Systems and methods for user authentication based on multiple devices

By allocating and reconstructing security keys among multiple electronic devices accessible to users, the security and convenience of existing authentication methods are solved, and secure and flexible multi-device collaborative authentication is achieved.

CN112567365BActive Publication Date: 2025-07-29PAYPAL INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201980052919.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-06-13
Filing Date
2019-06-12
Publication Date
2025-07-29
Estimated Expiration
2039-06-12

AI Technical Summary

Technical Problem

The existing user authentication methods have security and convenience issues. Conventional methods rely on users to select and protect passwords. Biometric verification requires additional hardware, and smart card verification requires additional equipment, which leads to insecure and inconvenience.

Method used

Based on the variable trust pattern of multiple electronic devices accessible by the user, authentication is performed using the distributed trust reconstruction key between devices by dividing security keys and assigning part of the keys between these devices according to the device trust level.

Benefits of technology

It provides a secure and convenient authentication method, and enhances the security and flexibility of the system through multi-device collaborative verification, adapting to verification needs at different risk levels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112567365B_ABST
    Figure CN112567365B_ABST
Patent Text Reader

Abstract

A user can be authenticated using an authentication scheme based on the user's access to two or more selected electronic devices. A security key can be assigned to the user. The security key is divided into multiple parts, and these multiple parts are distributed among the electronic devices associated with the user. The security key can be reconstructed based on the distributed trust among the devices, where some devices may have a higher trust level than others. For example, each device can receive a certain number of key parts. In response to a request to authenticate the user, parts of the security key can be retrieved from two or more (but less than all) of the multiple electronic devices associated with the user. The retrieved parts are used to reconstruct the security key, and the user is authenticated based on the reconstructed security key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification generally relates to user authentication, and more specifically, according to various embodiments of the present disclosure, relates to authenticating a user based on a variable trust model that involves a security key and an electronic device accessible by the user. Background Art

[0002] With the growth in the ability to access personal information and perform online transactions, the need for a secure and convenient way to authenticate users is increasing. Conventional authentication involving usernames and passwords has proven to be insecure and inconvenient in various aspects because the technology relies on the user to select a strong password and protect the password from malicious users. Biometric-based authentication techniques such as fingerprint scanning, iris scanning, facial recognition, etc. may require additional hardware and / or additional steps performed by the user to collect biometric data. Similarly, although smart card-based authentication can be more secure than just providing a username and password, it also requires additional hardware (e.g., a smart card reader) to accept the smart card. Therefore, there is a need to provide an improved authentication system that is secure and convenient. Brief Description of the Drawings

[0003] Figure 1 is a block diagram showing an electronic transaction system according to an embodiment of the present disclosure;

[0004] Figure 2 is a block diagram showing an authentication system according to an embodiment of the present disclosure;

[0005] Figure 3 is a flowchart showing a process of registering a user with an authentication system according to an embodiment of the present disclosure;

[0006] Figure 4 is a block diagram showing an authentication system according to an embodiment of the present disclosure;

[0007] Figure 5 is a flowchart showing a process of authenticating a user according to an embodiment of the present disclosure; and

[0008] Figure 6 is a block diagram of a system for implementing a device according to an embodiment of the present disclosure.

[0009] Embodiments of the present disclosure and their advantages are best understood by reference to the following detailed description. It should be recognized that like reference numerals are used to identify like elements illustrated in one or more of the drawings, where the drawings are shown for the purpose of illustrating embodiments of the present disclosure and not for the purpose of limiting them. Detailed Description

[0010] The present disclosure describes methods and systems for authenticating a user based on the accessibility of two or more selected electronic devices by a user device associated with the user. As networked electronic devices become increasingly prevalent, a user may be able to access multiple electronic devices via the user's user device (e.g., a mobile device) in any given situation. For example, when a user is at home, the user may access one or more of a home computer, a smart TV, a smart speaker, a networked refrigerator, a networked light switch, a networked thermostat, or other smart appliances via the user device. The user device may be communicatively coupled to these different electronic devices via different networks. For example, the user device may be communicatively coupled to the home computer via a home Wi-Fi network. The user device may be communicatively coupled to the smart speaker via a Bluetooth connection. The user device may be communicatively coupled to the smart TV via an infrared connection. The user device may be communicatively coupled to smart appliances such as a networked refrigerator, a networked light switch, and a networked thermostat via a Zigbee network or any other network protocol.

[0011] Similarly, when a user is away from home, the user may use the user device to access the in-vehicle management system of a vehicle (e.g., via a Bluetooth connection, etc.), a home security system (e.g., via an IP connection), a smartwatch the user is wearing (e.g., via a Bluetooth connection), a pair of smart glasses the user is wearing (e.g., via a Bluetooth connection), a chip on a pair of shoes (e.g., via a near field communication (NFC) connection), a chip on a briefcase (e.g., via a radio frequency identification connection), and so on. When a user is at work, the user may use the user device to access one or more of the following: a work computer (e.g., via a work Wi-Fi network), a smart speaker at work (e.g., via a Bluetooth connection), an external screen (e.g., via an infrared connection), or other electronic devices in the office. Thus, based on the user's location and / or the activities the user is engaged in, the user may be able to access different electronic devices. Note that the communication protocols and devices listed above are merely examples, and other protocols and / or devices may be used in various embodiments.

[0012] Accordingly, an authentication system may authenticate a user based on the user's ability to access two or more electronic devices associated with the user. In particular, as will be described below, these various devices may be associated with specific trust levels. For example, certain devices may have a higher trust level than other devices (because it may be more difficult to "hack" certain types of devices compared to others). During registration of the user with the authentication system, the authentication system may obtain the identities of the electronic devices accessible to the user. In some embodiments, for each electronic device, the authentication system may also obtain the network protocol and network address through which communication with the electronic device is possible.

[0013] Additionally, an authentication system can assign one or more security keys to a user for authenticating the user. The security keys assigned to the user can be divided into multiple different parts. In some embodiments, the security key can be divided in such a way that it can be reconstructed based on fewer than the total number of divided parts. For example, the security key can be divided into a total of nine parts, but any four of these nine parts may be sufficient to reconstruct the security key for authenticating the user.

[0014] In some embodiments, the different parts can be distributed among the electronic devices accessible to the user, e.g., via the user's user device. One or more parts of the security key can be sent to each electronic device accessible to the user based on the network protocol and network address associated with the electronic device according to a distribution scheme. These parts can then be stored in the non-transitory data storage device (e.g., random access memory storage device, flash drive, etc.) of the electronic device.

[0015] Different embodiments can use different techniques to determine the distribution scheme for distributing the parts among the electronic devices. In some embodiments, the authentication system can determine the distribution scheme based on the trust score associated with the electronic device. For example, when information about the electronic device is obtained, the authentication system can analyze the device to determine the trust score of the device. The trust score can be determined for the device based on the security profile of the device. For example, the authentication system can obtain the security level of each device and determine the trust score of the device based on the security level. In some embodiments, the authentication system can access each electronic device (e.g., via the user device) to analyze the hardware configuration (e.g., whether the hardware includes any security modules), software configuration (e.g., whether the software includes any security modules, whether any security patches are installed, etc.) and location (e.g., whether the device is fixed in a certain location) of the device. The authentication system can determine and / or update the trust score of the device based on the analysis of the hardware configuration, software configuration, and / or location of the device, and can determine the distribution scheme based on the trust score of the device. For example, the distribution scheme can provide a greater number of parts to the devices with a higher trust score (based on the hardware configuration, software configuration, and / or location) and a smaller number of parts to the devices with a lower trust score (based on the hardware configuration, software configuration, and / or location). Thus, in the authentication scheme discussed herein, different devices with different trust levels can be assigned a greater or smaller influence (via the number of distributed key parts assigned to them).

[0016] In some embodiments, the authentication system can then distribute portions of the security key among the electronic devices according to the determined distribution scheme. For example, when the security key is divided into nine portions, the authentication system can distribute three portions to the smart TV (since the smart TV is fixed in a location and can only be connected via an infrared connection, and forcing an infrared connection requires a line of sight from the connecting device), one portion to the chip in the briefcase (since the briefcase can be in a public area and can be easily stolen, etc.), two portions to the work computer (since the work computer should be physically located in a secure area), and so on. In different embodiments, various factors can determine the specific key portion assignments.

[0017] For example, when a user attempts to log in to a service provider's user account on a user device, or when a user attempts to conduct an electronic transaction using a user device, a request to authenticate the user can be received via the user device. For example, an authentication request can be generated in association with the user logging in to a PayPal TM account or another electronic account. Upon receiving the request, the authentication system can select some but not all of the electronic devices to authenticate the user.

[0018] In some embodiments, when the authentication system obtains information related to an electronic device, the authentication system can generate different profiles and / or associate different profiles with the electronic device. In one example, the authentication system can generate a home profile, a work profile, and a commute profile. Each electronic device can be associated with one or more profiles based on the location and / or circumstances in which the user can access the electronic device. For example, a home computer, a smart TV, a connected refrigerator, a connected light switch, and a connected thermostat can be associated with the home profile. A smartwatch and smart glasses can be associated with all of the home profile, the work profile, and the commute profile. The in-vehicle management system of a vehicle can be associated with the commute profile. The chips on shoes and the chips on briefcases can be associated with both the commute profile and the work profile. A work computer, an external screen in the office, a smart speaker at the workplace, and other electronic devices in the office can be associated with the work profile. Other profile types can be used in various embodiments.

[0019] In this way, the authentication system can first determine the user's location and / or activity and select an electronic device associated with the corresponding profile based on the determined location and / or activity. For example, when the authentication system determines that the user is at home, the authentication system can select an electronic device associated with the home profile. Similarly, when the authentication system determines that the user is commuting, the authentication system can select an electronic device associated with the commuting profile, and when the authentication system determines that the user is at work, the authentication system can select an electronic device associated with the work profile. However, in some embodiments, the authentication system can randomly select two or more electronic devices from the electronic devices associated with the user.

[0020] In addition, the authentication system can select a sufficient number of electronic devices such that the total number of portions assigned to the selected electronic devices is sufficient to reconstruct the security key. In some embodiments, the authentication system can select electronic devices such that at least two electronic devices need to access two different types of network connections (e.g., different network protocols) to enhance the security and effectiveness of the authentication system.

[0021] The authentication system can then access the selected electronic devices via the user device, retrieve the portions from the selected electronic devices, and reconstruct the security key based on the retrieved portions. The authentication system can authenticate the user based on the reconstructed security key. For example, when all the selected electronic devices can be accessed via the user device and thus all the portions assigned to the selected electronic devices are retrieved, the reconstructed security key should match the original security key assigned to the user. On the other hand, when fewer than the required number of portions are retrieved to reconstruct the security key (e.g., when one or more of the selected electronic devices cannot be accessed via the user device), the reconstructed security key will not match the original security key assigned to the user. Therefore, the authentication system can authenticate the user based on the reconstructed security key, and more specifically based on whether the reconstructed security key matches the original security key assigned to the user.

[0022] In some embodiments, the authentication system may update the trust score of an electronic device based on new information related to the security risk of the electronic device. For example, when the authentication system accesses a selected electronic device to retrieve parts, the authentication system may analyze the software configuration of the electronic device. When it is determined that the software of the electronic device (e.g., the operating system) has been updated, the authentication system may increase the trust score of the electronic device. On the other hand, when a new security module / update is available for the electronic device but is determined not to be installed on the device, the authentication system may decrease the trust score of the electronic device. Based on the updated trust score of the electronic device, the authentication system may update the allocation scheme. In some embodiments, the authentication system may remove one or more parts from the electronic device based on the updated trust score of the electronic device. The authentication system may also add one or more parts to the electronic device based on the updated trust score of the electronic device.

[0023] In some embodiments, more than one security key may be assigned to a user. Different security keys may be divided into parts in different ways such that for different security keys, different numbers of parts are required to reconstruct the corresponding security key. Additionally, different security keys may correspond to different risk levels, so a security key that requires a larger number of parts to be reconstructed may correspond to a higher risk level compared to a security key that requires a smaller number of parts to be reconstructed. For example, a first security key that requires two out of nine divided parts to be reconstructed may correspond to a low risk level, a second security key that requires four out of nine divided parts to be reconstructed may correspond to a medium risk level, and a third security key that requires six out of nine divided parts to be reconstructed may correspond to a high risk level. The parts of different security keys may be allocated among electronic devices according to the same allocation scheme or different allocation schemes.

[0024] Thus, upon receiving a request to authenticate a user, the authentication system may first determine the risk level associated with the request. For example, when the request is a request to log in to a user account, the authentication system may determine the risk level based on the location of the user (e.g., whether the user is located at a location normally associated with the user). When the request is a request to perform an electronic payment transaction, the authentication system may determine the risk level based on the amount associated with the transaction (e.g., a high risk level when the amount exceeds a predetermined threshold, a low risk level when the amount is below another predetermined threshold, etc.). The authentication system may then select one of the security keys assigned to the user based on the determined risk level of the request and retrieve the parts corresponding to the selected security key from the selected electronic device. As discussed above, the authentication system may reconstruct the security key based on the retrieved parts and authenticate the user based on the reconstructed security key.

[0025] Figure 1 FIG.

[0025] shows an electronic transaction system 100 in which an authentication system can be implemented according to an embodiment of the present disclosure. The electronic transaction system 100 includes a service provider server 130, a merchant server 120, and a user device 110 that can be communicatively coupled to each other via a network 160. In one embodiment, the network 160 can be implemented as a single network or a combination of multiple networks. For example, in various embodiments, the network 160 can include the Internet and / or one or more intranets, landline networks, wireless networks, and / or other suitable types of communication networks. In another example, the network 160 can include a wireless telecommunications network (e.g., a cellular phone network) adapted to communicate with other communication networks such as the Internet.

[0026] In one embodiment, the user device 110 can be used by a user 140 to interact with the merchant server 120 and / or the service provider server 130 via the network 160. For example, the user 140 can use the user device 110 to log in to a user account to perform account services or conduct various electronic transactions (e.g., electronic payment transactions, etc.) with the service provider server 130. Similarly, a merchant associated with the merchant server 120 can use the merchant server 120 to log in to a merchant account to perform account services or conduct various electronic transactions (e.g., electronic funds transactions, etc.) with the service provider server 130. In various embodiments, the user device 110 can be implemented using any suitable combination of hardware and / or software configured for wired and / or wireless communication on the network 160. In various implementations, the user device 110 can include at least one of the user devices described herein, such as a wireless cellular phone, a wearable computing device, a PC, a laptop computer, etc.

[0027] In one embodiment, the user device 110 includes a user interface (UI) application 112 (e.g., a web browser) that can be used by the user 140 to conduct electronic transactions (e.g., shopping, purchasing, bidding, etc.) with the service provider server 130 via the network 160. In one aspect, the purchase cost can be directly and / or automatically debited from an account associated with the user 140 via the user interface application 112.

[0028] In one implementation, the user interface application 112 includes a software program executable by a processor, such as a graphical user interface (GUI), which is configured to interface and communicate with the service provider server 130 via the network 160. In another implementation, the user interface application 112 includes a browser module that provides a web interface to browse information available on the network 160. For example, the user interface application 112 can be partially implemented as a web browser to view information available on the network 160.

[0029] In various embodiments, the user device 110 can include an authentication application 116 that implements at least some of the authentication functions disclosed herein. For example, during registration of the user 140 with the authentication system, the authentication application 116 can provide an interface to the user 140 to obtain information related to electronic devices associated with the user 140, network protocols and network addresses associated with these electronic devices, and can establish one or more profiles for these electronic devices. The authentication application 116 can also allocate portions of one or more security keys assigned to the user 140 to the electronic devices.

[0030] In some embodiments, the authentication application 116 can be communicatively coupled and / or integrated with the user interface application 112 to detect when a request to authenticate the user 140 is received. For example, when the user 140 is logging into a user account that utilizes the service provider server 130 or performing an electronic transaction with the user account via the user interface application 112, the authentication application 116 can receive a request to authenticate the user 140. When a request to authenticate the user 140 is received, the authentication application 116 can retrieve portions from one or more electronic devices based on the request to authenticate the user 140. In some embodiments, the authentication application 116 can reconstruct a security key based on the retrieved portions and authenticate the user 140 based on the reconstructed key.

[0031] In one embodiment, the user device 110 may include at least one identifier 114, which may be implemented as, for example: an operating system registry entry, a cookie associated with the user interface application 112, an identifier associated with the hardware of the user device 110 (e.g., a Media Access Control (MAC) address), or various other suitable identifiers. The identifier 114 may include one or more attributes related to the user 140 of the user device 110, such as personal information related to the user (e.g., one or more user names, passwords, photo images, biometric IDs, addresses, phone numbers, social security numbers, etc.) and banking information and / or sources of funds (e.g., one or more banking institutions, credit card issuers, user account numbers, security data and information, etc.). In various implementations, the identifier 114 may be transmitted to the service provider server 130 via the network 160 along with a user login request, and the identifier 114 may be used by the service provider server 130 to associate the user with a specific user account maintained by the service provider server 130.

[0032] In various implementations, the user 140 is able to input data and information into an input component (e.g., a keyboard) of the user device 110 to provide a transaction request for user information, such as a login request, a fund transfer request, a request to add additional sources of funds (e.g., a new credit card), or other types of requests. The user information may include user identification information.

[0033] In various embodiments, the user device 110 includes a location component 118, which is configured to determine, track, monitor, and / or provide the immediate geographical location of the user device 110. In one implementation, the geographical location may include GPS coordinates, zip code information, area code information, street address information, and / or various other commonly known types of location information. In one example, the location information may be directly input into the user device 110 by the user via a user input component such as a keyboard, a touch display, and / or a voice recognition microphone. In another example, the location information may be automatically obtained and / or provided by the user device 110 via an internal or external monitoring component that utilizes the Global Positioning System (GPS) and / or Assisted GPS (A-GPS), where GPS uses satellite-based positioning and A-GPS uses cell tower information to improve the reliability and accuracy of GPS-based positioning. In other embodiments, the location information may be automatically obtained without using GPS. In some cases, cell signals or wireless signals are used. For example, the location information may be obtained by checking in with a user device 110 via a check-in device (such as a beacon) at a certain location. This helps save battery life and allows for better indoor positioning in locations where GPS typically does not work.

[0034] Although inFigure 1 Only one user device 110 is shown, but it is contemplated that one or more user devices (each similar to user device 110) may be communicatively coupled within system 100 to service provider server 130 via network 160.

[0035] In various embodiments, merchant server 120 may be maintained by a commercial entity (or in some cases, by a partner of the commercial entity that processes transactions on behalf of the commercial entity). Examples of commercial entities include merchant premises, resource information premises, utility premises, real estate management premises, social networking premises, etc., which provide various items for purchase and process payments for purchases. Merchant server 120 may include a merchant database 124 for identifying available items, and the available database may be provided to user device 110 for viewing and purchase by a user.

[0036] In one embodiment, merchant server 122 may include a marketplace application 122 that may be configured to provide information to user interface application 112 of user device 110 via network 160. For example, user 140 of user device 110 may interact with marketplace application 122 via user interface application 112 over network 160 to search for and view various items available for purchase in merchant database 124.

[0037] In one embodiment, merchant server 120 may include at least one merchant identifier 126, which may be included as part of one or more items offered for purchase such that, for example, a particular item is associated with a particular merchant. In one implementation, merchant identifier 126 may include one or more attributes and / or parameters related to the merchant, such as commercial and banking information. Merchant identifier 126 may include attributes related to merchant server 120, such as identification information (e.g., serial number, location address, GPS coordinates, network identification number, etc.).

[0038] The merchant can also use the merchant server 120 to communicate with the service provider server 130 via the network 160. For example, in the process of providing various electronic services provided by the service provider to the merchant (such as providing an online platform that facilitates electronic payments between the merchant's customers and the merchant itself), the merchant can use the merchant server 120 to communicate with the service provider server 130. For example, the merchant server 120 can use an application programming interface (API) that allows it to offer the sale of goods or services, where customers are allowed to make electronic payments via the service provider server 130, and the user 140 can have an account with the service provider server 130 that allows the user 140 to use the service provider server 130 to make electronic payments to merchants that are allowed to use the service provider's authentication, authorization, and electronic payment services. The merchant can also have an account with the service provider server 130. Although only one merchant server 120 is shown in Figure 1 , it is contemplated that one or more merchant servers (each similar to the merchant server 120) can be communicatively coupled to the service provider server 130 and the user device 110 in the system 100 via the network 160.

[0039] In one embodiment, the service provider server 130 can be maintained by a transaction processing entity or an online service provider that can provide processing for electronic transactions between the user 140 of the user device 110 and one or more merchants. Thus, the service provider server 130 can include a service application 138 that can be adapted to interact with the user device 110 and / or the merchant server 120 via the network 160 to facilitate electronic transactions, such as logging into a user account, electronic payment transactions, customer onboarding transactions, and / or other electronic services provided by the service provider server 130. In one example, the service provider server 130 can be provided by Ltd. in San Jose, California, USA and / or one or more service entities or corresponding intermediaries that can provide multiple point-of-sale devices at various locations to facilitate the routing of transactions between merchants and, for example, service entities.

[0040] In some embodiments, the service application 138 can include a payment processing application (not shown) for processing purchases and / or payments for electronic transactions between the user and the merchant or between any two entities. In one implementation, the payment processing application assists in resolving electronic transactions through verification, delivery, and settlement. Thus, the payment processing application settles the debt between the user and the merchant, where monetary funds can be directly and / or automatically debited and / or credited to an account in a manner acceptable to the banking industry.

[0041] The service provider server 130 may also include a web server 134 configured to provide web content to a user in response to an HTTP request. Thus, the web server 134 may include pre-generated web content ready to be provided to the user. For example, the web server 134 may store a login page and be configured to provide the login page to the user for logging into the user's user account to access various services provided by the service provider server 130. The web server 134 may also include other web pages associated with different electronic services provided by the service provider server 130. As a result, the user may access the user account associated with the user and access various services provided by the service provider server 130 by generating an HTTP request for the service provider server 130.

[0042] In various embodiments, according to various embodiments of the present disclosure, the service provider server includes an authentication module 132 configured to authenticate a user 140 based on the accessibility of two or more electronic devices registered under the user account of the user 140 by the user device 110. In some embodiments, the authentication module 132 may generate one or more security keys for the user 140 and divide these security keys into multiple parts. The authentication module 132 may also distribute these parts to the electronic devices associated with the user 140 via the authentication application 116 according to an allocation scheme.

[0043] The authentication module 132 can receive an authentication request. For example, when the web server 132 receives a request to log in to a user account from the user interface application 112 of the user device 110, the authentication request can be received from the web server 132. The request can be received from the service application 138 when the service application 138 receives a request from the user device 110 to perform one or more electronic transactions with the service provider server 130. The request can also be received from the marketplace application 122 of the merchant server 120 when the user 140 performs an online purchase transaction with the merchant server 120. Upon receiving the authentication request, the authentication module 132 can select two or more of the electronic devices associated with the user 140 and retrieve portions from the two or more selected electronic devices via the authentication application 116. The authentication module 132 can reconstruct the security key based on the portions retrieved via the authentication application 116 and authenticate the user 140 based on the reconstructed security key. In some embodiments, the authentication module 132 and the authentication application 116 are part of an authentication system that can provide the authentication functionality disclosed herein as a stand-alone application or integrated with one or more services (such as the services associated with the service provider server 130 shown herein).

[0044] In one embodiment, the service provider server 130 can be configured to maintain one or more user accounts and merchant accounts in the account database 136, each of which can include account information associated with one or more individual users (e.g., the user 140 associated with the user device 110) and merchants. For example, the account information can include information related to the electronic devices associated with the corresponding user account (e.g., the identity of the electronic device, the network protocol and network address of the electronic device, etc.), the private financial information of the user and the merchant, which can be used by the authentication module 132 to authenticate the user. In certain embodiments, the account information further includes: user purchase profile information (such as the account funding options and payment options associated with the user), payment information, receipts, and other information collected in response to completed funding and / or payment transactions.

[0045] Figure 2Illustrated is an authentication system 200 according to an embodiment of the present disclosure. The authentication system 200 includes an authentication application 216, an authentication module 232, a database 202, and electronic devices, which include a networked lighting switch 242, an in-vehicle management system 244 of a vehicle of user 140, a smart home entertainment system 246, a networked refrigerator 248, and a smart watch 250. The authentication application 216 may correspond to the authentication application 116 of the user device 110, and the authentication module 232 may correspond to the authentication module 132 of the service provider server 130. The user device 110 may connect to and access the electronic devices 242-250 via different network protocols. For example, the networked lighting switch 242 may be connected via a Zigbee connection, the in-vehicle management system 244 may be connected via a Bluetooth connection, the smart home entertainment system 246 may be connected via a wireless infrared communication connection, the networked refrigerator 248 may be connected via a Wi-Fi connection using the Internet Protocol (IP), and the smart watch 250 may be connected via a Bluetooth connection.

[0046] Figure 3 Illustrated is a process 300 for registering a user to the authentication system 200 according to an embodiment of the present disclosure. In some embodiments, the process 300 may be executed by the authentication system 200. The process 300 begins by generating a security key for a user account (at step 305). For example, the authentication application 216 may provide a user interface that enables user 140 to register with the authentication system 200. During the registration process, the authentication module 232 may generate a security key 204 for a new user account associated with user 140. In some embodiments, the security key 204 may be a private key corresponding to a public key in an asymmetric cryptosystem.

[0047] Process 300 then (at step 310) divides the security key into multiple parts. For example, the authentication module 232 may divide the security key 204 according to a scheme (e.g., Shamir's secret sharing scheme) such that fewer than the total number of divided parts are required to reconstruct the security key 204. According to Shamir's secret sharing scheme, the security key 204 can be represented as a polynomial with multiple coefficients. Each divided part can represent a point associated with the polynomial (e.g., a non-zero integer input into the polynomial, and the corresponding integer output) such that multiple parts (fewer than the total number of divided parts) may be required to reconstruct the polynomial (security key 204). In some embodiments, the authentication module 232 may determine the number of parts desired or required to reconstruct the security key 204 before dividing the security key 204. For example, the authentication module 232 may decide to divide the security key 204 into nine parts, where any four parts are required to reconstruct the security key 204. The authentication module 232 may then divide the security key 204 into nine parts 210 (210a - 210i) according to Shamir's secret sharing scheme using the determined parameters.

[0048] Process 300 then (at step 315) identifies the electronic devices associated with the user account. For example, during the registration process, the authentication application 216 may obtain from the user 104 the identities of the electronic devices to be associated with the user account. In some embodiments, the authentication application 216 may be able to access the networking hardware of the user device 110 (e.g., network card, network adapter, antenna, etc.). The authentication application 216 may prompt the user 104 to access the electronic devices to be associated with the user account via the authentication application 116. The user 104 may have to indicate the network protocols (e.g., Wi-Fi protocol, Bluetooth protocol, Zigbee protocol, wireless infrared communication protocol, etc.) and possibly the network addresses associated with these electronic devices. In some embodiments, the authentication application 116 may discover the electronic devices based on the selected network protocol and may enable the user 140 to select from the discovered devices. As discussed herein, the electronic devices may be located at different locations (e.g., at home, at work, etc.). Thus, the authentication application 216 may enable the user 104 to continue registering new electronic devices to be associated with the user account over a period of time (e.g., several days, etc.).

[0049] As new electronic devices are added to be associated with a user account, information related to these electronic devices is obtained and stored (e.g., in database 202). Information for each electronic device may include: a name (e.g., assigned by user 104), a network protocol for connecting to the electronic device, and a network address. Additionally, as authentication application 216 accesses each electronic device, authentication application 216 may allocate space in the non-transitory memory of the electronic device (e.g., random access memory, flash drive, etc.) for storing portions of one or more security keys.

[0050] Authentication module 232 may also determine a trust score for each electronic device based on the security profile of the electronic device. For example, when authentication application 216 accesses an electronic device during the registration process, authentication application 216 may analyze the network connection type, hardware configuration, software configuration, and location (e.g., detection-based information obtained from location component 118 of user device 110 when accessing the electronic device via user device 110). For example, the trust score of an electronic device may start at "0", and as network connection types, hardware configurations, software configurations, and / or locations that enhance the security of the electronic device are revealed, authentication system 200 may correspondingly increase the trust score of the electronic device. In one example, based on authentication system 200 determining that the latest security software has been installed on smartwatch 250, authentication system 200 may increase the trust score of smartwatch 250. Authentication system 200 may determine a trust score of '20' for smartwatch 250. In another example, based on authentication system 200 determining that the connection type of smart home entertainment system 246 (e.g., wireless infrared communication) requires a line of sight to the connected device and smart home entertainment system 246 is fixed on the second story of user 140's home, authentication system 200 increases the trust score of smart home entertainment system 246. Authentication system 200 may determine a trust score of '30' for smart home entertainment system 246. In yet another example, authentication system 200 may determine that refrigerator 248 can be connected to the network via an IP connection and the latest security software has not been installed on networked refrigerator 248. Accordingly, authentication system 200 may determine a low trust score of '10' for networked refrigerator 248. Similarly, authentication system 200 may determine a trust score of '10' for networked lighting switch 242 and a trust score of '20' for in-vehicle management system 244.

[0051] Accordingly, the authentication system 200 can determine different trust scores for different electronic devices 242 - 250. In some embodiments, the authentication system 200 can determine an allocation scheme for the electronic devices 242 - 250 based on the trust scores of the electronic devices 242 - 250. For example, the allocation scheme can provide to allocate portions 210a - 210i in proportion to the trust scores determined for the electronic devices. Accordingly, according to the allocation scheme, the authentication system 200 can allocate one portion of the security key 204 to the networked lighting switch 242 (based on the trust score '10'), two portions of the security key 204 to the vehicle management system 244 (based on the trust score '20'), three portions of the security key 204 to the smart home entertainment system 246 (based on the trust score '30'), one portion of the security key 204 to the networked refrigerator (based on the trust score '10'), and two portions of the security key 204 to the smart watch 250 (based on the trust score '20').

[0052] At step 325, divide portions of the security key are allocated among the electronic devices. For example, the authentication module 232 can send portions 210 of the security key 204 and the allocation scheme to the authentication application 216. Subsequently, the authentication application 216 can allocate portions 210a - 210i to the electronic devices 242 - 250 according to the allocation scheme. For example, the authentication application 216 can send portion 210a to the networked lighting switch 242 via a Zigbee connection and store portion 210a in the allocated memory space of the networked lighting switch 242. Similarly, the authentication application 216 can send portions 210b and 210c to the vehicle management system 244 via a Bluetooth connection and store portions 210b and 210c in the allocated memory space of the vehicle management system 244, the authentication application 216 can send portions 210d, 210e, and 210f to the smart home entertainment system 246 via a wireless infrared communication connection and store portions 210d, 210e, and 210f in the allocated memory space of the smart home entertainment system 246, the authentication application 216 can send portion 210g to the networked refrigerator 248 via a Wi-Fi connection and store portion 210g in the allocated memory space of the networked refrigerator 248, and the authentication application 216 can send portions 210h and 210i to the smart watch 250 via a Bluetooth connection and store portions 210h and 210i in the allocated memory space of the smart watch 250.

[0053] In some embodiments, more than one security key may be generated for user 104 during the registration process. For example, as disclosed herein, different security keys may be generated for the user account of user 104, where each security key corresponds to a different risk level. For example, security key 204 may correspond to a medium risk level. Authentication system 200 may generate security key 206 corresponding to a low risk level and security key 208 corresponding to a high risk level. In some embodiments, different security keys 204-206 require different minimum numbers of parts in order to be reconstructed. For example, since security key 206 corresponds to a low risk level, authentication system 200 may divide security key 206 in such a way that a lower number (lower than the number of parts required to reconstruct security key 204) of parts (e.g., two parts) are required to reconstruct security key 206. Since security key 208 corresponds to a high risk level, authentication system 200 may divide security key 208 in such a way that a higher number (higher than the number of parts required to reconstruct security key 204) of parts (e.g., six parts) are required to reconstruct security key 208. These parts may be sent and distributed among electronic devices 242-250 in the same manner as discussed above with reference to step 325. In some embodiments, the parts of additional keys 206 and 208 may be distributed among electronic devices 242-250 according to the same distribution scheme determined in step 325. Authentication module 232 may also store information related to the parts being distributed to electronic devices 242-250 in database 202 (e.g., the number of parts stored in each of electronic devices 242-250, the identity of the parts being distributed to each of electronic devices 242-250, etc.).

[0054] Once the parts of security keys 204-208 are distributed and stored in electronic devices 242-250, authentication system 200 may authenticate user 104 using the techniques disclosed herein. Figure 4 An authentication system 200 for authenticating a user according to one embodiment of the present disclosure is shown and will be described with reference to Figure 5 which follows Figure 5 A process 500 for authenticating a user to authentication system 200 according to one embodiment of the present disclosure is shown. In some embodiments, process 500 may be performed by authentication system 200. Process 500 begins by (at step 505) receiving a request to authenticate a user accessing a user account. For example, authentication module 132 may receive an authentication request via web server 134, service application 138, and / or the marketplace application 122 of merchant server 120.

[0055] As discussed above, user 104 may use user device 110 to interact with web server 134, service application 138, and / or marketplace application 122 to perform various electronic transactions with merchant server 120 and / or service provider server 130. For some of these electronic transactions, such as login transactions, payment transactions, or customer onboarding transactions, merchant server 120 and / or service provider server 130 may require authentication of user 140 before processing the requested transaction. For example, user 140 may use user interface application 112 of user device 110 to log in to a user account that utilizes service provider server 130. In another example, the user may also use user interface application 112 to submit a request for an electronic payment transaction using a user account that utilizes service provider server 130. In yet another example, user 140 may be browsing a website associated with merchant server 120 and may initiate an online purchase of an item on that website. In some embodiments, merchant server 120 may be affiliated with service provider server 130 and may send an authentication request to service provider server 130 to authenticate user 140 for the online purchase. In various embodiments, many other types of authentication requests are also contemplated - for example, a user may need to authenticate to any Internet-based application (e.g., a web application). For example, a user may also need to authenticate to a security system (e.g., to gain access to a specific area or building), or more generally, a user may need to provide identification / authorization credentials at any time.

[0056] When authentication system 200 receives an authentication request, authentication system 200 may determine a risk level associated with the authentication request. For example, when the authentication request is associated with a login request, authentication system 200 may determine the risk level of the login request based on the location of user device 110 when the login request was issued (based on information obtained from location component 118 of user device 110) and / or the number of failed login attempts for the user account within a predetermined time period (e.g., within the last 24 hours, etc.). In some embodiments, when the user device is located at a location associated with user 104 (e.g., user 104's home, user 104's office, a commuting route between home and office, etc.) and the number of failed login attempts for the user account is low (e.g., 0), authentication system 200 may determine that the risk level of the login request is low. On the other hand, when the number of failed login attempts for the user account within a predetermined time period is high (e.g., 6, 10, etc.), authentication system 200 may determine that the risk level of the login request is high.

[0057] When an authentication request is associated with an electronic payment transaction request, the authentication system 200 can determine the risk level of the payment transaction request based on the amount associated with the electronic payment transaction request. For example, when the amount associated with the payment transaction request exceeds a first predetermined threshold (e.g., $500), the authentication system 200 can determine that the risk level of the payment transaction request is high. When the amount associated with the payment transaction request is below a second predetermined threshold (e.g., $20), the authentication system 200 can determine that the risk level of the payment transaction request is low, and when the amount associated with the payment transaction request is between the first predetermined threshold and the second predetermined threshold, the authentication system 200 can determine that the risk level of the payment transaction request is medium.

[0058] Process 500 then determines (at step 510) a security key for authenticating the user based on the risk level determined for the request. As discussed above, the user account of user 104 can be associated with multiple security keys (such as security keys 204 - 208), each security key associated with a different risk level and requiring a different number of parts to be reconstructed. Thus, based on the risk level determined for the authentication request, the authentication system 200 can select the corresponding security key for the authentication request. For example, the authentication request can be associated with an electronic payment transaction with an amount of $250. Thus, the authentication system 200 can determine that the risk level of the request is medium and select security key 204 corresponding to the medium risk level. As discussed above, security key 204 requires at least four parts to be reconstructed.

[0059] After determining the security key, process 500 (at step 515) selects two or more electronic devices for retrieving parts of the security key. For example, the authentication system 200 can select two or more but not all of the electronic devices 242 - 250 associated with the user account. In some embodiments, the authentication system 200 can select two or more electronic devices based on the location and / or activity associated with user 104. For example, when it is determined (based on information obtained from the location component 118 of user device 110) that the user is at home, the authentication system 200 can select the electronic devices associated with the home profile of the user account (e.g., the connected lighting switch 242, the smart home entertainment system 246, the connected refrigerator 248, etc.). Similarly, when it is determined that the user is at the office, the authentication system 200 can select the electronic devices associated with the office profile of the user account, and when it is determined that the user is commuting (e.g., when it is determined that user 104 is in a vehicle along a regular commuting route), the authentication system can select the electronic devices associated with the commuting profile.

[0060] In some embodiments, the authentication system 200 may select two or more electronic devices based on the risk level of the request and / or the number of parts required to reconstruct the determined security key. In the above example of determining the security key 204 for a request, the authentication system 200 may determine that the security key 204 requires at least four parts to be reconstructed. Thus, the authentication system 200 may select two or more electronic devices such that the total number of parts stored in the two or more selected electronic devices has at least four parts of the security key 204.

[0061] Additionally, the authentication system 200 may also select two or more electronic devices such that at least two of the two or more electronic devices require different network protocols and / or network connectivity to connect to the electronic device. Selecting electronic devices that require different network protocols and / or network connectivity for connection improves the security and effectiveness of the authentication system 200 because it prevents false authentication of the user even when one or more of the selected electronic devices may be accessed and / or taken over by an unauthorized user.

[0062] Reference Figure 4, the authentication system 200 determines that the user 104 is at home based on information obtained from the location component 118 of the user device 110. Accordingly, the authentication system 200 selects two or more electronic devices associated with the home profile for authenticating the user 104. The authentication system 200 may also look up the number of portions stored in each electronic device associated with the home profile to select two or more electronic devices such that the number of portions stored in the selected electronic devices is equal to or greater than a required threshold (e.g., four) for reconstructing the security key 204. In this example, the authentication system 200 selects the networked lighting switch 242, the smart home entertainment system 246, and the networked refrigerator 248 for authenticating the user 104. As shown, based on the information stored in the database 202, the selected electronic devices store a total of five portions of the security key 204 - the networked lighting switch 242 stores one portion of the security key 204, the smart home entertainment system 246 stores three portions of the security key 204, and the networked refrigerator 248 stores one portion of the security key 204, which exceeds the required threshold (four portions) for reconstructing the security key 204. In some embodiments, the authentication system 200 selects two or more electronic devices such that the number of portions stored in the selected devices is more than the required threshold for reconstructing the security key, thereby pre - preparing for the possibility that the user 104 may not be able to connect to each of the selected devices. In this example, since the security key 204 only requires four portions to be reconstructed, the user 104 can still be authenticated when the authentication application 216 fails to connect to the networked lighting switch 242 or the networked refrigerator 248.

[0063] The process 500 then (at step 520) retrieves the portions from the selected electronic devices. For example, the authentication module 232 may instruct the authentication application 216 to establish connections with the networked lighting switch 242, the smart home entertainment system 246, and the networked refrigerator 248 based on their corresponding network protocols and network addresses stored in the database 202. Once the connections with the selected electronic devices are established, the authentication application 216 can retrieve the portions of the security key 204 from the non - transient memory spaces allocated for the authentication system 200 in the selected electronic devices. In this example, the authentication application 216 retrieves portion 210a from the networked lighting switch 242 via a Zigbee connection, retrieves portions 201d, 210e, and 210f from the smart home entertainment system 246 via a wireless infrared communication connection, and retrieves portion 210g from the networked refrigerator via a Wi - Fi connection.

[0064] After retrieving portions from the selected electronic device, process 500 reconstructs the security key (at step 525) based on the retrieved portions. In some embodiments, the authentication application 216 sends the retrieved portions 210a, 210d, 210e, 210f, and 210g to the authentication module 232, which then reconstructs the security key based on the retrieved portions. Process 500 then (at step 530) determines whether the reconstructed security key matches the security key originally assigned to the user account. For example, after receiving portions 210a, 210d, 210e, 210f, and 210g from the authentication application 216, the authentication module 232 can reconstruct the security key 204 based on the retrieved portions and compare the reconstructed security key with the security key 204 originally assigned to the user account to determine whether they match.

[0065] However, to further enhance the security of the authentication system 200 (e.g., to avoid unnecessarily transmitting portions of the security key 204 over the network), the authentication application 216 in some embodiments can reconstruct the security key 204 based on the retrieved portions 210a, 210d, 210e, 210f, and 210g. The authentication application 216 can use the security key 204 to sign (e.g., encrypt) the authentication request and then send the signed authentication request to the authentication module 232. In this way, the authentication system 200 avoids sending any sensitive information over the network 160. As disclosed herein, in some embodiments, the security key 204 can be a private key corresponding to a public / private key pair. The authentication module 232 can save (e.g., store) the corresponding public key in the database 202. When the authentication module 232 receives the signed authentication request, the authentication module 232 can verify the authenticity of the reconstructed security key (e.g., determine whether the reconstructed security key matches the security key 204) by decrypting the signed authentication request using the corresponding public key.

[0066] If it is determined that the keys do not match, process 500 (at step 535) rejects the request. For example, the authentication module 232 can send a signal indicating authentication failure to the application that submitted the authentication request (e.g., the web server 134, the service application 138, and / or the marketplace application 122). In the example shown above, the authentication request is associated with a login request received from the web server 134. Thus, the authentication module 232 can send a signal indicating that authentication has failed to the web server 134. The web server 134 can then reject the login request based on this signal.

[0067] In some embodiments, instead of immediately rejecting a request, the authentication system 200 can allow multiple attempts to authenticate user 104 by selecting different combinations of electronic devices. For example, after failing to authenticate user 104 based on the networked lighting switch 242, the smart home entertainment system 246, and the networked refrigerator 248, the authentication system 200 can attempt to authenticate user 104 by selecting different combinations of electronic devices. In some embodiments, the authentication system 200 can select the networked lighting switch 242, the networked refrigerator 248, and the smart watch 250 to attempt to authenticate user 104 a second time using the same techniques described herein. In some embodiments, the authentication system 200 can set a predetermined number of attempts to authenticate user 104 before rejecting the request. For example, the authentication system 200 can reject the authentication request after failing to authenticate user 104 twice using different combinations of electronic devices.

[0068] On the other hand, if the key match is determined, the process 500 (at step 540) processes the request. For example, the authentication module 232 can send a signal indicating successful authentication to the application that submitted the authentication request (e.g., the web server 134, the service application 138, and / or the marketplace application 122). In the example shown above, the authentication request is associated with an electronic payment transaction request received from the web server 134. Thus, the authentication module 232 can send a signal indicating that user 104 has been authenticated to the web server 134. The web server 134 can then approve and process the electronic payment transaction request based on the signal.

[0069] In some embodiments, the authentication system 200 may periodically re-evaluate the electronic devices 242-250 and update the trust scores and the allocation scheme. For example, after each authentication of a user (e.g., after successfully verifying the reconstructed security key), the authentication system may re-evaluate the selected electronic devices by accessing news about the electronic devices as well as the hardware configuration and / or software configuration of the electronic devices. The authentication system 200 may determine whether a new security software update is available for an electronic device and whether the new security software update has been installed on the electronic device. For example, the authentication system 200 may determine that the latest version of the operating system including updated security patches is available for the networked lighting switch 242. When accessing the networked lighting switch, the authentication application 216 may analyze the software configuration of the networked lighting switch 242 to determine whether the operating system has been updated to the latest version. If the authentication application 216 determines that the operating system of the networked lighting switch 242 has been updated to the latest version, the authentication system 200 may increase the trust score of the networked lighting switch 242 from '10' to '20'.

[0070] The authentication system 200 may also receive news about intrusion events on vehicle management systems similar to the vehicle management system 244. Accordingly, based on the intrusion event, the authentication system 200 may decrease the trust score of the vehicle management system 244 from '20' to '10'. The authentication system 200 may then update the allocation scheme based on the updated trust scores of the electronic devices 242-250 and re-allocate portions of the security keys 204-208 among the electronic devices 242-250. In this example, based on the updated trust scores, the authentication system 200 may move portion 210b from the vehicle management system 244 to the networked lighting switch 242 based on the updated allocation scheme.

[0071] In some embodiments, the security of the authentication system 200 may be further enhanced by adopting a key rotation scheme that changes / updates the security keys associated with the user 104. For example, the authentication system 200 may periodically replace the security keys 204-208 with three different security keys. The authentication system 200 may use the same process as disclosed herein to divide the security keys 204-208 into portions corresponding to three risk levels such that a first new security key corresponding to a low risk level requires two portions to be reconstructed, a second new security key corresponding to a medium risk level requires four portions to be reconstructed, and a third new security key corresponding to a high risk level requires six portions to be reconstructed. The authentication system 200 may then allocate portions of the new security keys among the electronic devices 242-250 according to the allocation scheme.

[0072] Thus, using the techniques disclosed herein, the authentication system 200 provides a secure and convenient way for users to authenticate. Users no longer need to remember long passwords or use hardware devices to scan their biometric data. Instead, according to various embodiments disclosed herein, a user's user device can seamlessly perform authentication of the user by accessing an electronic device associated with the user.

[0073] Figure 6 FIG. 4 is a block diagram of a computer system 600 suitable for implementing one or more embodiments of the present disclosure, including a service provider server 130, a merchant server 120, a user device 110, and electronic devices 242-250. In various implementations, the user device 110 may include a mobile cellular phone suitable for wireless communication, a personal computer (PC), a laptop computer, a wearable computing device, etc., and each of the service provider server 130 and the merchant server 120 may include a network computing device, such as a server. Thus, it should be recognized that the devices 110, 120, 130, and 242-250 can be implemented as the computer system 600 in the following manner.

[0074] The computer system 600 includes a bus 612 or other communication mechanism for transferring information data, signals, and information between the various components of the computer system 600. These components include input / output (I / O) components 604, which process user (i.e., sender, receiver, service provider) actions such as selecting keys from a keypad / keyboard, selecting one or more buttons or links, etc., and send corresponding signals to the bus 612. The I / O components 604 may also include output components, such as a display 602 and a cursor control 608 (such as a keyboard, keypad, mouse, etc.). The display 602 may be configured to present a login page for logging into a user account or a checkout page for purchasing items from a merchant. An optional audio input / output component 606 may also be included to allow the user to use voice input information by converting audio signals. The audio I / O component 606 may allow the user to hear audio. A transceiver or network interface 620 sends and receives signals between the computer system 600 and other devices (such as another user device, a merchant server, or a service provider server) via a network 622. In one embodiment, the transmission is wireless, although other transmission media and methods may also be suitable. A processor 614 (which may be a microcontroller, a digital signal processor (DSP), or other processing component) processes these various signals, such as for display on the computer system 600 or transmission to other devices via a communication link 624. The processor 614 may also control the transmission of information such as cookies or IP addresses to other devices.

[0075] The components of computer system 600 also include system memory component 610 (e.g., RAM), static storage component 616 (e.g., ROM), and / or disk drive 618 (e.g., solid state drive, hard disk). Computer system 600 performs specific operations through processor 614 and other components by executing one or more sequences of instructions contained in system memory component 610. For example, processor 614 may perform the risk analysis functions described herein according to processes 300 and 500.

[0076] The logic can be encoded in a computer-readable medium, which can refer to any medium that participates in providing instructions to processor 614 for execution. Such a medium can take many forms, including but not limited to non-volatile media, volatile media, and transmission media. In various implementations, non-volatile media includes optical or magnetic disks, volatile media includes dynamic memory such as system memory component 610, and transmission media includes coaxial cables, copper wire, and fiber optics, including the wires that make up bus 612. In one embodiment, the logic is encoded in a non-transitory computer-readable medium. In one example, the transmission media can take the form of acoustic or light waves, such as those generated during radio wave, optical, and infrared data communications.

[0077] Some common forms of computer-readable media include, for example: floppy disks, flexible disks, hard disks, magnetic tape, any other magnetic media, CD-ROM, any other optical media, punched cards, paper tape, any other physical media with hole patterns, RAM, PROM, EPROM, FLASH-EPROM, any other memory chip or cartridge, or any other medium from which a computer is adapted to read.

[0078] In various embodiments of the present disclosure, the sequences of instructions for practicing the present disclosure can be executed by computer system 600. In various other embodiments of the present disclosure, multiple computer systems 600 coupled to a network (e.g., such as LAN, WLAN, PTSN, and / or various other wired or wireless networks, including telecommunications, mobile, and cellular telephone networks) via communication link 624 can execute sequences of instructions to practice the present disclosure in cooperation with each other.

[0079] In applicable cases, various embodiments provided by the present disclosure can be implemented using hardware, software, or a combination of hardware and software. Moreover, in applicable cases, without departing from the spirit of the present disclosure, the various hardware components and / or software components described herein can be combined into composite components including software, hardware, and / or both. In applicable cases, without departing from the scope of the present disclosure, the various hardware components and / or software components described herein can be divided into sub-components including software, hardware, or both. Additionally, in applicable cases, it is contemplated that software components can be implemented as hardware components and vice versa.

[0080] Software according to the present disclosure (such as program code and / or data) can be stored on one or more computer-readable media. It is also contemplated that one or more general-purpose or special-purpose computers and / or computer systems using networking and / or other means can be used to implement the software identified herein. In applicable cases, the order of the various steps described herein can be changed, combined into composite steps, and / or divided into sub-steps to provide the features described herein.

[0081] The various features and steps described herein can be implemented as systems that include one or more memories storing the various information described herein and one or more processors coupled to the one or more memories and a network, wherein the one or more processors are operable to execute the steps as described herein; implemented as a non-transitory machine-readable medium including a plurality of machine-readable instructions that, when executed by one or more processors, are adapted to cause the one or more processors to execute a method including the steps described herein, and methods performed by one or more devices such as hardware processors, user devices, servers, and other devices described herein.

Claims

1. A system for authenticating a user, comprising: A non-transitory memory; And One or more hardware processors coupled to the non-transitory memory and configured to read instructions from the non-transitory memory to cause the system to perform operations including the following: Receiving an authentication request for authenticating a user accessing a user account via a user device, wherein the user account is associated with a security key that is divided into multiple parts distributed among multiple electronic devices associated with the user, and wherein the multiple electronic devices include multiple networked electronic devices accessible via the user device; Determining a specific profile from multiple profiles associated with the user account based on the location of the user device, wherein the specific profile designates a first subset of the multiple electronic devices; Selecting two or more electronic devices from the first subset of the multiple electronic devices; Causing the user device to electronically connect to the two or more electronic devices; Receiving from the two or more electronic devices: (i) the parts of the security key assigned to the two or more electronic devices, (ii) updated device configurations associated with the two or more electronic devices; Reconstructing the security key based on the parts of the security key received from the two or more electronic devices; Authenticating the user accessing the user account based on the reconstructed security key; and Reassigning multiple parts of the security key to at least a second subset of the multiple electronic devices based on the updated device configurations associated with the two or more electronic devices.

2. The system according to claim 1, wherein The operations further include: Determining a risk level for authenticating the user at least in part based on the authentication request; and Selecting the security key from multiple security keys based on the determined risk level, wherein the security key requires at least a first quantity of parts corresponding to the determined risk level to be reconstructed.

3. The system according to claim 2, wherein The authentication request corresponds to a payment transaction request associated with an amount, and wherein the risk level is further determined based on the amount relative to a predetermined threshold amount.

4. The system according to claim 2, wherein The authentication request corresponds to a purchase transaction request associated with a merchant, and wherein the risk level is further determined based on the merchant type associated with the merchant.

5. The system according to claim 2, wherein, The risk level is further determined based on the location of the user device.

6. The system according to claim 1, wherein Each of the multiple electronic devices includes a quantity of parts that is insufficient to reconstruct the security key, and the operations further include: Determining a required quantity of parts of the security key for reconstructing the security key; Determining that the two or more electronic devices include the required quantity of parts of the security key.

7. The system according to claim 1, wherein, The two or more electronic devices are randomly selected from the first subset of the multiple electronic devices.

8. The system according to claim 1, wherein, Causing the user device to electronically connect to the two or more electronic devices includes: Establish a first type of connection between the user device and a first electronic device from the two or more electronic devices; and Establish a second type of connection between the user device and a second electronic device from the two or more electronic devices, wherein the first type of connection is different from the second type of connection, and wherein the plurality of portions are reallocated via the first type of connection and the second type of connection.

9. The system according to claim 1, wherein, The two or more electronic devices are fewer in number than the plurality of portions.

10. A method for authenticating a user, comprising:[[]] Receiving, by one or more hardware processors, an authentication request from a user device for authenticating a user accessing a user account; Determining, by the one or more hardware processors, a risk level associated with the request; Selecting, by the one or more hardware processors, a security key from a plurality of security keys associated with the user account based on the risk level of the authentication request, wherein the security key is divided into a plurality of portions distributed among a plurality of electronic devices associated with the user, wherein the security key requires at least a requisite number of portions from the plurality of portions to be reconstructed, and wherein the plurality of electronic devices includes a plurality of networked electronic devices accessible via the user device; Determining, by the one or more hardware processors, a specific profile from a plurality of profiles associated with the user account based on the location of the user device, wherein the specific profile designates a first subset of the plurality of electronic devices; Selecting, by the one or more hardware processors, two or more electronic devices from the first subset of the plurality of electronic devices for authenticating the user; Causing, by the one or more hardware processors, the user device to electronically connect to the two or more electronic devices; Retrieving, by the one or more hardware processors: (i) portions of the security key assigned to the two or more electronic devices, and (ii) updated device configurations associated with the two or more electronic devices; Reconstructing, by the one or more hardware processors, the security key based on the retrieved portions of the security key; Authenticating, by the one or more hardware processors, the user accessing the user account based on the reconstructed security key; and Reallocating, by the one or more hardware processors, a plurality of portions of the security key to at least a second subset of the plurality of electronic devices based on the updated device configurations associated with the two or more electronic devices.

11. The method according to claim 10, wherein, The two or more electronic devices include at least one of a vehicle, a smart appliance, or a wearable device.

12. The method according to claim 10, wherein Retrieving the portions of the security key from the two or more electronic devices includes:[[]] Retrieving a first number of portions from a first electronic device among the two or more electronic devices; and Retrieving a second number of portions from a second electronic device among the two or more electronic devices, wherein the first number is different from the second number.

13. The method according to claim 12, wherein, The first number is more than one.

14. The method according to claim 10, wherein, The first part of the security key is retrieved from a first electronic device of the two or more electronic devices, and wherein redistributing the plurality of parts of the security key includes: Based on the updated device configuration, removing the first part of the security key from the first electronic device.

15. The method according to claim 10, wherein, The first part of the security key is retrieved from a first electronic device of the two or more electronic devices, and wherein redistributing the plurality of parts of the security key includes: Based on the updated device configuration, storing a second part of the security key in the first electronic device in addition to the first part.

16. The method according to claim 10, further comprising: Determine that the two or more electronic devices include at least the required number of parts.

17. The method of claim 10, further comprising: Generating the security key for the user account; Dividing the security key into the plurality of parts; Determining a trust score for each of the plurality of electronic devices; and and Allocating parts of the security key among the plurality of electronic devices according to the trust scores.

18. A non-transitory machine-readable medium having machine-readable instructions stored thereon that are executable to cause a machine to perform operations including: Receive an authentication request for authenticating a user accessing a user account from a user device, wherein, The authentication request is associated with a security key that is divided into a plurality of parts distributed among a plurality of electronic devices associated with the user, wherein the plurality of electronic devices include a plurality of networked electronic devices accessible via the user device; Based on the location of the user device, determining a specific configuration from a plurality of profiles associated with the user account, the specific configuration specifying a first subset of the plurality of electronic devices; Selecting two or more electronic devices from the first subset of the plurality of electronic devices for authenticating the user; Causing the user device to electronically connect to the two or more electronic devices; Receiving from the two or more electronic devices: (i) the parts of the security key assigned to the two or more electronic devices, and (ii) an updated device configuration associated with the two or more electronic devices; Reconstructing the security key based on the received parts of the security key, wherein the number of the parts of the security key received from the two or more electronic devices is less than the plurality of parts; Authenticating the user accessing the user account based on the reconstructed security key; and Based on the updated device configuration associated with the two or more electronic devices, redistributing the plurality of parts of the security key to at least a second subset of the plurality of electronic devices.

19. The non-transitory machine-readable medium according to claim 18, wherein, The operations further include: Determining a risk level associated with the authentication request; and Selecting the security key from a plurality of security keys based on the determined risk level, wherein the security key requires at least a required number of parts corresponding to the determined risk level to be reconstructed.

20. The non-transitory machine-readable medium according to claim 19, wherein, The operations further include: determining that the two or more electronic devices include the required number of parts of the security key.

Citation Information

Patent Citations

  • Systems and methods for securing data in motion

    US20160379005A1