Processing authentication requests to secured information systems using machine-learned user-account behavior profiles

    公开(公告)号:US11036838B2

    公开(公告)日:2021-06-15

    申请号:US16210062

    申请日:2018-12-05

    Abstract: Aspects of the disclosure relate to processing authentication requests to secured information systems using machine-learned user-account behavior profiles. A computing platform may receive an authentication request corresponding to a request for a user of a client computing device to access one or more secured information resources associated with a user account. The computing platform may capture one or more behavioral parameters and activity data associated with one or more interactions with one or more non-authenticated pages. Then, the computing platform may evaluate the one or more behavioral parameters and the activity data using a behavioral profile associated with the user account. Based on this evaluation, the computing platform may identify the authentication request as malicious and may generate and send one or more denial-of-access commands to prevent the client computing device from accessing the one or more secured information resources associated with the user account.

    DETERMINING USER AUTHENTICATION BASED ON USER/DEVICE INTERACTION
    6.
    发明申请
    DETERMINING USER AUTHENTICATION BASED ON USER/DEVICE INTERACTION 有权
    基于用户/设备交互确定用户认证

    公开(公告)号:US20160055326A1

    公开(公告)日:2016-02-25

    申请号:US14928332

    申请日:2015-10-30

    Abstract: Embodiments are directed to systems, methods and computer program products for providing user authentication based on historical user patterns. Embodiments of the present invention may be configured to communicate code executable by a computing device that causes the computing device to monitor user patterns of a user based on the user interacting with the computing device; receive baseline user patterns to identify the user; identify, from the baseline user patterns, one or more routine actions performed by the user operating the computing device; receive a request to perform a transaction, wherein the transaction is associated with a level of security that must be authenticated; receive identification user patterns of the user based on the user interacting with the computing device; determine a threshold score based on comparing the identification user patterns with the baseline user patterns; and alter the level of security.

    Abstract translation: 实施例涉及用于基于历史用户模式提供用户认证的系统,方法和计算机程序产品。 本发明的实施例可以被配置为传送可由计算设备执行的代码,其使得计算设备基于与计算设备交互的用户来监视用户的用户模式; 接收基准用户模式以识别用户; 从所述基准用户模式识别由所述用户操作所述计算设备执行的一个或多个例行动作; 接收执行事务的请求,其中所述事务与必须被认证的安全级别相关联; 基于与计算设备交互的用户接收用户的识别用户模式; 通过将识别用户模式与基准用户模式进行比较来确定阈值分数; 并改变安全级别。

    User authentication based on historical user behavior
    7.
    发明授权
    User authentication based on historical user behavior 有权
    基于历史用户行为的用户认证

    公开(公告)号:US09185101B2

    公开(公告)日:2015-11-10

    申请号:US14175947

    申请日:2014-02-07

    CPC classification number: H04L63/08 G06F21/316 H04L63/105 H04L2463/082

    Abstract: Embodiments are directed to systems, methods and computer program products for providing user authentication based on historical user patterns. Embodiments receive from a user, a request to execute a user action associated with an application, wherein execution of the user action requires validation of authentication credentials; collect a set of data comprising information related to usage patterns associated with the apparatus of the user; determine a user pattern score associated with the user; determine a level of authentication; determine which authentication types are associated with the level of authentication; request authentication credentials corresponding to the authentication types; receive authentication credentials from the user; validate the authentication credentials, thereby resulting in a successful validation of the authentication credentials; and, in response to the successful validation, execute the user action.

    Abstract translation: 实施例涉及用于基于历史用户模式提供用户认证的系统,方法和计算机程序产品。 实施例从用户接收执行与应用相关联的用户动作的请求,其中用户动作的执行需要认证证书的验证; 收集包括与用户的装置相关联的使用模式的信息的一组数据; 确定与用户相关联的用户模式得分; 确定认证级别; 确定哪些认证类型与认证级别相关联; 请求与认证类型相对应的认证凭证; 从用户接收认证凭证; 验证身份验证凭证,从而导致验证凭证成功验证; 并且响应成功的验证,执行用户操作。

    COMPLETING MOBILE BANKING TRANSACTION WITH DIFFERENT DEVICES
    9.
    发明申请
    COMPLETING MOBILE BANKING TRANSACTION WITH DIFFERENT DEVICES 审中-公开
    完成移动银行交易与不同的设备

    公开(公告)号:US20150026057A1

    公开(公告)日:2015-01-22

    申请号:US13946581

    申请日:2013-07-19

    CPC classification number: G06Q20/3223 G06Q40/02

    Abstract: Embodiments of the present invention relates to systems, computer-implemented methods, and computer program products for completing a mobile banking transaction at a trusted location. In some embodiments, the system is configured to: (a) initiate, via a mobile device, a transaction request for a mobile banking transaction; (b) store the transaction request for the mobile banking transaction in a queue for mobile banking transaction requests; (c) retrieve from the queue, using a computing device, the transaction request for the mobile banking transaction, wherein the computing device is different from the mobile device; and (d) complete, using the computing device, the transaction request for the mobile banking transaction.

    Abstract translation: 本发明的实施例涉及用于在可信位置完成移动银行交易的系统,计算机实现的方法和计算机程序产品。 在一些实施例中,系统被配置为:(a)经由移动设备发起移动银行交易的交易请求; (b)将移动银行交易的交易请求存储在移动银行交易请求的队列中; (c)使用计算设备从所述队列中检索所述移动银行交易的交易请求,其中所述计算设备与所述移动设备不同; 和(d)使用计算设备完成移动银行交易的交易请求。

    ONLINE BANKING ALERTS
    10.
    发明申请
    ONLINE BANKING ALERTS 审中-公开
    在线银行报警

    公开(公告)号:US20150026053A1

    公开(公告)日:2015-01-22

    申请号:US13946304

    申请日:2013-07-19

    CPC classification number: G06Q20/108 G06Q20/3221

    Abstract: Disclosed is a system and associated method for providing alerts regarding a customer's online banking account. The system typically includes a processor, a memory, and an online banking module stored in the memory. The module is typically configured for initially associating a mobile device with the customer's online banking account. In addition, the module is typically configured for subsequently determining whether a computing device has engaged in a predefined online banking transaction associated with the customer's online banking account and transmitting a notification that the computing device has engaged in the predefined online banking transaction to the mobile device based on determining that (i) the computing device has engaged in a predefined online banking transaction associated with the customer's online banking account and (ii) the mobile device is associated with the customer's online banking account.

    Abstract translation: 公开了一种用于提供关于客户的在线银行账户的警报的系统和相关联的方法。 该系统通常包括存储在存储器中的处理器,存储器和网上银行模块。 该模块通常被配置为初始地将移动设备与客户的在线银行账户相关联。 此外,模块通常被配置用于随后确定计算设备是否已经参与与客户的在线银行帐户相关联的预定义的在线银行交易,并且将计算设备已经参与预定义的在线银行交易的通知发送到移动设备 基于确定(i)计算设备已经参与与客户的在线银行帐户相关联的预定义的在线银行交易,以及(ii)移动设备与客户的在线银行帐户相关联。

Patent Agency Ranking