US2017277873A1PendingUtilityA1

Characterizing user behavior via intelligent identity analytics

Assignee: PEGRIGHT INCPriority: Apr 29, 2014Filed: Jun 9, 2017Published: Sep 28, 2017
Est. expiryApr 29, 2034(~7.8 yrs left)· nominal 20-yr term from priority
G06F 21/45G06N 20/00G06F 21/316G06N 99/005
41
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, devices, and systems are provided to rapidly detect and prevent cyber-attacks that are enabled by either misuse of identity credentials or weaknesses within the identity credential lifecycle. An Identity Analytics and Intelligence Engine provides an automated process for the collection, exchange, analysis, correlation, and reporting of identity credential lifecycle data. The Identity Analytics and Intelligence Engine may be implemented as a Software as a Service (SaaS) capability. The Identity Analytics and Intelligence Engine applies Semantic Web concepts/technologies and graph databases to automatically capture the identity credential lifecycle data along with the associated data exchanges within one or more Trust Frameworks.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 collecting information associated with an identity credential associated with a user; and   creating two or more distributed graph databases, wherein each graph database is configured to store identity credential lifecycle data associated with the identity credential.   
     
     
         2 . The method of  claim 1 , further comprising:
 receiving a query associated with the identity credential lifecycle data of the identity credential;   arranging, in response to receiving the query, the identity credential lifecycle data in the two or more distributed graph databases for the identity credential into at least one data set having user behavior information; and   summarizing the user behavior information of the at least one data set.   
     
     
         3 . The method of  claim 2 , wherein summarizing the user behavior information of the at least one data set further comprises:
 applying at least one machine learning algorithm to the user behavior information of the at least one data set; and   creating, in response to applying the at least one machine learning algorithm, a use pattern for the identity credential.   
     
     
         4 . The method of  3 , further comprising:
 creating, in response to applying the at least one machine learning algorithm, a behavior pattern for the identity credential.   
     
     
         5 . The method of  claim 4 , further comprising:
 storing the use and behavior pattern for the identity credential in a memory associated with the identity credential.   
     
     
         6 . The method of  claim 5 , further comprising:
 receiving a subsequent query associated with the identity credential lifecycle data of the identity credential;   arranging, in response to receiving the subsequent query, the identity credential lifecycle data in the two or more distributed graph databases for the identity credential into at least another data set having user behavior information;   applying at least one machine learning algorithm to the user behavior information of the at least another data set;   creating, in response to applying the at least one machine learning algorithm, a subsequent use and behavior pattern for the identity credential; and   storing the use and behavior pattern for the identity credential in a memory associated with the identity credential.   
     
     
         7 . The method of  claim 2 , wherein arranging the identity credential lifecycle data in the two or more distributed graph databases, further comprises:
 filtering the user behavior information in the two or more distributed graph databases for the identity credential.   
     
     
         8 . The method of  claim 2 , wherein arranging the identity credential lifecycle data in the two or more distributed graph databases, further comprises:
 sorting the user behavior information in the two or more distributed graph databases for the identity credential.   
     
     
         9 . A method, comprising:
 collecting identity lifecycle data associated with at least one identity credential, wherein the identity lifecycle data includes a definition of at least one use behavior associated with the at least one identity credential;   determining an anticipated use behavior based on the collected identity lifecycle data; and   determining a variation between the anticipated use behavior and a detected unanticipated use behavior, wherein the detected unanticipated use behavior includes a use behavior of the identity lifecycle data that is outside a threshold of the anticipated use behavior.   
     
     
         10 . The method of  claim 9 , wherein the detected unanticipated use behavior includes at least one of a different subscriber authentication and different authorization property for the at least one identity credential than a subscriber authentication and authorization property associated with the anticipated use behavior. 
     
     
         11 . The method of  claim 10 , wherein the detected unanticipated use behavior is used to at least one of enable and authorize additional controlled behaviors in the identity credential lifecycle data, wherein the additional controlled behaviors include a processing function unavailable to the anticipated use behavior. 
     
     
         12 . A trust framework situated between a subscriber having an identity credential and a relying party that provides one or more computing resources to the subscriber based on identity authorization verifications received from the trust framework, the trust framework comprising:
 an identity and intelligence engine that automatically performs the following:
 (i) maintains a canonical data model for identity credential lifecycle data related to the subscriber; 
 (ii) receives event information related to at least one of actions and inactions of the subscriber and catalogs the event information; 
 (iii) compares the received event information with the canonical data model to determine whether or not the subscriber is acting in conformance with the canonical data model; and 
 (iv) in the event that the subscriber is determined to be acting out of conformance with the canonical data model, notifies the relying party thereby enabling the relying party to deny or restrict the subscriber's access to the one or more computing resources. 
   
     
     
         13 . The trust framework of  claim 12 , wherein the canonical data model is maintained with information obtained from a plurality of different data sources. 
     
     
         14 . The trust framework of  claim 12 , wherein the identity and intelligence engine further creates a set of distributed graph databases that represent the canonical data model. 
     
     
         15 . The trust framework of  claim 12 , wherein a predetermined deviation between the at least one of actions and inactions and the canonical data model is provided to allow the subscriber to still be in conformance with the canonical data model even when the at least one of actions and inactions to not exactly match the canonical data model. 
     
     
         16 . The trust framework of  claim 12 , wherein the identity and intelligence engine continuously and automatically updates the canonical data model with the at least one of actions and inactions when the subscriber is determined to be in conformance with the canonical data model. 
     
     
         17 . The trust framework of  claim 12 , wherein the identity credential lifecycle data includes data related to the creation, ownership, data update, usage, and patterns of behaviors associated with the identity credential. 
     
     
         18 . The trust framework of  claim 12 , wherein the received event information is compared in real-time. 
     
     
         19 . The trust framework of  claim 12 , wherein notifying the relying party includes rendering an alert image to a computer display operated by the relying party. 
     
     
         20 . The trust framework of  claim 14 , wherein the identity and intelligence engine automatically analyzes the canonical data in the graph databases using one or more machine learning algorithm.

Join the waitlist — get patent alerts

Track US2017277873A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.