IP Library › Granted Patent US 11,743,245
Granted Patent B2
US 11,743,245 · App. 17/077,557 · Granted Aug 29, 2023

Identity access management using access attempts and profile updates

Inventors: Kieran Gerard Sherlock (Palo Alto, CA); Jose Caldera (Palo Alto, CA)
Assignee: Acuant, Inc.
H04L63/08H04L63/105H04L63/108H04L63/1433H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,743,245
App. No.
17/077,557
Granted
Aug 29, 2023
Kind
B2
Abstract

Systems and methods for managing a reputation score of a user based on successful and failed logins, successful and failed multifactor authentications, and profile changes is described. The method includes receiving, by a server, status information of a user event from one or more computing devices. The status information includes one or more of an indicator of a successful login, an indicator of a failed login, an indicator of a successful multifactor authentication, an indicator of a failed multifactor authentication, an indicator of a profile update, and metadata associated with the user event from the one or more computing devices. The server updates events based on a type of the status information received and storing the events in a data store and determines whether a problematic situation has occurred. A reputation score of the user is updated when the problematic situation is determined.

Claims (39)

1. A method, comprising:

receiving, by a server, status information of a user event from one or more computing devices, wherein the status information includes one or more of an indicator of a successful login, an indicator of a failed login, an indicator of a successful multifactor authentication, an indicator of a failed multifactor authentication, an indicator of a profile update, and metadata associated with the user event from the one or more computing devices;

updating, by the server, events based on a type of the status information received and storing the events in a data store;

determining, by the server, whether a problematic situation has occurred; and

updating a reputation score of the user when the problematic situation is determined;

wherein the status information comprises a count of events, and in response to the count exceeding a threshold for at least one of a successful login, a successful multifactor authentication, a failed login, or a failed multifactor authentication, updating the reputation score of the user comprises changing a risk amount in the reputation score of the user,

wherein updating the reputation score of the user in response to a successful login, a successful multifactor authentication, or combination thereof, comprises reducing a risk amount in the reputation score of the user, and

wherein updating the reputation score of the user in response to a failed login, a failed multifactor authentication, or combination thereof, comprises increasing a risk amount in the reputation score of the user.

2. The method of claim 1 , wherein the profile update comprises an indicator of an identity-defining component that identifies an identity of an owner of the profile.

3. The method of claim 1 , wherein in response to determining the problematic situation has occurred, the method comprises requiring the user to reverify.

4. The method of claim 1 , wherein the one or more computing devices include a user computing device used for accessing one or more sites or a computing device making the one or more sites available to the user.

5. The method of claim 1 , comprising alerting the user of a change to the reputation score of the user.

6. The method of claim 1 , wherein the status information comprises non-quantifiable data.

7. The method of claim 6 , wherein the non-quantifiable data includes metadata defining authentication parameters.

8. A non-transitory computer-readable storage medium for tangibly storing computer program instructions capable of being executed by a computer processor, the computer program instructions defining a method, comprising:

receiving, by a server, status information of a user event from one or more computing devices, wherein the status information includes one or more of an indicator of a successful login, an indicator of a failed login, an indicator of a successful multifactor authentication, an indicator of a failed multifactor authentication, an indicator of a profile update, and metadata associated with the user event from the one or more computing devices;

updating, by the server, events based on a type of the status information received and storing the events in a data store;

determining, by the server, whether a problematic situation has occurred; and

updating a reputation score of the user when the problematic situation is determined;

wherein the status information comprises a count of events, and in response to the count exceeding a threshold for at least one of a successful login, a successful multifactor authentication, a failed login, or a failed multifactor authentication, updating the reputation score of the user comprises changing a risk amount in the reputation score of the user,

wherein updating the reputation score of the user in response to a successful login, a successful multifactor authentication, or combination thereof, comprises reducing a risk amount in the reputation score of the user, and

wherein updating the reputation score of the user in response to a failed login, a failed multifactor authentication, or combination thereof, comprises increasing a risk amount in the reputation score of the user.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the profile update comprises an indicator of an identity-defining component that identifies an identity of an owner of the profile.

10. The non-transitory computer-readable storage medium of claim 8 , comprising alerting the user of a change to the reputation score of the user.

11. The non-transitory computer-readable storage medium of claim 8 , wherein in response to determining the problematic situation has occurred, the method comprises requiring the user to reverify.

12. The non-transitory computer-readable storage medium of claim 8 , wherein the status information comprises non-quantifiable data, the non-quantifiable data defining authentication parameters.

13. A system, comprising:

a processor; and

a non-transitory computer-readable storage medium for tangibly storing thereon program instructions for execution by the processor, the stored program instructions comprising:

receiving, by a server, status information of a user event from one or more computing devices, wherein the status information includes one or more of an indicator of a successful login, an indicator of a failed login, an indicator of a successful multifactor authentication, an indicator of a failed multifactor authentication, an indicator of a profile update, and metadata associated with the user event from the one or more computing devices;

updating, by the server, events based on a type of the status information received and storing the events in a data store;

determining, by the server, whether a problematic situation has occurred; and

updating a reputation score of the user when the problematic situation is determined;

wherein the status information comprises a count of events, and in response to the count exceeding a threshold for at least one of a successful login, a successful multifactor authentication, a failed login, or a failed multifactor authentication, updating the reputation score of the user comprises changing a risk amount in the reputation score of the user,

wherein updating the reputation score of the user in response to a successful login, a successful multifactor authentication, or combination thereof, comprises reducing a risk amount in the reputation score of the user, and

wherein updating the reputation score of the user in response to a failed login, a failed multifactor authentication, or combination thereof, comprises increasing a risk amount in the reputation score of the user.

14. The system of claim 13 , wherein the profile update comprises an indicator of an identity-defining component that identifies an identity of an owner of the profile.

15. The system of claim 13 , wherein the status information comprises non-quantifiable data, the non-quantifiable data defining authentication parameters.

16. The system of claim 13 , wherein in response to determining the problematic situation has occurred, the stored program instructions comprise requiring the user to reverify.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2020
From: SHERLOCK, KIERAN GERARD; CALDERA, JOSE
To: ACUANT, INC.
Reel/Frame 054141/0216 →
Continuity (1)
Related Publication 20220131844A1 · Apr 28, 2022
Cited By (1)
US 12,476,998