Systems and methods for user authentication based on multiple devices
Abstract
A user may be authenticated using an authentication scheme based on user access to two or more selected electronic devices. A security key may be assigned to the user. The security key is divided into multiple parts that are distributed among electronic devices associated with the user. The security key can be reconstructed based on a distributed trust among the devices, where some devices may have a higher trust level than others. For example, each device can receive a number of key parts. In response to a request to authenticate the user, parts of the security key may be retrieved from two or more, but less than all, of the plurality of electronic devices associated with the user. The retrieved parts are used to reconstruct the security key, and the user is authenticated based on the reconstructed security key.
Claims
exact text as granted — not AI-modified1 . (canceled)
2 . A system, comprising:
a processor; a network interface device; and a computer-readable medium having stored thereon instructions that are executable to cause the system to perform operations comprising: receiving an authentication request, corresponding to a user of a first user device, to authenticate the user for a requested access to a computing resource analyzing the authentication request to determine a required multi-device security trust level for approving the authentication request, the multi-device security trust level corresponding to a plurality of different computing devices associated with the user, wherein the plurality of different computing devices include at least two different types of computing device; based on the required multi-device security trust level, obtaining first and second partial authentication responses for the authentication request respectively from a first of the plurality of different computing devices and a second of the plurality of different computing devices, wherein the first and second partial authentication responses include first and second security authentication information that is user-specific and issued only to the user, and wherein each of the first and second partial authentication responses is insufficient by itself to authenticate the user for the authentication request; calculating a total received security trust score for the authentication request based on the first and second partial authentication responses, wherein the first partial authentication response contributes a first trust amount to the total received security trust score and the second partial authentication response contributes a second trust amount to the total received security trust score; based on the total received security trust score, generating an authentication response for the authentication request from the user; and transmitting the generated authentication response via the network interface device.
3 . The system of claim 2 , wherein generating the authentication response comprises determining if the total received security trust score meets a required threshold for the required multi-device security trust level and generating an approval authentication response if the required threshold is met, and generating a rejection authentication response if the required threshold is not met.
4 . The system of claim 2 , wherein the first trust amount is different from the second trust amount.
5 . The system of claim 2 , wherein the operations further comprise:
causing the first and second security authentication information to be distributed to the first and second different computing devices prior to receiving the authentication request.
6 . The system of claim 2 , wherein the computing resource comprises an Internet server configured to provide access to functionality of a user account of the user.
7 . The system of claim 2 , wherein the operations further comprise:
causing a prompt to be shown to the user on the first user device indicating an identity of available devices of the plurality different computing devices that are usable to fulfill the authentication request.
8 . A method, comprising:
receiving, by a computer system, an authentication request corresponding to a user of a first user device, wherein the authentication request is to authenticate the user for a requested access to a computing resource; analyzing the authentication request to determine a required multi-device security trust level for approving the authentication request, the multi-device security trust level corresponding to a plurality of different computing devices associated with the user, wherein the plurality of different computing devices include at least two different types of computing device; based on the required multi-device security trust level, the computer system receiving first and second partial authentication responses for the authentication request respectively from a first of the plurality of different computing devices and a second of the plurality of different computing devices, wherein the first and second partial authentication responses include first and second security authentication information that is user-specific, and wherein each of the first and second partial authentication responses is insufficient by itself to authenticate the user for the authentication request; calculating, by the computer system, a total received security trust score for the authentication request based on the first and second partial authentication responses, wherein the first partial authentication response contributes a first trust amount to the total received security trust score and the second partial authentication response contributes a second trust amount to the total received security trust score; based on the total received security trust score, the computer system generating an authentication response for the authentication request from the user; and the computer system transmitting the generated authentication response via a network interface device of the computer system.
9 . The method of claim 8 , wherein the operations further comprise:
responsive to a user registration request prior to the authentication request, registering the first and second different computing devices for authentication usage for the user and assigning the first and second different computing devices different trust amounts.
10 . The method of claim 8 , wherein generating the authentication response comprises determining if the total received security trust score meets a required threshold for the required multi-device security trust level and generating an approval authentication response if the required threshold is met, and generating a rejection authentication response if the required threshold is not met.
11 . The method of claim 8 , further comprising:
causing a prompt to be shown to the user on the first user device indicating an identity of available devices of the plurality different computing devices that are usable to fulfill the authentication request.
12 . The method of claim 8 , wherein the computing resource comprises an Internet server configured to provide access to functionality of a user account of the user.
13 . The method of claim 8 , wherein the generated authentication response is transmitted to the first user device.
14 . The method of claim 8 , wherein the first different computing device comprises a smart appliance associated with a particular communication network corresponding to the user.
15 . The method of claim 8 , wherein the first and second partial authentication responses each comprise respective encrypted information decryptable only by the computer system.
16 . A non-transitory computer-readable medium having stored thereon instructions that are executable by a computer system to cause the computer system to perform operations comprising:
receiving an authentication request, corresponding to a user of a first user device, to authenticate the user for a requested access to a computing resource analyzing the authentication request to determine a required multi-device security trust level for approving the authentication request, the multi-device security trust level corresponding to a plurality of different computing devices associated with the user, wherein the plurality of different computing devices include at least two different types of computing device; based on the required multi-device security trust level, obtaining first and second partial authentication responses for the authentication request respectively from a first of the plurality of different computing devices and a second of the plurality of different computing devices, wherein the first and second partial authentication responses include first and second security authentication information that is user-specific and issued only to the user, and wherein each of the first and second partial authentication responses is insufficient by itself to authenticate the user for the authentication request; calculating a total received security trust score for the authentication request based on the first and second partial authentication responses, wherein the first partial authentication response contributes a first trust amount to the total received security trust score and the second partial authentication response contributes a second trust amount to the total received security trust score; based on the total received security trust score, generating an authentication response for the authentication request from the user; and transmitting the generated authentication response via the network interface device.
17 . The non-transitory computer-readable medium of claim 16 , wherein generating the authentication response comprises determining if the total received security trust score meets a required threshold for the required multi-device security trust level and generating an approval authentication response if the required threshold is met, and generating a rejection authentication response if the required threshold is not met.
18 . The non-transitory computer-readable medium of claim 16 , wherein the first trust amount is different from the second trust amount.
19 . The non-transitory computer-readable medium of claim 16 , wherein the computing resource comprises an Internet server configured to provide access to functionality of a user account of the user.
20 . The non-transitory computer-readable medium of claim 16 , wherein the operations further comprise:
causing a prompt to be shown to the user on the first user device indicating an identity of available devices of the plurality different computing devices that are usable to fulfill the authentication request.
21 . The non-transitory computer-readable medium of claim 16 , wherein the generated authentication response is transmitted to the first user device.Join the waitlist — get patent alerts
Track US2022094678A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.