IP Library › Granted Patent US 12,292,951
Granted Patent B2
US 12,292,951 · App. 18/759,026 · Granted May 6, 2025

Biometric authentication based on behavioral analysis

Inventors: Joseph Benjamin Castinado (North Glenn, CO); Brandon Ingram (Charlotte, NC); Naoll Addisu Merdassa (Chakopee, MN); Kevin Graham Robberts (Charlotte, NC); Ann Ta (Scottsdale, AZ)
Assignee: BANK OF AMERICA CORPORATION
G06F21/316G06F21/45G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,292,951
App. No.
18/759,026
Filed
Jun 28, 2024
Granted
May 6, 2025
Kind
B2
Examiner
ZEE, EDWARD
Art Unit
2435
USPC
726/6
Abstract

A heightened level of security is provided in a computing platform by monitoring usage of applications and/or services residing on or accessible to a computing platform to determine abnormal usage patterns. In response to determining an abnormal pattern of usage, the user is required to provide biometric data, such as voice data, facial feature data, fingerprint data or the like, as a means of authenticating the user. The abnormal pattern of usage may be determined dynamically by comparing current usage patterns to known user baseline usage patterns. Alternatively, the abnormal pattern of usage is predefined, such as the resetting of passwords in a predefined number of applications and/or services over a predefined period of time.

Claims (35)

1. A system for requiring biometric user authentication, the system comprising:

a first computing platform having a first memory and at least one first processing device in communication with the first memory, wherein the first memory stores a plurality of network-accessible services;

a second computing platform having a second memory and at least one second processing device in communication with the second memory, wherein the second memory stores a plurality of applications; and

a user authentication engine stored in the first memory or the second memory and executable by the at least one first processing device or at least one second processing device and configured to:

monitor usage by a user of two or more of the plurality of applications or services;

in response to the monitoring, determine a predetermined abnormal pattern of usage amongst at least two of the plurality of applications or services that is contrary to one or more normal patterns of usage of the user, wherein the predetermined abnormal pattern of usage is defined as resetting of passwords within (i) a predetermined number greater than one of the plurality of applications or services and (ii) a predetermined period of time; and

in response to determining the predetermined abnormal pattern of usage amongst the at least two of the plurality of applications or services, require the user to authenticate by providing biometric data to further access the plurality of applications or services.

2. The system of claim 1 , wherein the biometric data provided by the user is predefined biometric data.

3. The system of claim 1 , wherein the user authentication engine is further configured to:

receive the biometric data and authenticate the user based on a match between the received biometric data and previously stored biometric data.

4. The system of claim 1 , wherein the user authentication engine is further configured to, in response to determining the predetermined abnormal pattern of usage, generate and communicate an alert to a predetermined entity.

5. The system of claim 1 , wherein the user authentication engine is further configured to allow the user to preconfigure at least one of (i) the predetermined number greater than one of the plurality of applications or services for determining the abnormal pattern of usage, and (ii) the predetermined period of time for determining the abnormal pattern of usage.

6. The system of claim 1 , wherein the user authentication engine is configured to require the user to provide the biometric data to further access the plurality of applications or services, wherein the biometric data is chosen from the group consisting of voice data, facial feature data and fingerprint data.

7. A computer-implemented method for requiring biometric user authentication, the computer-implemented method is executable by one or more computing processor devices, the method comprising:

monitoring usage, by a user, of two or more of a plurality of applications or a plurality of services;

in response to the monitoring, determining a predetermined abnormal pattern of usage amongst at least two of the plurality of applications or services that is contrary to one or more normal patterns of usage of the user, wherein the predetermined abnormal pattern of usage is defined as resetting of passwords within (i) a predetermined number greater than one of the plurality of applications or services and (ii) a predetermined period of time; and

in response to determining the predetermined abnormal pattern of usage amongst the at least two of the plurality of applications or services, requiring the user to provide biometric data to further access the plurality of applications or services.

8. The computer-implemented method of claim 7 , wherein the biometric data provided by the user is predefined biometric data.

9. The computer-implemented method of claim 7 , further comprising:

receiving the biometric data and authenticating the user based on a match between the received biometric data and previously stored biometric data.

10. The computer-implemented method of claim 7 , further comprising:

in response to determining the predetermined abnormal pattern of usage, generating and communicating an alert to a predetermined entity.

11. The computer-implemented method of claim 7 , further comprising:

providing for the user to preconfigure at least one of (i) the predetermined number greater than one of the plurality of applications or services for determining the abnormal pattern of usage, and (ii) the predetermined period of time for determining the abnormal pattern of usage.

12. The computer-implemented method of claim 7 , wherein requiring the user to provide the biometric data further comprises requiring the user to provide the biometric data, wherein the biometric data is chosen from the group consisting of voice data, facial feature data and fingerprint data.

13. A computer program product including a non-transitory computer-readable medium, the non-transitory computer-readable medium comprising:

a first set of codes for causing a computer to monitor usage, by a user, of two or more of a plurality of applications or a plurality of services;

a second set of codes for causing a computer to, in response to the monitoring, determine a predetermined abnormal pattern of usage amongst at least two of the plurality of applications or services that is contrary to one or more normal patterns of usage of the user, wherein the predetermined abnormal pattern of usage is defined as resetting of passwords within (i) a predetermined number greater than one of the plurality of applications or services and (ii) a predetermined period of time; and

a third set of codes for causing a computer to, in response to determining the predetermined abnormal pattern of usage amongst the at least two of the plurality of applications or services, require the user to provide biometric data to further access the plurality of applications or services.

14. The computer program product of claim 13 , wherein the biometric data provided by the user is predefined biometric data.

15. The computer program product of claim 13 , wherein the computer-readable medium further comprises:

a fourth set of codes for causing a computer to receive the biometric data and authenticate the user based on a match between the received biometric data and previously stored biometric data.

16. The computer program product of claim 13 , wherein the third set of codes is further configured to, in response to determining the predetermined abnormal pattern of usage, generate and communicate an alert to a predetermined entity.

17. The computer program product of claim 13 , wherein the computer-readable medium further comprises a fourth set of codes for causing a computer to provide for the user to preconfigure at least one of (i) the predetermined number greater than one of the plurality of applications or services for determining the abnormal pattern of usage, and (ii) the predetermined period of time for determining the abnormal pattern of usage.

18. The computer program product of claim 13 , wherein the third set of codes is further configured to, in response to determining the predetermined abnormal pattern of usage, require the user to provide the biometric data to further access the plurality of applications or services, wherein the biometric data is chosen from the group consisting of voice data, facial feature data and fingerprint data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2024
From: CASTINADO, JOSEPH BENJAMIN; INGRAM, BRANDON; MERDASSA, NAOLL ADDISU; ROBBERTS, KEVIN GRAHAM; TA, ANN
To: BANK OF AMERICA CORPORATION
Reel/Frame 067874/0873 →
Continuity (2)
Continuation 17388592 · Jul 29, 2021
Related Publication 20240354384A1 · Oct 24, 2024
References Cited (17)
US 7039699B1 · Narin et al. · 2006 [cited by applicant]
US 8775471B1 · Kozyrczak et al. · 2014 [cited by applicant]
US 8843760B2 · Atherton · 2014 [cited by applicant]
US 9301140B1 · Costigan et al. · 2016 [cited by applicant]
US 10069852B2 · Turgeman et al. · 2018 [cited by applicant]
US 10754936B1 · Hawes · 2020 [cited by examiner]
US 10911470B2 · Muddu et al. · 2021 [cited by applicant]
US 11696682B2 · Tran · 2023 [cited by applicant]
US 20020178257A1 · Cerrato · 2002 [cited by applicant]
US 20070236330A1 · Cho et al. · 2007 [cited by applicant]
US 20070239604A1 · O'Connell et al. · 2007 [cited by applicant]
US 20080091453A1 · Meehan et al. · 2008 [cited by applicant]
US 20080162202A1 · Khanna et al. · 2008 [cited by applicant]
US 20090089869A1 · Varghese · 2009 [cited by applicant]
US 20090199296A1 · Xie et al. · 2009 [cited by applicant]
US 20140026220A1 · Gehrig, Jr. · 2014 [cited by applicant]
US 20150264572A1 · Turgeman · 2015 [cited by applicant]