IP Library Granted Patent US 10,284,601
Granted Patent B1
US 10,284,601 · App. 15/597,393 · Granted May 7, 2019

Managing deviations between expected and normal operations of authentication systems

Inventors: Ika Bar-Menachem (Herzelia, IL); Marcelo Blatt (Modiin, IL); Tomer Meidan (Ramat Gan, IL); Elad Koren (Tel Aviv, IL); Oded Peer (Raanana, IL); Shachar Israeli (Hod Hasharon, IL)
Assignee: EMC IP Holding Company LLC
H04L63/20H04L63/1433G06Q20/4016
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,284,601
App. No.
15/597,393
Filed
May 17, 2017
Granted
May 7, 2019
Kind
B1
Art Unit
2497
USPC
726/1
Abstract

There are disclosed techniques for use in authentication. In one embodiment, the techniques comprise generating first and second distributions. The first distribution relating to risk scores expected to be produced by an authentication system in connection with requests to access a computerized resource. The expected risk scores are based on a normalization process configured to produce risk scores by normalizing raw risk scores in connection with requests. The second distribution relates to risk scores actually produced by the authentication system in connection with requests. The actual risk scores include risk scores normalized by the normalization process. The techniques also comprise comparing the first and second distributions by determining a Kolmogorov-Smirnov distance between the respective distributions. The techniques also comprise initiating, based on the comparison, a failover of the normalization process to a new normalization process for use by the authentication system.

Claims (41)

1. A computer-implemented method, comprising:

generating, by processing circuitry, a first distribution of risk scores expected to be produced by an authentication system in connection with a first set of one or more requests to access a computerized resource, wherein generating the first distribution comprises utilizing a normalization process to produce the expected risk scores by normalizing preliminary expected risk scores in connection with the first set of one or more requests to a scale of risk scores such that a pre-defined amount of the first set of one or more requests have expected risk scores in a range of risk scores at an end of the scale indicating high risk;

generating, by processing circuitry, a second distribution relating to risk scores actually produced by the authentication system in connection with a second set of one or more requests to access the computerized resource, wherein generating the second distribution comprises utilizing a normalization process to produce the actual risk scores by normalizing preliminary actual risk scores in connection with the second set of one or more requests to the scale of risk scores;

performing, by processing circuitry, a comparison between the first and the second distributions, wherein performing the comparison comprises utilizing the Kolmogorov-Smirnov distance to detect a deviation between the expected and the actual risk scores in the range of risk scores at the end of the scale indicating high risk;

performing, by processing circuitry, a normalization process failover to a new normalization process after detection of the deviation, wherein the new normalization process is configured to reduce the deviation between the expected and the actual risk scores in the range of risk scores at the end of the scale indicating high risk, wherein the new normalization process is based on data related to a third set of one or more requests to access the computerized resource that are received after the detection of the deviation;

receiving, by processing circuitry, a fourth set of one or more requests to access the computerized resource after the detection of the deviation,

determining, by processing circuitry, actual risk scores in connection with the fourth set of one or more requests by normalizing preliminary actual risk scores in connection with the fourth set of one or more requests to the scale of risk scores in accordance with the new normalization process; and

utilizing, by processing circuitry, the actual risk scores in connection with the fourth set of one or more requests to control access to the computerized resource.

2. The method as claimed in claim 1 , wherein the first distribution comprises a first empirical cumulative distribution suitable for comparing with a distribution that relates to actual risk scores.

3. The method as claimed in claim 1 , wherein the second distribution comprises a second empirical cumulative distribution suitable for comparing with a distribution that relates to expected risk scores.

4. The method as claimed in claim 1 , wherein the initiation of the failover is based on the Kolmogorov-Smirnov distance between the respective distributions being larger than a value that is based on Kolmogorov-Smirnov distances associated with historical distributions.

5. The method as claimed in claim 1 , wherein the initiation of the failover is based on the Kolmogorov-Smirnov distance between the respective distributions being larger than a conversion function associated with a required assurance level of a goodness-of-fit test.

6. The method as claimed in claim 1 , wherein the initiation of the failover is based on there being a sufficient amount of historical information.

7. An apparatus, comprising:

memory; and

processing circuitry coupled to the memory, the memory storing instructions which, when executed by the processing circuitry, cause the processing circuitry to:

generate a first distribution of risk scores expected to be produced by an authentication system in connection with a first set of one or more requests to access a computerized resource, wherein generating the first distribution comprises utilizing a normalization process to produce the expected risk scores by normalizing preliminary expected risk scores in connection with the first set of one or more requests to a scale of risk scores such that a pre-defined amount of the first set of one or more requests have expected risk scores in a range of risk scores at an end of the scale indicating high risk;

generate a second distribution relating to risk scores actually produced by the authentication system in connection with a second set of one or more requests to access the computerized resource, wherein generating the second distribution comprises utilizing a normalization process to produce the actual risk scores by normalizing preliminary actual risk scores in connection with the second set of one or more requests to the scale of risk scores;

perform a comparison between the first and the second distributions, wherein performing the comparison comprises utilizing the Kolmogorov-Smirnov distance to detect a deviation between the expected and the actual risk scores in the range of risk scores at the end of the scale indicating high risk;

perform a normalization process failover to a new normalization process after detection of the deviation, wherein the new normalization process is configured to reduce the deviation between the expected and the actual risk scores in the range of risk scores at the end of the scale indicating high risk, wherein the new normalization process is based on data related to a third set of one or more requests to access the computerized resource that are received after the detection of the deviation;

receive a fourth set of one or more requests to access the computerized resource after the detection of the deviation;

determine actual risk scores in connection with the fourth set of one or more requests by normalizing preliminary actual risk scores in connection with the fourth set of one or more requests to the scale of risk scores in accordance with the new normalization process; and

utilize actual risk scores in connection with the fourth set of one or more requests to control access to the computerized resource.

8. The apparatus as claimed in claim 7 , wherein the first distribution comprises a first empirical cumulative distribution suitable for comparing with a distribution that relates to actual risk scores.

9. The apparatus as claimed in claim 7 , wherein the second distribution comprises a second empirical cumulative distribution suitable for comparing with a distribution that relates to expected risk scores.

10. The apparatus as claimed in claim 7 , wherein the initiation of the failover is based on the Kolmogorov-Smirnov distance between the respective distributions being larger than a value that is based on Kolmogorov-Smirnov distances associated with historical distributions.

11. The apparatus as claimed in claim 7 , wherein the initiation of the failover is based on the Kolmogorov-Smirnov distance between the respective distributions being larger than a conversion function associated with a required assurance level of a goodness-of-fit test.

12. The apparatus as claimed in claim 7 , wherein the initiation of the failover is based on there being a sufficient amount of historical information.

13. A computer program product having a non-transitory computer-readable medium storing instructions, the instructions, when carried out by processing circuitry, causing the processing circuitry to perform a method of:

generating a first distribution of risk scores expected to be produced by an authentication system in connection with a first set of one or more requests to access a computerized resource, wherein generating the first distribution comprises utilizing a normalization process to produce the expected risk scores by normalizing preliminary expected risk scores in connection with the first set of one or more requests to a scale of risk scores such that a pre-defined amount of the first set of one or more requests have expected risk scores in a range of risk scores at an end of the scale indicating high risk;

generating a second distribution relating to risk scores actually produced by the authentication system in connection with a second set of one or more requests to access the computerized resource, wherein generating the second distribution comprises utilizing a normalization process to produce the actual risk scores by normalizing preliminary actual risk scores in connection with the second set of one or more requests to the scale of risk scores;

performing a comparison between the first and the second distributions, wherein performing the comparison comprises utilizing the Kolmogorov-Smirnov distance to detect a deviation between the expected and the actual risk scores in the range of risk scores at the end of the scale indicating high risk;

performing a normalization process failover to a new normalization process after detection of the deviation, wherein the new normalization process is configured to reduce the deviation between the expected and the actual risk scores in the range of risk scores at the end of the scale indicating high risk, wherein the new normalization process is based on data related to a third set of one or more requests to access the computerized resource that are received after the detection of the deviation;

receiving a fourth set of one or more requests to access the computerized resource after the detection of the deviation;

determining actual risk scores in connection with the fourth set of one or more requests by normalizing preliminary actual risk scores in connection with the fourth set of one or more requests to the scale of risk scores in accordance with the new normalization process; and

utilizing the actual risk scores in connection with the fourth set of one or more requests to control access to the computerized resource.

14. The computer program product as claimed in claim 13 , wherein the first distribution comprises a first empirical cumulative distribution suitable for comparing with a distribution that relates to actual risk scores.

15. The computer program product as claimed in claim 13 , wherein the second distribution comprises a second empirical cumulative distribution suitable for comparing with a distribution that relates to expected risk scores.

16. The computer program product as claimed in claim 13 , wherein the initiation of the failover is based on the Kolmogorov-Smirnov distance between the respective distributions being larger than a value that is based on Kolmogorov-Smirnov distances associated with historical distributions.

17. The computer program product as claimed in claim 13 , wherein the initiation of the failover is based on the Kolmogorov-Smirnov distance between the respective distributions being larger than a conversion function associated with a required assurance level of a goodness-of-fit test.

18. The computer program product as claimed in claim 13 , wherein the initiation of the failover is based on there being a sufficient amount of historical information.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (043775/0082) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060958/0468 →
RELEASE OF SECURITY INTEREST AT REEL 043772 FRAME 0750 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0606 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 043775/0082 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043772/0750 →
Continuity (1)
Continuation 14230551 · Mar 31, 2014
Cited By (2)
US 12,212,581 US 12,664,485