IP Library Granted Patent US 11,599,611
Granted Patent B2
US 11,599,611 · App. 16/719,258 · Granted Mar 7, 2023

Continuous authentication system and related methods

Inventors: Andrew James Malton (Waterloo, CA); Andrew Eric Walenstein (Waterloo, CA)
Assignee: BlackBerry Limited
G06F21/32G06F21/316G06F2221/2103G06F2221/2113G06F2221/2139
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,599,611
App. No.
16/719,258
Filed
Dec 18, 2019
Granted
Mar 7, 2023
Kind
B2
Art Unit
2433
USPC
726/19
Abstract

A continuous authentication system and related methods are provided. The system detects requests to perform user actions. A security value is associated with each user action. The system determines a subsequent session security level in response to an adjustment to a session security level by a security value of a requested user action. The requested user action is permitted and the session security level is adjusted based on the security value of the requested user action in response to a determination by the system that the subsequent session security level is greater than or equal to a threshold session security level. A user authentication challenge is caused (e.g., prompted) in response to a determination by the system that the subsequent session security level is less than the threshold session security level. The requested user action is permitted and the session security level is adjusted based on the security value of the requested user action in response to a successful user authentication challenge. The requested user action is rejected in response to an unsuccessful user authentication challenge.

Claims (44)

1. A non-transitory machine readable medium having tangibly stored thereon executable instructions for execution by a processor of a computing device, wherein the executable instructions, when executed by the processor, cause the computing device to:

detect a request to perform a user action of a plurality of user actions, wherein each of the plurality of user actions has a corresponding type, wherein each type of user action has a security value, wherein the security value of each type of user action is based on a time of inactivity measured from a last user action of the respective type, wherein the security value is gradually increased based on the time of inactivity measured from the last user action of the respective type;

determine the security value of the requested user action;

in response to the request to perform the user action, determine a subsequent session security level based on the security value of the requested user action and a session security level;

in response to a determination that the subsequent session security level is greater than or equal to a threshold session security level, permit the requested user action and adjust the session security level based on the security value of the requested user action; and

in response to a determination that the subsequent session security level is less than the threshold session security level, cause a user authentication challenge:

in response to a successful user authentication challenge, permit the requested user action and adjust the session security level based on one or both of the security value of the requested user action and a security value of a successful user authentication challenge; and

in response to an unsuccessful user authentication challenge, reject the user action.

2. The non-transitory machine readable medium of claim 1 , wherein the session security level is based on a time of inactivity measured from a last user action.

3. The non-transitory machine readable medium of claim 2 , wherein the session security level is gradually decreased based on the time of inactivity measured from the last user action.

4. The non-transitory machine readable medium of claim 1 , wherein each user action type is an explicit security action, an implicit security action, or a non-security action.

5. The non-transitory machine readable medium of claim 4 , wherein an explicit security action comprises a re-authentication action, an implicit security action comprises a non-resource specific user action, and a non-security action comprises a resource specific user action.

6. The non-transitory machine readable medium of claim 5 , wherein an implicit security action comprises any one or more of session information or biometric information.

7. The non-transitory machine readable medium of claim 6 , wherein the biometric information comprises any one or more of a typing speed, a typing cadence, a clicking speed, a clicking cadence, gait, finger print or eye scan.

8. The non-transitory machine readable medium of claim 6 , wherein the session information comprises any one or more of an idle time duration, a user activity rate, or a session duration.

9. The non-transitory machine readable medium of claim 5 , wherein the non-security actions comprises any one of a document access or idle time duration.

10. The non-transitory machine readable medium of claim 9 , wherein the document access comprises any one or more of a document read, a document write, a document copy, a document delete, a document move, or a document profile change.

11. The non-transitory machine readable medium of claim 1 , wherein the security value is based at least in part on a resource associated with the user action.

12. The non-transitory machine readable medium of claim 1 , wherein the session security level is associated with a user account of the session.

13. The non-transitory machine readable medium of claim 1 , wherein the security value is dynamically determined based on the user actions within the session.

14. The non-transitory machine readable medium of claim 1 , wherein the session security level is increased in response to the security value being positive, wherein the session security level is decreased in response to the security value being negative, and wherein the session security level is unchanged in response to the security value being neutral.

15. The non-transitory machine readable medium of claim 1 , wherein the session security level is adjusted in response to each permitted user action.

16. A computing device having a processor and a memory coupled to the processor, the memory having tangibly stored thereon executable instructions for execution by the processor, wherein the executable instructions, when executed by the processor, cause the computing device to:

detect a request to perform a user action of a plurality of user actions, wherein each of the plurality of user actions has a corresponding type, wherein each type of user action has a security value, wherein the security value of each type of user action is based on a time of inactivity measured from a last user action of the respective type, wherein the security value is gradually increased based on the time of inactivity measured from the last user action of the respective type;

determine the security value of the requested user action;

in response to the request to perform the user action, determine a subsequent session security level based on the security value of the requested user action and a session security level;

in response to a determination that the subsequent session security level is greater than or equal to a threshold session security level, permit the requested user action and adjust the session security level based on the security value of the requested user action; and

in response to a determination that the subsequent session security level is less than the threshold session security level, cause a user authentication challenge:

in response to a successful user authentication challenge, permit the requested user action and adjust the session security level based on one or both of the security value of the requested user action and a security value of a successful user authentication challenge; and

in response to an unsuccessful user authentication challenge, reject the user action.

17. A continuous authentication method, comprising:

detecting a request to perform a user action of a plurality of user actions, wherein each of the plurality of user actions has a corresponding type, wherein each type of user action has a security value, wherein the security value of each type of user action is based on a time of inactivity measured from a last user action of the respective type, wherein the security value is gradually increased based on the time of inactivity measured from the last user action of the respective type;

determining the security value of the requested user action;

in response to the request to perform the user action, determining a subsequent session security level based on the security value of the requested user action and a session security level;

in response to a determination that the subsequent session security level is greater than or equal to a threshold session security level, permitting the requested user action and adjust the session security level based on the security value of the requested user action; and

in response to a determination that the subsequent session security level is less than the threshold session security level, causing a user authentication challenge:

in response to a successful user authentication challenge, permitting the requested user action and adjust the session security level based on one or both of the security value of the requested user action and a security value of a successful user authentication challenge; and

in response to an unsuccessful user authentication challenge, rejecting the user action.

18. A non-transitory machine readable medium having tangibly stored thereon executable instructions for execution by a processor of a computing device, wherein the executable instructions, when executed by the processor, cause the computing device to:

detect a request to perform a user action of a plurality of user actions, wherein each of the plurality of user actions has a corresponding type, wherein each type of user action has a security value, wherein the security value of each type of user action is based on a time of inactivity measured from a last user action of the respective type, wherein the security value is gradually increased based on the time of inactivity measured from the last user action of the respective type;

in response to a determination that a session security level is greater than or equal to a threshold session security level, permit the requested user action and adjust the session security level based on the security value of the requested user action; and

in response to a determination that the session security level is less than the threshold session security level, cause a user authentication challenge:

in response to a successful user authentication challenge, permit the requested request and adjust the session security level based on one or both of the security value of the requested user action and a security value of a successful user authentication challenge; and

in response to an unsuccessful user authentication challenge, reject the requested user action.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2020
From: MALTON, ANDREW JAMES
To: BLACKBERRY LIMITED
Reel/Frame 052308/0669 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2020
From: WALENSTEIN, ANDREW ERIC
To: BLACKBERRY CORPORATION
Reel/Frame 052308/0786 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2020
From: BLACKBERRY CORPORATION
To: BLACKBERRY LIMITED
Reel/Frame 052095/0780 →
Continuity (1)
Related Publication 20210192027A1 · Jun 24, 2021