IP Library Granted Patent US 9,122,850
Granted Patent B2
US 9,122,850 · App. 13/759,369 · Granted Sep 1, 2015

Alternate game-like multi-level authentication

Inventors: Francis Kapo Tse (Rochester, NY); Zahra Langford (Rochester, NY); Jennifer Watts-Englert (Pittsford, NY); Catherine McCorkindale (Fairport, NY); David Russell Vandervort (Walworth, NY); Mary Ann Sprague (Macedon, NY)
Assignee: Xerox Corporation
G06F21/31G06F21/46G06F2221/2109G06F2221/2113G06F2221/2147G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,122,850
App. No.
13/759,369
Granted
Sep 1, 2015
Kind
B2
Abstract

The disclosed embodiments provide a convenient way for users to access segregated work spaces on mobile devices. A game-like multi-level interactive approach is used to prompt users for input to verify their identity. Multiple identity verification attributes can be collected at each level of interaction. Authentication is achieved when a settable level of user identification confidence is reached. This can potentially reduce the amount of interaction needed as compared to requiring a user to type in a long, cryptic password.

Claims (79)

1. A system comprising:

at least one challenge, each challenge being answerable by a challenge response comprising at least one of producing a drawing, gesture, or sound;

a processor and a data bus coupled to the processor;

a plurality of user profiles associated with a plurality of users wherein each one of the user profiles is associated with one of the users by an identifier and comprises at least one challenge response provided by that one user and wherein one of the user profiles is associated with a registrant; and

a non-transitory computer-usable medium coupled to the data bus wherein the computer usable medium embodies computer code, and wherein the computer program code comprises instructions executable by the processor and configured for:

receiving a user identifier from a person wherein the user identification is associated with a specific user;

presenting a plurality of authentication alternatives, the alternatives comprising password authentication and non-password authentication;

receiving an authentication selection wherein the person selects non-password authentication;

presenting the person with at least one of the challenges;

recording the at least one challenge response provided by the person in response to the at least one challenge;

computing a confidence level based on the person's at least one challenge response and on the at least one challenge response stored in one of the user profiles associated with the specific user;

authenticating the person as the specific user if the confidence level exceeds a threshold;

receiving the user identifier from the registrant;

presenting the registrant with a plurality of authentication options wherein the authentication options comprise password authentication and non-password authentication;

accepting a non-password authentication selection from the registrant; and

presenting the registrant with at least one of the challenges and recording the registrant's at least one challenge response.

2. The system of claim 1 wherein the user identifier is a username comprising a plurality of characters.

3. The system of claim 1 wherein the user identifier is an icon.

4. The system of claim 1 wherein the user identifier is a picture of the requestor.

5. The system of claim 1 wherein the instructions are further configured for:

receiving a password from the registrant; and

associating a credential with the user identifier wherein the credential is based on the password.

6. The system of claim 1 wherein the instructions are further configured for:

requiring the registrant to submit challenge responses to at least a minimum number of the challenges.

7. The system of claim 6 wherein the minimum number is greater than 1.

8. The system of claim 7 wherein the minimum number equals the number of challenges.

9. The system of claim 1 wherein the challenges comprise:

a challenge to draw an animal identified by name;

a challenge to draw an animal identified as favorite;

a challenge to draw a number identified as favorite;

a challenge to provide a name for a pictured animal; and

a challenge to draw a number corresponding to the quantity of an item in a picture.

10. The system of claim 1 wherein the challenge responses comprise: a gesture; a drawing; and a selection of one picture from a plurality of pictures.

11. The system of claim 1 ,

wherein the user identifier is a username comprising a plurality of characters, an icon, or a picture of the requestor;

wherein the challenge responses comprise: a gesture; a drawing; and a selection of one picture from a plurality of pictures;

wherein the system provides the person with access rights to a plurality of services and capabilities based on the confidence level with greater access rights being provided as a function of increasing confidence level;

wherein the challenges comprise: a challenge to draw an animal identified by name; a challenge to draw an animal identified as favorite; a challenge to draw a number identified as favorite; a challenge to provide a name for a pictured animal; and a challenge to draw a number corresponding to the quantity of an item in a picture, and

wherein the instructions are further configured for:

receiving a password from the registrant;

associating a credential with the user identifier wherein the credential is based on the password;

requiring the registrant to submit challenge responses to all of the challenges; and

increasing or decreasing the confidence level based on the person's challenge response when the person responds to another of the challenges.

12. A non-transitory processor-readable medium storing code representing instructions to cause a processor to perform a process to authenticate a person as a specific user wherein the instructions are configured to:

access a plurality of challenges;

access a plurality of challenge responses, each challenge response having been provided by one of a plurality of users in response to one of the challenges and wherein each challenge response is production of a drawing or a gesture;

access a plurality of user profiles associated with the users wherein each one of the user profiles is associated with one of the users by an identifier and comprises at least one of those challenge responses provided by one of the users;

receive a user identifier from the person wherein the user identification is associated with the specific user;

present a plurality of authentication alternatives, the alternatives comprising password authentication and non-password authentication;

receive an authentication selection wherein the person selects non-password authentication;

present the person with at least one of the challenges;

record the at least one challenge response provided by the person in response to the at least one challenge;

compute a confidence level based on the person's at least one challenge response and on the at least one challenge response stored in one of the user profiles associated with the specific user;

authenticate the person as the specific user if the confidence level exceeds a threshold;

receive the user identifier from a registrant;

present the registrant with a plurality of authentication options wherein the authentication options comprise password authentication and non-password authentication;

accept a non-password authentication selection from the registrant; and

presenting the registrant with at least one of the challenges and recording the registrant's at least one challenge response.

13. The processor-readable media of claim 12 wherein the code further comprises code to provide the person with access rights to a plurality of services, data, and capabilities.

14. The processor-readable media of claim 13 wherein the code further comprises code to provide the person with access rights to additional services and capabilities based on the magnitude of the confidence level.

15. A user authentication system comprising:

a plurality of challenges and a plurality of challenge responses wherein each of the challenges is answerable by a challenge response specific to that challenge and wherein each challenge response comprises at least one of producing a drawing or gesture;

a user profile generator that accepts a registrant identifier from a registrant, presents at least one of the challenges to the registrant, and records at least one registrant challenge response;

a user profile directory that stores a plurality of user profiles associated with a user identifier and comprising at least one user challenge response and wherein one of the user profiles is a registrant profile associated with the registrant identifier and comprising the at least one registrant challenge response;

a processor and a data bus coupled to the processor;

a non-transitory computer-usable medium coupled to the data bus wherein the computer usable medium embodies computer code, and wherein the computer code comprises instructions executable by the processor and configured for:

receiving a user identifier from a person wherein the user identification is associated with a specific user;

presenting a plurality of authentication alternatives, the alternatives comprising password authentication and non-password authentication;

receiving an authentication selection wherein the person selects non-password authentication;

presenting the person with at least one of the challenges;

recording the at least one challenge response provided by the person in response to the at least one challenge;

computing a confidence level based on the person's at least one challenge response and on the at least one challenge response stored in one of the user profiles associated with the specific user; and

authenticating the person as the specific user if the confidence level exceeds a threshold.

16. The user authentication system of claim 15 further comprising:

a user authentication interface that receives a personal identifier from a person, provides the person with at least one of the challenges, and records at least one personal challenge response provided by the person; and

a user authentication module that accepts and authenticates the person as a specific user based on the personal identifier, the at least one challenge response, and one of the user profiles associated with the specific user.

17. The user authentication system of claim 16 wherein the confidence level controls access to a plurality of subsets of a set of services and capabilities and wherein accessible subsets are based on the magnitude of the confidence level.

18. The user authentication system of claim 17 wherein the challenge responses comprise a gesture.

19. The user authentication system of claim 18 wherein the challenge responses comprise a drawing.

Assignments (10)
SECOND LIEN NOTES PATENT SECURITY AGREEMENT Recorded Jul 2, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 071785/0550 →
FIRST LIEN NOTES PATENT SECURITY AGREEMENT Recorded Apr 11, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 070824/0001 →
SECURITY INTEREST Recorded Feb 13, 2024
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066741/0001 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT RF 064760/0389 Recorded Feb 13, 2024
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: XEROX CORPORATION
Reel/Frame 068261/0001 →
SECURITY INTEREST Recorded Nov 20, 2023
From: XEROX CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 065628/0019 →
SECURITY INTEREST Recorded Jun 22, 2023
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 064760/0389 →
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 062740/0214 Recorded May 18, 2023
From: CITIBANK, N.A., AS AGENT
To: XEROX CORPORATION
Reel/Frame 063694/0122 →
SECURITY INTEREST Recorded Nov 10, 2022
From: XEROX CORPORATION
To: CITIBANK, N.A., AS AGENT
Reel/Frame 062740/0214 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2013
From: SWENTON-WALL, PATRICIA
To: XEROX CORPORATION
Reel/Frame 031786/0588 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2013
From: TSE, FRANCIS KAPO; LANGFORD, ZAHRA; WATTS-ENGLERT, JENNIFER; MCCORKINDALE, CATHERINE; VANDERVORT, DAVID RUSSELL; SPRAGUE, MARY ANN
To: XEROX CORPORATION
Reel/Frame 029755/0662 →
Continuity (1)
Related Publication 20140223547A1 · Aug 7, 2014