US2019356673A1PendingUtilityA1

Smart authentication friction level adjusted based on circumstances

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Jun 14, 2016Filed: Jun 10, 2019Published: Nov 21, 2019
Est. expiryJun 14, 2036(~9.9 yrs left)· nominal 20-yr term from priority
H04L 63/107G06F 2221/2137G06F 2221/2111H04L 63/08H04L 63/108G06F 21/316H04W 12/06H04W 12/065H04W 12/069
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Granting a validation period. A method includes receiving user input providing one or more authentication factors. The method further includes receiving information about one or more authentication scales. Based on the strength of the authentication factors received from the user and the information about the one or more authentication scales, the method further includes determining a validation period. The method further includes granting or revoking the validation period to the user.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A computer system comprising:
 a processor; and   a computer-readable hardware storage device having stored thereon instructions that are executable by the processor to configure the computer system to grant access to the computer system based on an adversity quotient, including instructions that are executable to configure the computer system to perform at least the following:
 receive an environmental sensor signal about a circumstance relating to a user device; 
 compute an adversity quotient at least based on the environmental sensor signal; 
 determine that the adversity quotient meets a first adversity quotient threshold; 
 based at least on determining that the first adversity quotient threshold has been met, identify an authentication factor that is valid at the first adversity quotient threshold, the authentication factor being valid at the first adversity quotient threshold for authenticating the user device to the computer system but being invalid at a second adversity quotient threshold for authenticating the user device to the computer system; 
 initiate a request for a user to provide the authentication factor; 
 receive a user input providing the authentication factor; and 
 based on receiving the authentication factor, grant the user device access to the computer system. 
   
     
     
         3 . The computer system of  claim 2 , wherein the environmental sensor signal comprises at least one of a geographical location of the user device, a physical location of the user device, a network associated with the user device, a presence of another device in proximity to the user device, a date on which the user device is operating, or a time of day on which the user device is operating. 
     
     
         4 . The computer system of  claim 2 , wherein initiating the request for the user to provide the authentication factor comprises initiating a request for the user to provide one of a plurality of authentication factors that are valid at the first adversity quotient threshold. 
     
     
         5 . The computer system of  claim 2 , the instructions including instructions that are executable to configure the computer system to determine a length of a validation time-period, during which time-period the user device is granted access to the computer system. 
     
     
         6 . The computer system of  claim 5 , wherein the length of the validation time-period is determined based on an authentication scale that ranks a strength of a plurality of different authentication factors, the length of the validation time-period being longer for a more strongly-ranked authentication factor than it is for a more weakly-ranked authentication factor. 
     
     
         7 . The computer system of  claim 6 , wherein the authentication scale comprises at least one of a user scale comprising weights and rules configured by a computing system user, a service scale comprising weights and rules provided by a computing service, or an enterprise scale comprising rules and weights provided by an enterprise. 
     
     
         8 . The computer system of  claim 5 , the instructions including instructions that are executable to configure the computer system to revoke or shorten the validation time-period, based on determining that a change to the adversity quotient. 
     
     
         9 . The computer system of  claim 8 , wherein the change to the adversity quotient is based at least on a change to the environmental sensor signal. 
     
     
         10 . The computer system of  claim 2 , wherein the authentication factor is a first authentication factor, and wherein a second authentication factor is valid at the second adversity quotient threshold. 
     
     
         11 . The computer system of  claim 10 , wherein the second authentication factor is invalid at the first adversity quotient threshold. 
     
     
         12 . The computer system of  claim 10 , wherein the first authentication factor is associated with a first authentication friction level, and wherein the second authentication factor is associated with a second authentication friction level. 
     
     
         13 . A method, implemented at a computer system that includes a processor, for granting access to a computer service based on an adversity quotient, the method comprising:
 receiving an environmental sensor signal about a circumstance relating to a user device;   computing an adversity quotient at least based on the environmental sensor signal;   determining that the adversity quotient meets a first adversity quotient threshold;   based at least on determining that the first adversity quotient threshold has been met, identifying an authentication factor that is valid at the first adversity quotient threshold, the authentication factor being valid at the first adversity quotient threshold for authenticating the user device to the computer service but being invalid at a second adversity quotient threshold for authenticating the user device to the computer service;   initiating a request for a user to provide the authentication factor;   receiving a user input providing the authentication factor; and   based on receiving the authentication factor, granting the user device access to the computer service.   
     
     
         14 . The method of  claim 13 , wherein the environmental sensor signal comprises at least one of a geographical location of the user device, a physical location of the user device, a network associated with the user device, a presence of another device in proximity to the user device, a date on which the user device is operating, or a time of day on which the user device is operating. 
     
     
         15 . The method of  claim 13 , wherein initiating the request for the user to provide the authentication factor comprises initiating a request for the user to provide one of a plurality of authentication factors that are valid at the first adversity quotient threshold. 
     
     
         16 . The method of  claim 13 , further comprising determining a length of a validation time-period, during which time-period the user device is granted access to the computer service. 
     
     
         17 . The method of  claim 16 , further comprising revoking or shortening the validation time-period, based on determining that a change to the adversity quotient. 
     
     
         18 . The method of  claim 13 , wherein the authentication factor is a first authentication factor, and wherein a second authentication factor is valid at the second adversity quotient threshold. 
     
     
         19 . The method of  claim 18 , wherein the second authentication factor is invalid at the first adversity quotient threshold. 
     
     
         20 . The method of  claim 18 , wherein the first authentication factor is associated with a first authentication friction level, and wherein the second authentication factor is associated with a second authentication friction level.

Join the waitlist — get patent alerts

Track US2019356673A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.