IP Library Granted Patent US 9,160,730
Granted Patent B2
US 9,160,730 · App. 13/994,016 · Granted Oct 13, 2015

Continuous authentication confidence module

Inventors: Micah J. Sheller (Hillsboro, OR); Conor P. Cahill (Waterford, VA); Jason Martin (Beaverton, OR); Ned M. Smith (Beaverton, OR); Brandon Baker (Portland, OR)
Assignee: Intel Corporation
H04L63/08G06F21/316H04L67/14G06F2221/2101G06F2221/2103H04L67/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,160,730
App. No.
13/994,016
Granted
Oct 13, 2015
Kind
B2
Abstract

Generally, this disclosure describes a continuous authentication confidence module. A system may include user device including processor circuitry configured to determine presence data; a confidence factor including at least one of a sensor configured to capture sensor input and a system monitoring module configured to monitor activity of the user device; memory configured to store a confidence score and an operating system; and a continuous authentication confidence module configured to determine the confidence score in response to an initial authentication of a specific user, update the confidence score based, at least in part, an expectation of user presence and/or selected presence data, and notify the operating system that the authentication is no longer valid if the updated confidence score is within a tolerance of a session close threshold; the initial authentication configured to open a session, the confidence score configured to indicate a current strength of authentication during the session.

Claims (39)

1. A user device comprising:

processor circuitry configured to determine presence data;

a confidence factor comprising at least one of a sensor configured to capture sensor input and a system monitoring module configured to monitor operation of the user device and to collect monitor data related to the monitoring;

memory configured to store a confidence score and an operating system; and

a continuous authentication confidence module (CACM) configured to:

determine the confidence score in response to an initial authentication of a specific user;

update the confidence score based, at least in part, on at least one of an expectation of user presence and selected presence data; and

notify at least one of the operating system and a remote communication partner that the authentication is no longer valid if the updated confidence score is within a tolerance of a session close threshold;

wherein:

the initial authentication configured to open a session, the confidence score configured to indicate a current strength of authentication at a point in time during the session;

when the confidence score is at or above a confidence score power threshold, the CACM is configured to choose a type of said selected presence data based, at least in part, on a power consumption associated with obtaining said chosen type of said selected presence data; and

determine a confidence value based, at least in part, on the chosen type of selected presence data; and

adjust the confidence score based, at least in part, on the confidence value.

2. The user device of claim 1 , wherein the chosen type of selected presence data comprises at least one of human presence data configured to indicate whether an unidentified human is present, and user presence data configured to indicate whether the specific user is present.

3. The user device of claim 1 , wherein the CACM is further configured to determine the confidence score based, at least in part, on a time since authentication.

4. The user device of claim 1 , wherein when the confidence score is below an active factor threshold, the CACM is configured to choose the type of selected presence data based, at least in part, on user presence data associated with an active factor.

5. The user device of claim 1 , wherein the processor circuitry is configured to determine the chosen type of selected presence data based, at least in part, on at least one of the captured sensor input and the collected monitor data.

6. The user device of claim 1 , wherein the CACM is configured to choose the type of selected presence data based, at least in part, on at least one configuration parameter.

7. A method comprising:

determining a confidence score in response to an initial authentication of a specific user to a user device, the initial authentication configured to open a session, the confidence score configured to indicate a current strength of authentication at a point in time during the session;

updating the confidence score based, at least in part, on at least one of an expectation of user presence and selected presence data; and

notifying at least one of the user device and a remote communication partner that the authentication is no longer valid if the updated confidence score is within a tolerance of a session close threshold;

said updating comprises, when the confidence score is at or above a confidence score power threshold, choosing a type of selected presence data based at least in part on a power consumption associated with obtaining said chosen type of said presence data;

determining a confidence value based at least in part on the chosen type of selected presence data; and

adjusting the confidence score based at least in part on the confidence value.

8. The method of claim 7 , wherein the chosen type of selected presence data comprises at least one of human presence data configured to indicate whether an unidentified human is present and user presence data configured to indicate whether the specific user is present.

9. The method of claim 7 , wherein said updating comprises determining the confidence score based, at least in part, on a time since authentication.

10. The method of claim 7 , further comprising choosing the type of selected presence data based at least in part on at least one configuration parameter.

11. The method of claim 7 , wherein when the confidence score is below an active factor threshold, said updating comprises choosing the type of selected presence data based at least in part on user presence data associated with an active factor.

12. A system comprising one or more storage mediums having stored thereon, individually or in combination, instructions that when executed by one or more processors result in the following operations comprising:

determining a confidence score in response to an initial authentication of a specific user to a user device, the initial authentication configured to open a session, the confidence score configured to indicate a current strength of authentication at a point in time during the session;

updating the confidence score based, at least in part, on at least one of an expectation of user presence and selected presence data, said updating comprising, when the confidence score is at or above a confidence score power threshold, choosing a type of selected presence data based at least in part on a power consumption associated with obtaining said chosen type of said presence data;

notifying at least one of the user device and a remote communication partner that the authentication is no longer valid if the updated confidence score is within a tolerance of a session close threshold;

determining a confidence value based at least in part on the chosen type of selected presence data; and

adjusting the confidence score based at least in part on the confidence value.

13. The system of claim 12 , wherein the chosen type of selected presence data comprises at least one of human presence data configured to indicate whether an unidentified human is present and user presence data configured to indicate whether the specific user is present.

14. The system of claim 12 , wherein said updating comprises determining the confidence score based, at least in part, on a time since authentication.

15. The system of claim 12 , wherein when the confidence score is below an active factor threshold, the type of selected presence data is chosen based, at least in part, on user presence data associated with an active factor.

16. The system of claim 12 , wherein the type of selected presence data is chosen based, at least in part, on at least one configuration parameter.

Continuity (1)
Related Publication 20140366111A1 · Dec 11, 2014