US2022094678A1PendingUtilityA1

Systems and methods for user authentication based on multiple devices

Assignee: PAYPAL INCPriority: Jun 13, 2018Filed: Nov 30, 2021Published: Mar 24, 2022
Est. expiryJun 13, 2038(~11.9 yrs left)· nominal 20-yr term from priority
Inventors:Shlomi Boutnaru
G06Q 20/3829G06Q 20/12G06Q 20/4014G06Q 20/308H04L 2463/082G06Q 20/4016H04L 9/0894H04L 2209/56H04L 9/085G06Q 2220/00H04L 63/08H04L 2209/84H04L 63/0853H04L 63/06G06Q 20/306H04L 2209/805G06Q 20/321
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A user may be authenticated using an authentication scheme based on user access to two or more selected electronic devices. A security key may be assigned to the user. The security key is divided into multiple parts that are distributed among electronic devices associated with the user. The security key can be reconstructed based on a distributed trust among the devices, where some devices may have a higher trust level than others. For example, each device can receive a number of key parts. In response to a request to authenticate the user, parts of the security key may be retrieved from two or more, but less than all, of the plurality of electronic devices associated with the user. The retrieved parts are used to reconstruct the security key, and the user is authenticated based on the reconstructed security key.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A system, comprising:
 a processor;   a network interface device; and   a computer-readable medium having stored thereon instructions that are executable to cause the system to perform operations comprising:   receiving an authentication request, corresponding to a user of a first user device, to authenticate the user for a requested access to a computing resource   analyzing the authentication request to determine a required multi-device security trust level for approving the authentication request, the multi-device security trust level corresponding to a plurality of different computing devices associated with the user, wherein the plurality of different computing devices include at least two different types of computing device;   based on the required multi-device security trust level, obtaining first and second partial authentication responses for the authentication request respectively from a first of the plurality of different computing devices and a second of the plurality of different computing devices, wherein the first and second partial authentication responses include first and second security authentication information that is user-specific and issued only to the user, and wherein each of the first and second partial authentication responses is insufficient by itself to authenticate the user for the authentication request;   calculating a total received security trust score for the authentication request based on the first and second partial authentication responses, wherein the first partial authentication response contributes a first trust amount to the total received security trust score and the second partial authentication response contributes a second trust amount to the total received security trust score;   based on the total received security trust score, generating an authentication response for the authentication request from the user; and   transmitting the generated authentication response via the network interface device.   
     
     
         3 . The system of  claim 2 , wherein generating the authentication response comprises determining if the total received security trust score meets a required threshold for the required multi-device security trust level and generating an approval authentication response if the required threshold is met, and generating a rejection authentication response if the required threshold is not met. 
     
     
         4 . The system of  claim 2 , wherein the first trust amount is different from the second trust amount. 
     
     
         5 . The system of  claim 2 , wherein the operations further comprise:
 causing the first and second security authentication information to be distributed to the first and second different computing devices prior to receiving the authentication request.   
     
     
         6 . The system of  claim 2 , wherein the computing resource comprises an Internet server configured to provide access to functionality of a user account of the user. 
     
     
         7 . The system of  claim 2 , wherein the operations further comprise:
 causing a prompt to be shown to the user on the first user device indicating an identity of available devices of the plurality different computing devices that are usable to fulfill the authentication request.   
     
     
         8 . A method, comprising:
 receiving, by a computer system, an authentication request corresponding to a user of a first user device, wherein the authentication request is to authenticate the user for a requested access to a computing resource;   analyzing the authentication request to determine a required multi-device security trust level for approving the authentication request, the multi-device security trust level corresponding to a plurality of different computing devices associated with the user, wherein the plurality of different computing devices include at least two different types of computing device;   based on the required multi-device security trust level, the computer system receiving first and second partial authentication responses for the authentication request respectively from a first of the plurality of different computing devices and a second of the plurality of different computing devices, wherein the first and second partial authentication responses include first and second security authentication information that is user-specific, and wherein each of the first and second partial authentication responses is insufficient by itself to authenticate the user for the authentication request;   calculating, by the computer system, a total received security trust score for the authentication request based on the first and second partial authentication responses, wherein the first partial authentication response contributes a first trust amount to the total received security trust score and the second partial authentication response contributes a second trust amount to the total received security trust score;   based on the total received security trust score, the computer system generating an authentication response for the authentication request from the user; and   the computer system transmitting the generated authentication response via a network interface device of the computer system.   
     
     
         9 . The method of  claim 8 , wherein the operations further comprise:
 responsive to a user registration request prior to the authentication request, registering the first and second different computing devices for authentication usage for the user and assigning the first and second different computing devices different trust amounts.   
     
     
         10 . The method of  claim 8 , wherein generating the authentication response comprises determining if the total received security trust score meets a required threshold for the required multi-device security trust level and generating an approval authentication response if the required threshold is met, and generating a rejection authentication response if the required threshold is not met. 
     
     
         11 . The method of  claim 8 , further comprising:
 causing a prompt to be shown to the user on the first user device indicating an identity of available devices of the plurality different computing devices that are usable to fulfill the authentication request.   
     
     
         12 . The method of  claim 8 , wherein the computing resource comprises an Internet server configured to provide access to functionality of a user account of the user. 
     
     
         13 . The method of  claim 8 , wherein the generated authentication response is transmitted to the first user device. 
     
     
         14 . The method of  claim 8 , wherein the first different computing device comprises a smart appliance associated with a particular communication network corresponding to the user. 
     
     
         15 . The method of  claim 8 , wherein the first and second partial authentication responses each comprise respective encrypted information decryptable only by the computer system. 
     
     
         16 . A non-transitory computer-readable medium having stored thereon instructions that are executable by a computer system to cause the computer system to perform operations comprising:
 receiving an authentication request, corresponding to a user of a first user device, to authenticate the user for a requested access to a computing resource   analyzing the authentication request to determine a required multi-device security trust level for approving the authentication request, the multi-device security trust level corresponding to a plurality of different computing devices associated with the user, wherein the plurality of different computing devices include at least two different types of computing device;   based on the required multi-device security trust level, obtaining first and second partial authentication responses for the authentication request respectively from a first of the plurality of different computing devices and a second of the plurality of different computing devices, wherein the first and second partial authentication responses include first and second security authentication information that is user-specific and issued only to the user, and wherein each of the first and second partial authentication responses is insufficient by itself to authenticate the user for the authentication request;   calculating a total received security trust score for the authentication request based on the first and second partial authentication responses, wherein the first partial authentication response contributes a first trust amount to the total received security trust score and the second partial authentication response contributes a second trust amount to the total received security trust score;   based on the total received security trust score, generating an authentication response for the authentication request from the user; and   transmitting the generated authentication response via the network interface device.   
     
     
         17 . The non-transitory computer-readable medium of  claim 16 , wherein generating the authentication response comprises determining if the total received security trust score meets a required threshold for the required multi-device security trust level and generating an approval authentication response if the required threshold is met, and generating a rejection authentication response if the required threshold is not met. 
     
     
         18 . The non-transitory computer-readable medium of  claim 16 , wherein the first trust amount is different from the second trust amount. 
     
     
         19 . The non-transitory computer-readable medium of  claim 16 , wherein the computing resource comprises an Internet server configured to provide access to functionality of a user account of the user. 
     
     
         20 . The non-transitory computer-readable medium of  claim 16 , wherein the operations further comprise:
 causing a prompt to be shown to the user on the first user device indicating an identity of available devices of the plurality different computing devices that are usable to fulfill the authentication request.   
     
     
         21 . The non-transitory computer-readable medium of  claim 16 , wherein the generated authentication response is transmitted to the first user device.

Join the waitlist — get patent alerts

Track US2022094678A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.