IP Library Granted Patent US 12,361,112
Granted Patent B2
US 12,361,112 · App. 18/139,295 · Granted Jul 15, 2025

Access prediction service receiving authentication journey characteristics for supervised learning

Inventors: Sudhakar Peddibhotla (Seattle, WA); Darryl Jones (Princeton, NJ); Raminder Deep Singh Kaler (Redwood City, CA); Peter Barker (Austin, TX)
Assignee: Ping Identity International, Inc.
G06F21/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,361,112
App. No.
18/139,295
Granted
Jul 15, 2025
Kind
B2
Abstract

A process, system and medium for building a training set and performing supervised training of a Machine Learning (ML) model that determines a risk score used to decide whether to impose stepped up authentication during an authentication journey are described. The process includes selecting examples of completed authentication journeys, including failed and successful authentication outcomes after step-up requirements during the example journeys. The process includes pairing ground truth outcomes from the example journeys with authentication request features initially available prior to imposition of the step-up requirements to produce request feature-outcome pairs. The process includes using at least the request feature-outcome pairs to perform the supervised training of the ML model to determine a risk score that can be used to decide whether to impose the stepped up authentication during an authentication journey. The system and medium are configured to execute the process.

Claims (60)

1. A method of building a training set and performing supervised training of a Machine Learning (ML) model that determines a risk score used to decide whether to impose stepped up authentication during an authentication journey, the method comprising:

selecting example completed authentication journeys, including failed and successful authentication outcomes after step-up requirements during the example completed authentication journeys;

pairing ground truth outcomes from the example completed authentication journeys with authentication request features initially available prior to imposition of the step-up requirements to produce request feature-outcome pairs, the authentication request features including 5 or more of:

geographical country from which an authentication request originated,

geographical city from which the authentication request originated,

device type from which the authentication request originated,

day of week on which the authentication request was received,

part of day in which the authentication request was received,

operating system (OS) type from which the authentication request was sent, or

user agent from which the authentication request was sent; and

using at least the request feature-outcome pairs to perform the supervised training of the ML model to produce a trained ML model to determine a risk score that can be used to decide whether to impose the stepped up authentication during an authentication journey.

2. The method of claim 1 , further including:

receiving fresh authentication request features of the authentication journey;

processing, with the trained ML model, the fresh authentication request features; and

providing the risk score determined by the trained ML model.

3. The method of claim 2 , further including:

if the risk score exceeds a threshold, providing an explanation of the risk score, wherein the explanation comprises a feature.

4. The method of claim 1 , wherein the supervised training of the ML model uses journey features as training features.

5. The method of claim 4 , wherein the journey features include type of step-up.

6. The method of claim 5 , wherein the type of step-up comprises at least one of multi-factor authentication, CAPTCHA, or biometrics.

7. A non-transitory computer-readable medium configured with instructions to build a training set and perform supervised training of a Machine Learning (ML) model that determines a risk score used to decide whether to impose stepped up authentication during an authentication journey, the instructions, when executed on a processor, implement a method comprising:

selecting example completed authentication journeys, including failed and successful authentication outcomes after step-up requirements during the example completed authentication journeys;

pairing ground truth outcomes from the example completed authentication journeys with authentication request features initially available prior to imposition of the step-up requirements to produce request feature-outcome pairs, the authentication request features including 5 or more of:

geographical country from which an authentication request originated,

geographical city from which the authentication request originated,

device type from which the authentication request originated,

day of week on which the authentication request was received,

part of day in which the authentication request was received,

operating system (OS) type from which the authentication request was sent, or

user agent from which the authentication request was sent; and

using at least the request feature-outcome pairs to perform the supervised training of the ML model to produce a trained ML model to determine a risk score that can be used to decide whether to impose the stepped up authentication during an authentication journey.

8. The non-transitory computer-readable medium of claim 7 , the method further including:

receiving fresh authentication request features of the authentication journey;

processing, with the trained ML model, the fresh authentication request features; and

providing the risk score determined by the trained ML model.

9. The non-transitory computer-readable medium of claim 8 , the method further including:

if the risk score exceeds a threshold, providing an explanation of the risk score, wherein the explanation comprises a feature.

10. The non-transitory computer-readable medium of claim 7 , wherein the supervised training of the ML model uses journey features as training features.

11. The non-transitory computer-readable medium of claim 10 , wherein the journey features include type of step-up.

12. The non-transitory computer-readable medium of claim 11 , wherein the type of step-up comprises at least one of multi-factor authentication, CAPTCHA, or biometrics.

13. A system including one or more processors coupled to memory, the memory loaded with computer instructions to build a training set and perform supervised training of a Machine Learning (ML) model that determines a risk score used to decide whether to impose stepped up authentication during an authentication journey, the computer instructions, when executed on the one or more processors, implement actions comprising:

selecting example completed authentication journeys, including failed and successful authentication outcomes after step-up requirements during the example completed authentication journeys;

pairing ground truth outcomes from the example completed authentication journeys with authentication request features initially available prior to imposition of the step-up requirements to produce request feature-outcome pairs, the authentication request features including 5 or more of:

geographical country from which an authentication request originated,

geographical city from which the authentication request originated,

device type from which the authentication request originated,

day of week on which the authentication request was received,

part of day in which the authentication request was received,

operating system (OS) type from which the authentication request was sent, or

user agent from which the authentication request was sent; and

using at least the request feature-outcome pairs to perform the supervised training of the ML model to produce a trained ML model to determine a risk score that can be used to decide whether to impose the stepped up authentication during an authentication journey.

14. The system of claim 13 , wherein the memory further includes computer instructions that, when executed on the one or more processors, implement actions comprising:

receiving fresh authentication request features of the authentication journey;

processing, with the trained ML model, the fresh authentication request features; and

providing the risk score determined by the trained ML model.

15. The system of claim 14 , wherein the memory further includes computer instructions that, when executed on the one or more processors, implement actions comprising:

if the risk score exceeds a threshold, providing an explanation of the risk score, wherein the explanation comprises a feature.

16. The system of claim 13 , wherein the supervised training of the ML model uses journey features as training features.

17. The system of claim 16 , wherein the journey features include type of step-up.

18. The system of claim 17 , wherein the type of step-up comprises at least one of multi-factor authentication, CAPTCHA, or biometrics.

Assignments (3)
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: FORGEROCK, INC.
To: PING IDENTITY INTERNATIONAL, INC.
Reel/Frame 066358/0483 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2023
From: KALER, RAMINDER DEEP SINGH; BARKER, PETER; PEDDIBHOLTA, SUDHAKAR; JONES, DARRYL
To: FORGEROCK, INC.
Reel/Frame 063565/0208 →
Continuity (1)
Related Publication 20240362316A1 · Oct 31, 2024
References Cited (50)
US 10303576B1 · Seymour et al. · 2019 [cited by applicant]
US 11182468B1 · Walters et al. · 2021 [cited by applicant]
US 12093950B2 · John et al. · 2024 [cited by applicant]
US 12229768B2 · John et al. · 2025 [cited by applicant]
US 20150205708A1 · Michelsen · 2015 [cited by applicant]
US 20160140023A1 · Michelsen et al. · 2016 [cited by applicant]
US 20160217062A1 · Singi et al. · 2016 [cited by applicant]
US 20170295062A1 · Tang · 2017 [cited by applicant]
US 20180189033A1 · Narang et al. · 2018 [cited by applicant]
US 20190087075A1 · Dhayanithi et al. · 2019 [cited by applicant]
US 20190392450A1 · Gosset · 2019 [cited by examiner]
US 20200125483A1 · Lipke · 2020 [cited by applicant]
US 20210004253A1 · Barnes et al. · 2021 [cited by applicant]
US 20210072966A1 · Zong et al. · 2021 [cited by applicant]
US 20210194883A1 · Badhwar · 2021 [cited by examiner]
US 20220108701A1 · Gupta · 2022 [cited by examiner]
US 20220210151A1 · Williams et al. · 2022 [cited by applicant]
US 20240107301A1 · Koral · 2024 [cited by examiner]
US 20240195819A1 · Grajek · 2024 [cited by examiner]
US 20240364730A1 · Jones et al. · 2024 [cited by applicant]
US 20240428306A1 · Sliwka · 2024 [cited by examiner]
Akers, A., What Is Step-Up Authentication When to Use It?, Okta, Auth0 Blog, Dec. 17, 2020, 14 pages (downloaded Apr. 6, 2023 from https://auth0.com/blog/what-is-step-up-authentication-when-to-use-it/. [cited by applicant]
Distinguish step-up from multi-factor authentication, IBM, Mar. 9, 2021, 2 pages, (downloaded Apr. 6, 2023 from https://www.ibm.com/docs/en/sva/9.0.1?topic=authentication-distinguish-step-up-from-multi-factor). [cited by applicant]
Jordan, J., Variational autoencoders, JeremyJordan.me, Mar. 19, 2019, 15 pages (downloaded Mar. 21, 2023 from https://www.jeremyjordan.me/variational-autoencoders/). [cited by applicant]
About Autonomous Access—ForgeRock Identity Cloud Docs, ForgeRock, Inc. May 2022, 27 pages (downloaded Dec. 12, 2022 from https://backstage.forgerock.com/docs/idcloud/latest/auto-access/chap-about-autoaccess.html). [cited by applicant]
Huang, Z., Extensions to the k-Means Algorithm for Clustering Large Data Sets with Categorical Values, Data Mining and Knowledge Discovery, 2, 283-304 Sep. 1998 Kluwer Academic Publishers, 22 pages (https://doi.org/10.1… [cited by applicant]
“Theme Node, Dynamically theme the ForgeRock out-of-the-box US on the fly”, Oct. 2020, ForgeRock, Inc.,pp. 5 pgs. (downloaded from https://web.archive.org/web/20201024234908/https://backstage.forgerock.com/marketplace/e… [cited by applicant]
“Theme Node, Dynamically theme the ForgeRock out-of-the-box US on the fly”, Apr. 2020, ForgeRock, Inc.,, 8 pgs (downloaded from https://github.com/vscheuber/ThemeNode). [cited by applicant]
McKendrick, What is low-code and no-code? A guide to development platforms, ZDNet, Mar. 3, 2021,9 pgs (downloaded from https://www.zdnet.com/article/special-report-what-is-low-code-no-code-a-guide-to-development-platfor… [cited by applicant]
Authentication and Single Sign-On Guide, ForgeRock Access Management 6.5, ForgeRock, Inc., Jul. 4, 2019, 482 pages. [cited by applicant]
Release Notes, AM 5.0.0, ForgeRock, Inc., Jun. 2, 2020. [cited by applicant]
Protect Users Witthout Frustrating Them Using AI-Driven Behavorial Biometrics, White Pater, Behavion Sec, 2020, (retrieved Dec. 14, 2021 from https://www.behaviosec.com/wp-content/uploads/2020/11/bhs-whitepaper.pdf). [cited by applicant]
Behavioral Biometrics for Mobile, BioCatch, 2021, 3 pages (retrieved Dec. 14, 2021 from https://www.biocatch.com/hubfs/New%20Boilerplate/BC%20SB%20Mobile%20Data%20v6%20NBP.pdf). [cited by applicant]
Innovating the Customer Experience Without Opening Fraud Floodgates, BioCatch, 10 pages (retrieved Dec. 14, 2021 from https://www.biocatch.com/hubfs/WP-Innovate-Customer-Experience-Without-Fraud.pdf). [cited by applicant]
Threat Matrix Guide, ID Dataweb, 7 pages (retrieved Dec. 14, 2021 from https://docs.iddataweb.com/docs/threatmetrix-1). [cited by applicant]
Cichonski et al., “Computer Security Incident Handling Guide”, National Institute of Standards and Technology, U.S. Department of Commerce, Special Publication 800-61, Revision 2, http://dx.doi.org/10.6028/NIST.SP.800-6… [cited by applicant]
“Hardening your cluster's security”, Kubernetes Engine, (https://cloud.google.com/kubernetes-engine/docs/concepts/security-overview), Jul. 2019, 10 pages. [cited by applicant]
Dempsey, et al., “Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations”, NIST National Institute of Standards and Technology, U.S. Dept. of Commerce, NIST Special Publicati… [cited by applicant]
“Configuring Vertical Pod Autoscaling”, Kubernetes Engine, Google Cloud (https://cloud.google.com/kubernetes-engine/), Aug. 14, 2019, 8 pages. [cited by applicant]
Wilkin, “Kubernetes Deployment Dependencies”, https://medium.com/google-cloud/kubernetes-deployment-dependencies-ef703e563956, Jul. 2, 2018, 21 pages. [cited by applicant]
“Vertical Pod Autoscaling”, Kubernetes Engine, https://cloud.google.com/kubernetes-engine/docs/concepts/verticalpodautoscaler), Aug. 29, 2019, 8 pages. [cited by applicant]
Sakimura et al, “OpenID Connect Dynamic Client Registration 1.0 incorporating errata set 1”, https://openid.net/specs/openid-connect-registration-1_0.html, Oct. 1, 2019, 19 pages. [cited by applicant]
Jayanandana, “Enable Rolling updates in Kubernetes with Zero downtime”, https://medium.com/platformer-blog/enable-rolling-updates-in-kubernetes-with-zero-downtime-31d7ec.388c81, Sep. 27, 2018, 6 pages. [cited by applicant]
“FAQ: IDM/OpenIDM performance and tuning”, https://backstage.forgerock.com/knowledge/kb/article/a32504603, Jun. 26, 2019, 7 pages. [cited by applicant]
Amazon; AWS Elastic Beanstalk Developer Guide; Aug. 2019; 924 pgs (https://web.archive.org/web/20190805110626/https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/awseb-dg.pdf). [cited by applicant]
Kingma et al, Auto-Encoding Variational Bayes, arXiv:1312.6114v11 [stat.ML] Dec. 10, 2022]. [cited by applicant]
U.S. Appl. No. 16/790,724, filed Feb. 13, 2020, U.S. Pat. No. 11,586,530, Feb. 21, 2023, Granted. [cited by applicant]
U.S. Appl. No. 18/111,501, filed Feb. 17, 2023, Pending. [cited by applicant]
U.S. Appl. No. 17/673,692, filed Feb. 16, 2022, US 2022/0263833, Aug. 18, 2022, Pending. [cited by applicant]
Office Action for U.S. Appl. No. 18/139,296 mailed Feb. 26, 2025, 12 pages. [cited by applicant]
Cited By (1)
US 12,645,920