encrypted passcode is generated by the user authentication system from a graphical pattern created by the respective authentic user as the corresponding at least one registered authentication item.

11. The user authentication system of claim 1 , wherein one or more of the plurality of different challenge levels comprises a third challenge level that directs the login candidate to answer one or more operational security questions

derived from past activity of an authentic user for the given UID, and

that an authentic user for the given UID would be expected to be able to answer at least within a defined level of accuracy and/or timeliness.

12. The user authentication system of claim 1 , wherein:

the at least one registered authentication item for the given UID further comprises one or more alternative graphic patterns; and

one or more of the plurality of different challenge levels comprises multiple authentication screens, wherein a difficulty of challenge level is adjusted by at least one of

varying complexity for each screen of a set of one or more authentication screens presented for a corresponding alternative graphic pattern challenge to the login candidate,

varying a number of successive authentication screens presented to the login candidate, or

varying time given to the login candidate to respond to each screen of the set of one or more authentication screens.

13. The user authentication system of claim 1 , wherein the login candidate's interaction with the login interface comprises one or more online interactions with a login domain interface.

14. A method of authenticating logins to a system, the method comprising:

collecting a plurality of observable characteristics for a current login attempt by a login candidate, the current login attempt requesting a login for a given user identifier (UID) of a group of UIDs for a login domain, the plurality of observable characteristics including information characterizing

the login candidate's interaction with a login interface to the domain, and at least one additional aspect of the current login attempt;

maintaining, in a login feature data store and for each UID in the group of UIDs, information indicative of collected observable characteristics from one or more past authenticated login attempts;

supplying input to a trained artificial intelligence (AI) risk assessor, the input comprising

 the collected plurality of observable characteristics for the current login attempt, and

 information maintained in the login feature data store indicative of collected observable characteristics from one or more past authenticated login attempts for the given UID;

by the trained AI risk assessor and based on the supplied input, forming an assessment of risk that the login candidate is unauthentic;

setting, from among a plurality of different challenge levels available for the given UID, a difficulty of challenge level, based at least in part on the assessment of risk formed by the trained AI risk assessor, and for the current login attempt;

 interacting with the login candidate to obtain one or more authentication responses for the set difficulty of challenge level to determine whether the login candidate is an authentic user for the given UID; and

maintaining, in an authentication data store and for each UID of the group of UIDs, at least one registered authentication item created for that UID from input from a respective authentic user of that UID, wherein

the at least one registered authentication item for the given UID comprises a registered graphic pattern; and

the plurality of different challenge levels comprise

a first challenge level that directs the login candidate to reproduce, from a set of basic elements, the registered graphic pattern for the given UID, and

a second challenge level that instructs the login candidate to select, from an array of alternative graphic patterns that excludes the registered graphic pattern, a pattern that is within a threshold difference of matching the registered graphic pattern.

15. The method of claim 14 , wherein the information characterizing the login candidate's interaction with the device interface comprises input timing and/or movement values collected proximate in time to the current login attempt.

16. The method of claim 14 , wherein the at least one additional aspect of the current login attempt comprises at least one of hardware specifics for a computing device associated with the current login attempt, operating system specifics for the computing device, web browser identification, network address information, network communication attributes, or browsing history.

17. The method of claim 14 , wherein the information indicative of collected observable characteristics from past successful login attempts comprises information from up to a selected threshold number of past successful login attempts for each of the group of UIDs, the method further comprising, upon successful authentication by the login candidate for the current login attempt, saving information from the collected plurality of observable characteristics to the login feature data store for the given UID.

18. The method of claim 14 , further comprising, upon unsuccessful authentication by the login candidate for the current login attempt, saving information from the collected plurality of observable characteristics to the login feature data store for the given UID along with an indication that the saved information corresponds to an invalid login attempt.

Continuity (7)
Continuation 16834961 · Mar 30, 2020
Provisional Application 62827435 · Apr 1, 2019
Provisional Application 62857573 · Jun 5, 2019
Provisional Application 62868756 · Jun 28, 2019
Provisional Application 62871096 · Jul 6, 2019
Provisional Application 62876087 · Jul 19, 2019
Related Publication 20230252126A1 · Aug 10, 2023
References Cited (150)
US 5465084A · Cottrell · 1995 [cited by applicant]
US 7124433B2 · Little · 2006 [cited by applicant]
US 7219368B2 · Juels et al. · 2007 [cited by applicant]
US 7702629B2 · Cytron et al. · 2010 [cited by applicant]
US 7844825B1 · Neginsky · 2010 [cited by applicant]
US 8189905B2 · Eaton et al. · 2012 [cited by applicant]
US 8458485B2 · Bandyopadhyay et al. · 2013 [cited by applicant]
US 8539550B1 · Terres et al. · 2013 [cited by applicant]
US 8601552B1 · Bowers et al. · 2013 [cited by applicant]
US 8718374B2 · Ashbrook · 2014 [cited by applicant]
US 8789206B2 · Harris · 2014 [cited by applicant]
US 8868919B2 · Barton et al. · 2014 [cited by applicant]
US 8881251B1 · Hilger · 2014 [cited by applicant]
US 8904479B1 · Johansson · 2014 [cited by examiner]
US 8931060B2 · Bidare · 2015 [cited by applicant]
US 8955074B2 · Barton et al. · 2015 [cited by applicant]
US 9104855B2 · Vargas et al. · 2015 [cited by applicant]
US 9111073B1 · Jiang et al. · 2015 [cited by applicant]
US 9117068B1 · Zhang et al. · 2015 [cited by applicant]
US 9165159B1 · McDonnell · 2015 [cited by applicant]
US 9215072B1 · Barton et al. · 2015 [cited by applicant]
US 9230079B2 · Yun · 2016 [cited by applicant]
US 9235715B1 · Bailey et al. · 2016 [cited by applicant]
US 9348981B1 · Hearn et al. · 2016 [cited by applicant]
US 9813409B2 · Zia · 2017 [cited by applicant]
US 10013546B1 · Johansson et al. · 2018 [cited by applicant]
US 10120989B2 · Anson · 2018 [cited by applicant]
US 10169565B2 · Zia et al. · 2019 [cited by applicant]
US 10176315B2 · Riddiford · 2019 [cited by applicant]
US 10754814B1 · Li et al. · 2020 [cited by applicant]
US 10754936B1 · Hawes et al. · 2020 [cited by applicant]
US 11003749B2 · Park · 2021 [cited by examiner]
US 11042880B1 · Hazan et al. · 2021 [cited by applicant]
US 11561983B2 · Sandstrom · 2023 [cited by applicant]
US 11604867B2 · Sandstrom · 2023 [cited by applicant]
US 11893463B2 · Sandstrom · 2024 [cited by applicant]
US 20020029341A1 · Juels · 2002 [cited by examiner]
US 20040143750A1 · Kulack et al. · 2004 [cited by applicant]
US 20050097320A1 · Golan et al. · 2005 [cited by applicant]
US 20060174339A1 · Tao · 2006 [cited by applicant]
US 20060206918A1 · McLean · 2006 [cited by applicant]
US 20080208777A1 · Stephens et al. · 2008 [cited by applicant]
US 20080244700A1 · Osborn · 2008 [cited by examiner]
US 20090037986A1 · Baker · 2009 [cited by applicant]
US 20090187962A1 · Brenneman et al. · 2009 [cited by applicant]
US 20100043062A1 · Alexander et al. · 2010 [cited by applicant]
US 20100251388A1 · Dorfman · 2010 [cited by applicant]
US 20100281526A1 · Raghavan · 2010 [cited by examiner]
US 20110010763A1 · Beardslee · 2011 [cited by applicant]
US 20120026109A1 · Baba · 2012 [cited by applicant]
US 20120066650A1 · Tirpak et al. · 2012 [cited by applicant]
US 20120084734A1 · Wilairat · 2012 [cited by applicant]
US 20120252409A1 · Cao · 2012 [cited by applicant]
US 20130044954A1 · Ashbrook · 2013 [cited by applicant]
US 20130139226A1 · Welsch et al. · 2013 [cited by applicant]
US 20130276100A1 · Yi et al. · 2013 [cited by applicant]
US 20130276125A1 · Bailey · 2013 [cited by examiner]
US 20130347066A1 · Wells et al. · 2013 [cited by applicant]
US 20140025467A1 · Nagarajan et al. · 2014 [cited by applicant]
US 20140115670A1 · Barton et al. · 2014 [cited by applicant]
US 20140157382A1 · Ford · 2014 [cited by applicant]
US 20140165186A1 · Ramu et al. · 2014 [cited by applicant]
US 20140175179A1 · Carter · 2014 [cited by examiner]
US 20140195974A1 · Ballard et al. · 2014 [cited by applicant]
US 20140344186A1 · Nadler · 2014 [cited by applicant]
US 20140359300A1 · Shirakawa · 2014 [cited by applicant]
US 20140365904A1 · Kim et al. · 2014 [cited by applicant]
US 20150012444A1 · Brown et al. · 2015 [cited by applicant]
US 20150143509A1 · Selander et al. · 2015 [cited by applicant]
US 20150324559A1 · Boss et al. · 2015 [cited by applicant]
US 20160110528A1 · Gupta et al. · 2016 [cited by applicant]
US 20160132673A1 · Birk et al. · 2016 [cited by applicant]
US 20160150260A1 · Ovide · 2016 [cited by applicant]
US 20160253288A1 · Reddy et al. · 2016 [cited by applicant]
US 20160277439A1 · Rotter et al. · 2016 [cited by applicant]
US 20160306994A1 · Olsen-Kreusch · 2016 [cited by examiner]
US 20160337346A1 · Momchilov · 2016 [cited by examiner]
US 20170064555A1 · Johansson et al. · 2017 [cited by applicant]
US 20170109509A1 · Baghdasaryan · 2017 [cited by examiner]
US 20170132404A1 · Tao · 2017 [cited by applicant]
US 20170308644A1 · Van et al. · 2017 [cited by applicant]
US 20170317993A1 · Weber · 2017 [cited by examiner]
US 20170323092A1 · Thakur et al. · 2017 [cited by applicant]
US 20170331817A1 · Votaw · 2017 [cited by examiner]
US 20180032714A1 · Zia et al. · 2018 [cited by applicant]
US 20180053274A1 · Kendall et al. · 2018 [cited by applicant]
US 20180107920A1 · Jayaraman et al. · 2018 [cited by applicant]
US 20180204403A1 · Wang · 2018 [cited by examiner]
US 20180248863A1 · Kao · 2018 [cited by examiner]
US 20180253717A1 · Kim et al. · 2018 [cited by applicant]
US 20180300178A1 · Sandstrom · 2018 [cited by applicant]
US 20190012074A1 · Ajayan et al. · 2019 [cited by applicant]
US 20190034613A1 · Jajoo et al. · 2019 [cited by applicant]
US 20190057207A1 · Schwartz et al. · 2019 [cited by applicant]
US 20190095605A1 · Gupta et al. · 2019 [cited by applicant]
US 20190137955A1 · Fahrenkopf et al. · 2019 [cited by applicant]
US 20190220583A1 · Douglas · 2019 [cited by examiner]
US 20190312861A1 · Kairi et al. · 2019 [cited by applicant]
US 20190316794A1 · Song et al. · 2019 [cited by applicant]
US 20190347586A1 · Kaulgud et al. · 2019 [cited by applicant]
US 20200026843A1 · Anwar et al. · 2020 [cited by applicant]
US 20200065469A1 · Norris, III · 2020 [cited by applicant]
US 20200066392A1 · Bess et al. · 2020 [cited by applicant]
US 20200090240A1 · Sinha et al. · 2020 [cited by applicant]
US 20200104737A1 · Abaci et al. · 2020 [cited by applicant]
US 20200110651A1 · Milman · 2020 [cited by applicant]
US 20200112560A1 · Hunt · 2020 [cited by examiner]
US 20200134167A1 · Craymer et al. · 2020 [cited by applicant]
US 20200162451A1 · Alhawaj · 2020 [cited by examiner]
US 20200167914A1 · Stamatoyannopoulos et al. · 2020 [cited by applicant]
US 20200285645A1 · Sandstrom · 2020 [cited by applicant]
US 20200288306A1 · Do et al. · 2020 [cited by applicant]
US 20200311250A1 · Sandstrom · 2020 [cited by examiner]
US 20200311586A1 · Sandstrom · 2020 [cited by applicant]
US 20200387594A1 · Sandstrom · 2020 [cited by applicant]
US 20230237376A1 · Sanstrom · 2023 [cited by applicant]
US 20230246851A1 · Lind · 2023 [cited by examiner]
US 20230262082A1 · Shah · 2023 [cited by examiner]
CN 105976517A · 2016 [cited by applicant]
EP 3559889A1 · 2019 [cited by applicant]
EP 3935501A1 · 2022 [cited by applicant]
EP 3980910A1 · 2022 [cited by applicant]
FR 3037684A1 · 2016 [cited by applicant]
IN 202117043365A · 2022 [cited by applicant]
JP 2014211818A · 2014 [cited by applicant]
RU 2672394C1 · 2018 [cited by applicant]
WO 0177792A2 · 2001 [cited by applicant]
WO 2020181268A1 · 2020 [cited by applicant]
WO 2020247800A1 · 2020 [cited by applicant]
U.S. Appl. No. 16/798,310, filed Feb. 22, 2020, Sandstrom. [cited by applicant]
U.S. Appl. No. 16/812,158, filed Mar. 6, 2020, Sandstrom. [cited by applicant]
“Grid Locker”, accessed at “https://www.f88x.com/modules/grid-locker-draw-a-plugin-wp-password-wordpress-utilities-download.html” accessed on Mar. 19, 2020, 2 pages. (Previously submitted in related U.S. Appl. No. 16/83… [cited by applicant]
Grzegorczyk, et al., “Vector Representations of Text Data in Deep Learning”, AGH University of Science and Technology, Faculty of Computer Science, Electronics and Telecommunications, Department of Computer Science, arX… [cited by applicant]
Gewali, et al., “Machine Learning Based Hyperspectral Image Analysis: A Survey”, Rochester Institute of Technology, Rochester, NY, arXiv: 1802.08701v2, Feb. 10, 2019, pp. 1-46. (Previously submitted in related U.S. Appl… [cited by applicant]
Kaur, et al., “Multi-Factor Graphical Password for Cloud Interface Authentication Security”, International Journal of Computer Applications, vol. 125, No. 7, Sep. 2015, pp. 32-35. (Previously submitted in related U.S. A… [cited by applicant]
International Preliminary Report on Patentability for International Application No. PCT/US2020/021581 dated Sep. 16, 2021, 15 pages. (Previously submitted in related U.S. Appl. No. 16/834,961). [cited by applicant]
International Preliminary Report on Patentability for International Application No. PCT/US2020/036394 dated Dec. 16, 2021, 9 pages. (Previously submitted in related U.S. Appl. No. 16/834,961). [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2020/021581 dated Jul. 22, 2020, 18 pages. (Previously submitted in related U.S. Appl. No. 16/834,961). [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2020/036394 dated Sep. 30, 2020, 14 pages. (Previously submitted in related U.S. Appl. No. 16/834,961). [cited by applicant]
Invitation to Pay Additional Fees and, Where Applicable, Protest Fee for International Application No. PCT/US2020/036394 mailed Jul. 21, 2020, 3 pages. (Previously submitted in related U.S. Appl. No. 16/834,961). [cited by applicant]
Invitation to Pay Additional Fees and, Where Applicable, Protest Fee of PCT Application No. PCT/US2020/021581 dated May 5, 2020, 2 pages. (Previously submitted in related U.S. Appl. No. 16/834,961). [cited by applicant]
Non-Final Office Action dated Jul. 25, 2022 in U.S. Appl. No. 16/834,961, 16 pages. (Previously submitted in related U.S. Appl. No. 16/834,961). [cited by applicant]
Non-Final Office Action dated Jun. 6, 2022 in U.S. Appl. No. 16/834,961, 10 pages. (Previously submitted in related U.S. Appl. No. 16/834,961). [cited by applicant]
Non-Final Office Action dated May 20, 2022 in U.S. Appl. No. 16/894,177, 35 pages. (Previously submitted in related U.S. Appl. No. 16/834,961). [cited by applicant]
Response to Non-Final Office Action filed Aug. 19, 2022 in U.S. Appl. No. 16/894,177, 12 pages. (Previously submitted in related U.S. Appl. No. 16/834,961). [cited by applicant]
Non-Final Office Action dated Apr. 6, 2022 in U.S. Appl. No. 16/834,961, 9 pages. [cited by applicant]
Notice of Allowance dated Jul. 19, 2022 in U.S. Appl. No. 16/834,961, 7 pages. [cited by applicant]
Extended European Search Report dated Jun. 28, 2023 in EP Application No. 20817925.9, 13 pages. [cited by applicant]
Bruzzone et al., “Robust Multiple Estimator Systems for the Analysis of Biophysical Parameters From Remotely Sensed Data”, IEEE Transactions on Geoscience and Remote Sensing, vol. 43, No. 1, dated Jan. 2005, 16 pages. [cited by applicant]
Cavalin et al., “Dynamic Selection Approaches For Multiple Classifier Systems”, Neural Comput & Applic, Mar. 11, 2011, pp. 673-688. [cited by applicant]