US20160197918A1

Device, system, and method of password-less user authentication and password-less detection of user identity

Claim Score by NHIP

Read claim 1, the broadest

Abstract

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting possible attackers; as well as password-less user authentication, and password-less detection of user identity. A system or a computing device requires a user to perform a particular unique non-user-defined task, the task optionally being an on-screen connect-the-dots task. The system monitors user interactions, extracts user-specific features that characterizes the manner in which the user performs the tasks; and subsequently relies on such user-specific features as a means for user authentication, optionally without utilizing a password or passphrase. Optionally, a user interface anomaly or interference is intentionally introduced in order to elicit the user to perform corrective gestures, which are optionally used for extraction of additional user-specific features.

US20160197918A1, drawing sheet 1
Sheet 1 of 4

Term

6 yearsto projected expiry

Projected expiry 24 September 2032, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

31 claims: 2 independent, 29 dependent

  1. 1
    Broadest claimClaim Score 40, average(NHIP)A method comprising:differentiating between a first user and a second user of a computerized service, by performing: (a) autonomously selecting a unique and non-user-defined task, that is intended to be performed by a specific user via an input unit of an electronic device;(b) generating the task, and collecting user interactions data via the input unit while the user is performing the task;(c) repeating step (b) for at least N iterations for said specific user, wherein N is a positive integer;(d) during step (b) and during step (c), determining from said user interactions data a user-specific cognitive behavioral biometric profile;(e) storing the user-specific cognitive behavioral profile in a repository;(f) subsequently, generating said task again upon a subsequent request of a user to access said computerized service, and collecting fresh user interactions data from fresh performance of said task;(g) if the fresh user interactions data that was collected from said fresh performance of said task, does not match the previously-stored user-specific cognitive behavioral biometric profile, then un-authorizing access of the user to the computerized service.
  2. 29
    An apparatus comprising:a memory unit to store code;a processor to execute said code;an input unit to receive manual user interactions;a user-authentication unit to perform: (a) increasing a range of possible manual user interactions that are usable for automated distinguishing among different users, by autonomously selecting and allocating, to each user in a group of users or to each electronic device in a group of electronic devices, a unique task that is performed via an input unit;(b) collecting user interactions data, at least during performance of said unique task;(c) based on the collected user interactions data, generating a user-specific cognitive behavioral biometric signature;(d) subsequently, during a fresh attempt for user authentication: (i) generating said unique task;(ii) collecting fresh user interactions data at least during performance of said unique task;(iii) if the fresh user interactions data does not match said user-specific cognitive behavioral biometric signature, then rejecting the fresh attempt for user authentication.