Determine the session duration used for device authentication

By analyzing the environmental characteristics and state changes of user devices, the session duration is dynamically adjusted, solving the problem of frequent or insecure authentication in cloud computing environments and achieving a more efficient and secure authentication mechanism.

CN116368774BActive Publication Date: 2025-10-31CISCO TECHNOLOGY INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180072659.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-08-27
Filing Date
2021-08-23
Publication Date
2025-10-31
Estimated Expiration
2041-08-23

AI Technical Summary

Technical Problem

In cloud computing environments, existing authentication mechanisms struggle to effectively manage the session duration of user devices, leading to frequent authentication issues or insufficient security.

Method used

By analyzing the environmental characteristics and state changes of user devices through authentication entities, the session duration is dynamically adjusted, machine learning models are used to identify abnormal situations, and multi-factor authentication is combined to improve security and efficiency.

Benefits of technology

The authentication frequency of user devices has been optimized, reducing the waste of computing resources, improving security, and reducing the risk of unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116368774B_ABST
    Figure CN116368774B_ABST
Patent Text Reader

Abstract

This disclosure describes techniques for authenticating a user device for a session. For example, an authentication entity may use single sign-on authentication and / or multi-factor authentication to authenticate the user device. The authentication entity can then determine the duration for which the user device is authenticated for a session. For example, the authentication entity may receive information representing the state of the user device's environment. The authentication entity can then use this information to identify one or more transitions in the environment between the current session and previous sessions. Using these one or more transitions, the authentication entity can determine the duration of the session by increasing or decreasing the previous duration associated with the previous session.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-references to related applications

[0002] This application claims priority to U.S. Patent Application No. 17 / 004,368, filed August 27, 2020, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This disclosure generally relates to an authentication entity for authenticating one or more devices associated with a cloud computing service. Background Technology

[0004] Cloud computing provides businesses with cost-effective access to virtually unlimited computing power and storage, rather than requiring them to purchase and / or maintain physical computing resources. Consequently, many businesses offer services executed in distributed and / or remote locations. Because many services involve the use of users' private information, such as personal and / or financial information, security is paramount for many services delivered via cloud computing. However, the distributed nature of cloud computing increases the complexity of security issues. Therefore, the increasing use of cloud computing by businesses necessitates improved customer protection methods. Attached Figure Description

[0005] The following detailed description refers to the accompanying drawings. In the drawings, the leftmost number(s) of the reference numerals indicates the drawing in which the reference numeral first appears. The same reference numerals are used in different drawings to indicate similar or identical items. In some cases, parentheses are used after the reference numerals to distinguish similar elements. Using reference numerals without the associated parentheses is generally acceptable for the elements. The systems depicted in the drawings are not drawn to scale, and the components in the drawings may not be drawn to scale with each other.

[0006] Figure 1 A component diagram of an example environment in which the concept of cloud authentication can be adopted according to the concepts of this disclosure is shown.

[0007] Figure 2A-2B An example is shown of updating the duration of a session using information associated with the user device’s environment, based on the concepts of this disclosure.

[0008] Figure 3 A flowchart is shown for a first example method for determining the duration associated with an authenticated user device during a session.

[0009] Figure 4 A flowchart is shown for a second example method for determining the duration associated with an authenticated user device during a session.

[0010] Figure 5A flowchart is shown for a third example method for determining the duration associated with an authenticated user device during a session.

[0011] Figure 6 A computing system diagram illustrating the configuration of a data center that can be used to implement various aspects of the techniques disclosed herein is shown.

[0012] Figure 7 This is a computer architecture diagram illustrating an illustrative computer hardware architecture for implementing a server computing device that can be used to implement various aspects of the various techniques proposed herein. Detailed Implementation

[0013] Overview

[0014] Various aspects of the invention are set forth in the independent claims, and preferred features are set forth in the dependent claims. A feature of one aspect may be applied alone to any aspect or in combination with other aspects.

[0015] This disclosure describes at least in part one or more devices configured to: determine a first duration associated with an authenticated user device during a first session. The one or more devices may then receive credentials associated with a user account and authenticate the user device for a second session based at least in part on those credentials. Based on the authentication of the user device, the one or more devices may receive information associated with the user device's environment and determine a second duration associated with the authenticated user device during the second session based at least in part on the first duration and that information. Furthermore, the one or more devices may generate data representing at least the second duration and send that data to the user device.

[0016] This disclosure also describes, at least in part, a method comprising: storing first information associated with the environment of a user device during a first session. The method may then include: receiving credentials associated with a user account, and authenticating the user device for a second session based at least in part on the credentials. Based at least in part on the authentication of the user device, the method may include: receiving second information associated with the environment of the user device for the second session, and determining, at least in part on the first and second information, the duration of authentication associated with the user device during the second session. Furthermore, the method may include: generating data representing at least the duration, and sending the data to the user device.

[0017] This disclosure also describes, at least in part, a method comprising: determining a first duration associated with an authenticated user device during a first session. The method may further comprise: receiving credentials associated with a user account, and authenticating the user device for a second session based at least in part on the credentials. Based on the authentication of the user device, the method may include: receiving information associated with the user device's environment, and determining a second duration associated with the authenticated user device during a second session based at least in part on the first duration and the information. Furthermore, the method may include: generating data representing at least the second duration, and sending the data to the user device.

[0018] Example Implementation

[0019] This disclosure describes, at least in part, techniques that can be implemented by an authentication entity coupled to one or more user devices and one or more online services. For example, the authentication entity may provide an interface through which a user's user device can be authenticated to access one or more online services. The authentication entity can help the online services trust the user's user device to allow access to the online service(s) using credentials associated with the user. For example, the authentication entity may provide the user with Single Sign-On (SOO) authentication, where the user's user device is authenticated using at least credentials. In some cases, the authentication entity may also use multi-factor authentication when authenticating the user device for one or more online services. Once the authentication entity has authenticated the user device, it can provide the user with data, such as a token, that the user device can use to access each of the online services(s) during a session. The session may be associated with the duration for which the token is valid for accessing one or more online services. Once the token's duration expires, the authentication entity may require the user device to be re-authenticated using at least credentials (and / or multi-factor authentication).

[0020] For more details, a user can attempt to log in to an online service using their user device. To log in, the user device can receive input representing credentials (e.g., username, password, etc.) and send those credentials to the online service. The online service can then communicate with an authentication entity to determine if the user device can be trusted. In some cases, the authentication entity uses the credentials to authenticate the user device as a trusted device for the online service. For example, the authentication entity can match the credentials with additional credentials stored in association with the user's account. Additionally, or alternatively, in some cases, the authentication entity performs multi-factor authentication to authenticate the user device as a trusted device for the online service. For example, the authentication entity can generate an authentication request and send it to the user (e.g., via email, message, app, etc.). The authentication request can include, but is not limited to, codes, questions, passwords, push notifications, and / or any other factors that can be used to authenticate the user device. The authentication entity can then receive a response to the authentication request from the user device and / or another device and use that response to authenticate the user device.

[0021] After authenticating a user device, the authentication entity can generate authentication data (e.g., tokens, cookies, etc.) that the user device can use to access online services and one or more other online services during a session. The authentication data may include at least the duration during which it is valid for accessing one or more online services during the session. After generating the authentication data, the authentication entity can send it to the user device. The user device can then use the authentication data to access one or more online services during the session. For example, the user device can send authentication data to one or more online services during the session, where the online services use the authentication data to trust the user device. After trusting the user device, the user device can use the resources provided by one or more online services. However, when the duration expires, the authentication data may no longer be valid for the authenticated user device, and therefore, the authentication entity may need to re-authenticate the user device.

[0022] The duration for which authentication data is valid can be important for one or more reasons. In the first example, if the duration is too short, the authentication entity may require multiple re-authentications of the user's device over a period of time, such as an hour, a day, a week, etc., while the user is accessing one or more online services. This can cause problems, such as burdening the user and requiring computational resources to continuously authenticate the user's device. In the second example, if the duration is too long, the authentication entity may not require re-authentication of the user's device during the extended period. This can also cause problems, such as authentication data being leaked during the session (e.g., retrieved by an unauthorized device during the session) and used to gain unauthorized access to one or more of the user's online services. Therefore, the authentication entity described herein may use one or more techniques to determine the duration of a session.

[0023] For example, if this is the first time a user device is being authenticated for a session, the authentication entity can use the set duration. The set duration can be, but is not limited to, one hour, twelve hours, one day, one week, and / or any other time period. The authentication entity can then update the duration each time it authenticates the user device for a new session. In some cases, the authentication entity updates the duration by increasing or decreasing the previous duration of a previous session. Additionally, or alternatively, in some cases, the authentication entity updates the duration by reusing the set duration. In either case, when updating the duration for the user device, the authentication entity can use information associated with the user device's environment.

[0024] For example, components (e.g., applications) executing on a user device can analyze the environment to determine one or more characteristics associated with the state of the environment. As described herein, these characteristics may include, but are not limited to, a unique device identifier associated with the user device, hardware associated with the user device (e.g., hardware installed on the user device), software installed on the user device, one or more applications active on the user device, central processing unit (CPU) usage associated with the user device, memory usage associated with the user device, Internet Protocol (IP) address associated with the user device, power consumption associated with the user device, type of network connection associated with the user device, one or more other devices with which the user device is communicating (e.g., via Bluetooth, WiFi, etc.), sensor data representing the user of the user device, and / or the like. In some cases, the information sent to the authentication entity represents this characteristic(s). Additionally, or alternatively, in some cases, the information sent to the authentication entity represents one or more transitions associated with the environment.

[0025] For example, a component can compare one or more characteristics associated with the environment with one or more previous characteristics associated with the environment. In some cases, the component determines previous characteristics during one or more previous sessions (in which the user equipment has been authenticated). Based on this comparison, when the authenticating entity authenticates the user equipment, the component can identify one or more transitions between the current state of the environment and the state of the environment during one or more previous sessions. As described herein, one or more transitions may include, but are not limited to, changes in a unique device identifier, changes in hardware associated with the user equipment, changes in software installed on the user equipment, changes in one or more applications active on the user equipment, changes in CPU usage associated with the user equipment, changes in memory usage associated with the user equipment, changes in IP address associated with the user equipment, changes in power consumption associated with the user equipment (e.g., whether the user equipment continuously receives power or whether the user equipment stops receiving power for a period of time), changes in the type of network connection associated with the user equipment, changes in the user of the user equipment (such as those determined using sensor data), and / or any other state change.

[0026] When the information represents one or more environment-related characteristics, the authentication entity can perform a process similar to that of a component to identify one or more transitions. For example, the authentication entity can store additional information representing one or more previous characteristics associated with the environment. In some cases, the authentication entity stores this information whenever it receives such information from the user device and / or whenever it authenticates the user device. The authentication entity can then compare the environment-related characteristics with one or more previous characteristics to identify one or more transitions between the current state of the environment and the state of the environment during one or more previous sessions when authenticating the user device.

[0027] In either of the above examples, the authentication entity may use one or more transitions to determine the duration. For the first example, if the transition(s) indicate that the current state of the environment is similar to one or more previous states of the environment, the authentication entity may determine the duration by increasing the previous duration associated with the previous session. In some cases, the greater the similarity between the current state of the environment and one or more previous states of the environment, the larger the increase the authentication entity uses when determining the duration. For the second example, if the transition(s) indicate that the current state of the environment is different from one or more previous states of the environment, the authentication entity may determine the duration by decreasing the previous duration associated with the previous session. In some cases, the greater the difference between the current state of the environment and one or more previous states of the environment, the larger the decrease the authentication entity uses when determining the duration.

[0028] In some cases, when there is little difference between the compared characteristics(s), the authentication entity can determine that the transition(s) indicate that the current state of the environment is similar to one or more previous states of the environment(s). For the first example, if the transition(s) indicate only small changes in CPU usage (e.g., 1%, 5%, 10%, etc.) and / or small changes in memory usage (e.g., 10%, 5%, etc.), the authentication entity can determine that the current state of the environment is similar to one or more previous states of the environment(s). For the second example, if the transition(s) indicate only the activation of a new software application on the user device, the authentication entity can determine that the current state of the environment is still similar to one or more previous states of the environment(s). However, the authentication entity can determine that the similarity in the first example is greater than the similarity in the second example, and therefore, the authentication entity can increase the duration in the first example by a larger amount than in the second example.

[0029] In certain situations, when there are significant differences between the compared characteristics(s), the authentication entity can determine that the transition(s) indicate that the current state of the environment differs from one or more previous states of the environment. For a first example, if the transition(s) indicate a large change in CPU usage (e.g., 75%, 80%, 90%, etc.) and / or a large change in memory usage (e.g., 75%, 80%, 90%, etc.), the authentication entity can determine that the current state of the environment differs from one or more previous states of the environment. For a second example, if the transition(s) indicate that the user equipment is using a new IP address and / or has a new unique device identifier, the authentication entity can again determine that the current state of the environment differs from one or more previous states of the environment. However, the authentication entity can determine that the difference in the second example is greater than the difference in the first example, and therefore, the authentication entity will reduce the duration in the second example by a larger amount than in the first example.

[0030] In some cases, the authentication entity can analyze this information to identify "triggering events" relevant to the user device's environment. As described herein, triggering events may include, but are not limited to, changes in the user of the user device (determined using image data, biometric data, etc.), malicious hardware / software (e.g., malware) identified on the user device, changes in the unique device identifier, changes in the IP address, insecure network connections (e.g., the user device connecting to a public and insecure network), etc. In some cases, when the authentication entity identifies a triggering event, it may require the user device to be re-authenticated (using credentials and / or by performing multi-factor authentication). Additionally, or alternatively, in some cases, when the authentication entity identifies a triggering event, it may determine the duration to a set duration and / or determine the duration by reducing the previous duration.

[0031] In the examples above, and in some cases, the authentication entity may receive this information from the user device whenever it authenticates the user device for one or more online services. Additionally, or alternatively, in some cases, the authentication entity may receive this information at different times. For example, the authentication entity may receive the information at given time intervals during a session, continuously during a session, whenever there is an inactivity period between the user device and one or more online services, and / or at any other time. Additionally, or alternatively, in some cases, the authentication entity may receive the information based on a request sent to the user device for that information.

[0032] For example, after authenticating a user device for a session, the authentication entity can determine the duration associated with the session (e.g., 24 hours). However, during the session (e.g., 12 hours after the session began), the authentication entity can re-authenticate the user device (e.g., using the process described herein). Based on this authentication, the authentication entity can determine whether to update the duration, such as reducing the duration from the time of the original authentication (e.g., reducing it to 18 hours) or increasing the duration (e.g., increasing it to 48 hours). This way, when determining when to re-authenticate the user device again, the new duration can be used for authentication. For example, if the authentication entity reduces the duration, it can determine to re-authenticate the user device 18 hours after the original authentication. Furthermore, if the authentication entity increases the duration, it can determine to re-authenticate the user device 24 hours after the original authentication.

[0033] For another example, an authentication entity may re-authenticate the user equipment for a first session that includes a first duration (e.g., 24 hours). However, at some point during the first session (e.g., 12 hours after entering the first session), the authentication entity may determine a second duration for the second session. If the second duration (e.g., 10 hours) is less than the time before entering the first session (e.g., 12 hours after entering the first session), the authentication entity may determine to re-authenticate the user equipment immediately. However, if the second duration (e.g., 48 hours) is greater than the time before entering the first duration (e.g., 12 hours after entering the first session), the authentication entity may determine not to re-authenticate the user equipment during the second duration (e.g., 48 hours after the start of the first duration).

[0034] Furthermore, in the above example, components executing on the user device and / or authentication entity can use one or more machine learning models to identify one or more transitions associated with the current state of the environment. For example, one or more machine learning models can be configured to analyze one or more characteristics associated with the user device's environment, such as whenever a component identifies one or more characteristics. Based on this analysis, the machine learning models identify (e.g., learn) one or more characteristics that remain substantially constant. For example, the machine learning models can identify that the user device typically uses the same IP address, typically uses the same unique device identifier, includes CPU usage falling within a given range, includes applications typically active on the user device, and so on. The component and / or authentication entity can then compare the new characteristics with the learned characteristics to identify one or more transitions. When one or more transitions are identified using one or more machine learning models, the transition may correspond to an "anomaly" of the user device. The authentication entity can then use these anomalies when determining their duration.

[0035] For example, if the authentication entity determines that the anomaly is minor, it can determine the duration by increasing the previous duration associated with the user equipment. In some cases, the authentication entity can use a similar process as described above regarding state changes to determine that the anomaly is minor. For example, the authentication entity can determine that the anomaly is minor based on an anomaly indicating that the current state of the environment is similar to one or more previous states of the environment. For example, if the authentication entity determines that the anomaly is significant, it can determine the duration by decreasing the previous duration associated with the user equipment. In some cases, the authentication entity can use a similar process as described above regarding state changes to determine that the anomaly is significant. For example, the authentication entity can determine that the anomaly is significant based on an anomaly indicating that the current state of the environment differs from one or more previous states of the environment.

[0036] While the examples described herein may refer to user devices and / or authentication entities as multi-party cloud authentication systems participating in a cloud network environment, these technologies can generally be applied to any device or role, including enterprise human resources scenarios. Furthermore, these technologies are generally applicable to any network of devices managed by any entity supplying virtual resources. In some instances, these technologies can be implemented by software-defined networking (SDN), and in others, a variety of devices can be used within the system to implement the technologies described herein. The user devices implementing these technologies are implementation-dependent, and the described technologies are not limited to any particular architecture or implementation.

[0037] The techniques described in this paper offer various improvements and efficiencies in network communication. For example, the techniques described in this paper can reduce computing resource usage, storage consumption, data loss, latency, and can reduce other problems experienced in the network due to lack of network resources, overuse of network resources, timing issues in network communication, and / or incorrect data routing problems. By improving network communication on the network, the overall performance of servers and virtual resources can be improved.

[0038] Certain implementations and embodiments of this disclosure will now be described more fully with reference to the accompanying drawings, in which various aspects are illustrated. However, these aspects may be implemented in many different forms and should not be construed as limited to the implementations set forth herein. This disclosure includes variations of the embodiments as described herein. The same reference numerals refer to the same elements throughout.

[0039] Figure 1 An example environment 100 according to the cloud authentication concept of this disclosure is shown. Example environment 100 may include a cloud computing network 102 (e.g., a network), one or more user devices 104, one or more server devices 106, and / or one or more authentication devices 108 (e.g., authentication entities). Parentheses are used after reference numerals to distinguish similar elements. Reference numerals without associated parentheses are generic for the elements. For example, Figure 1 Two instances of user equipment 104 are included: user equipment 104(1) which can represent a desktop computer and user equipment 104(2) which can represent a mobile phone. In some scenarios, multiple user equipment 104 may be associated with a single user. One or more server devices 106 may provide remote online services that the user wishes to participate in, at least through user equipment 104(1). In addition, one or more authentication devices 108 may perform one or more authentication entity functions to authenticate user equipment 104(21) against one or more server devices 106.

[0040] In some examples, environment 100 includes a data center or cloud computing network, comprising servers and other network components (e.g., routers, switches, etc.) stored across multiple data centers spanning geographical regions. In these cases, the cloud computing environment can be a distributed network through which users (typically customers) can interact via user devices to manage or otherwise interact with the services provided by the cloud computing network. The cloud computing network can provide on-demand availability of computing system resources (e.g., data repositories, computing power (e.g., CPUs, GPUs, etc.), networks, databases, etc.) without requiring direct, active management by the user. In some examples, the cloud computing network can be managed and maintained by a service provider, freeing users from investing in and maintaining computing infrastructure for their computing resource needs. Generally, users can be provided with access to or allocation of usage of a portion of computing resources within the cloud computing network. The cloud computing network can be scaled based on individual user needs, such as by adding or removing resources. The portions of the cloud computing network can be allocated using hardware virtualization, allowing users to configure and manage the portions of the cloud computing network (e.g., security configuration, load balancing configuration, etc.). However, the cloud computing network does not necessarily have to be managed by a service provider and can be managed by any entity, including the users themselves running applications or services.

[0041] One or more user devices 104, one or more server devices 106, and / or one or more authentication devices 108 can be communicatively coupled to each other and / or to various other devices via cloud computing network 102. Within example environment 100, user devices 104, server devices 106, authentication devices 108, and / or other devices can exchange communications (e.g., packets) via one or more network connections to cloud computing network 102, as indicated by double arrows 110. For example, network connection 110 can be a Transmission Control Protocol (TCP) network connection or any network connection that enables these devices to exchange packets with other devices via cloud computing network 102 (e.g., an Information Center Network (ICN)). Network connection 110 represents, for example, a data path between user device 104 and one or more authentication devices 108. For example, user device 104 can be a computer, laptop computer, mobile device, tablet computer, etc., while one or more server devices 106 and / or one or more authentication devices 108 can be configured to provide data and / or network services to user device 104. One or more server devices 106 and / or one or more authentication devices 108 may or may not be the producer, generation point, and / or source of data. For example, data may originate from other locations that one or more server devices 106 and / or one or more authentication devices 108 can provide to user device 104. Additionally or alternatively, data may be transmitted via other network devices (e.g., routers, switches) along the path from one or more server devices 106 and / or one or more authentication devices 108 to user device 104. It should be understood that the term "network connection" can also be referred to as "network path." The use of a cloud computing network in this example is not intended to be limiting. Other types of networks are envisioned based on the concept of multi-party cloud authentication.

[0042] In “Step 1”, user device 104(1) may communicate with one or more server devices 106. Communication at Step 1 may include user device 104(1) attempting to log in to an account (e.g., an email account, a messaging account, etc.) associated with one or more server devices 106. For example, user device 104(1) may receive one or more inputs representing credentials 112 associated with the account. Credentials 112 may include, but are not limited to, a username and password associated with the account. User device 104(1) may then send credentials 112 to server device 106. In some cases, based on the received credentials 112, one or more server devices 106 may authenticate user device 104(1). For example, one or more server devices 106 may match credentials 112 with additional credentials stored associated with the account. Additionally or alternatively, in some cases, one or more server devices 106 may determine to authenticate user device 104(1) as a trusted device using one or more authentication devices 108.

[0043] For example, in “Step 2”, server device 106 may communicate with authentication device 108. The communication in Step 2 may include server device 106 sending credential 112 and / or other data identifying user device 104(1) to authentication device 108. In some cases, authentication device 108 may use credential 112 to authenticate user device 104(1), similar to server device 106 described above. Additionally or alternatively, in some cases, authentication device 108 may determine to use multi-factor authentication to authenticate user device 104(1). In this case, although in Figure 1 Not shown in the example, but one or more authentication devices 108 may communicate with user device 104(1) to select how the authentication devices 108 provide the authentication request 114 associated with multi-factor authentication. For example, the authentication devices 108 may allow the user to choose email, text message, push notification, etc. to send the authentication request 114.

[0044] In “Step 3”, one or more authentication devices 108 may communicate with user device 104 (2). Communication at Step 3 may include providing an authentication request 114 to user device 104 (2) via a selected communication type. User device 104 (2) may then receive input representing a response 116 to authentication request 114. For a first example, if authentication request 114 includes a code sent to the user via email, response 116 may include that code sent via email. For a second example, if authentication request 114 includes a question for the user, response 116 may include an answer to that question. Furthermore, for a third example, if authentication request 114 includes a push notification, response 116 may include the user selecting an interface element associated with the push notification, such as a button. In either example, user device 104 (2) may then send response 116 back to one or more authentication devices 108.

[0045] Then, one or more authentication devices 108 can use the response 116 to authenticate user device 104 (1) through multi-factor authentication. For example, one or more authentication devices 108 can determine that the response 116 to authentication request 114 is correct. One or more authentication devices 108 can then generate authentication data 118, such as tokens, cookies, etc., which user device 104 (1) can use to access one or more services provided by one or more server devices 106. Figure 1 As shown in the example, authentication data 118 includes at least a duration 120 during which authentication data 118 is valid. For example, during the duration 120 of authentication data 118, user device 104(1) can use authentication data 118 to access resources provided by one or more server devices 106. For example, one or more server devices 106 can receive authentication data 118 from user device 104(1) and use authentication data 118 to determine that user device 104(1) is trustworthy. However, when the duration 120 expires, user device 104(1) may no longer be able to use authentication data 118 to access resources provided by one or more server devices 106. Instead, user device 104(1) may be required to re-authenticate with authentication device 108.

[0046] To determine the duration, and in “step 4”, one or more authentication devices 108 may communicate with user equipment 104(1). The communication at step 4 may include one or more authentication devices 108 requesting information 122 from user equipment 104(1), which the authentication devices 108 use to determine the duration 120. Based on this request, state component 124 (e.g., an application running on user equipment 104(1)) may analyze the environment to determine one or more characteristics 126 associated with the state of the environment. As described herein, one or more characteristics 126 may include, but are not limited to, a unique device identifier 128 associated with user equipment 104(1), hardware 130 associated with user equipment 104(1) (e.g., hardware 130 installed on user equipment 104(1)), software 132 installed on user equipment 104(1), one or more applications 134 active on user equipment 104(1), central processing unit (CPU) usage associated with user equipment 104(1), memory 136 usage associated with user equipment 104(1), IP address associated with user equipment 104(1), power consumption associated with user equipment 104(1), type of network connection associated with user equipment 104(1), one or more other devices with which user equipment 104(1) is communicating (e.g., via Bluetooth, WiFi, etc.), sensor data 138 representing the user of user equipment 104, etc. In some cases, information 122 may represent one or more characteristics 126 associated with the environment.

[0047] Furthermore, or alternatively, in some cases, the state component 124 may compare one or more characteristics 126 associated with the current state of the environment with one or more previous characteristics 126 associated with one or more previous states of the environment. In some cases, the state component 124 determines one or more previous characteristics during one or more previous sessions (for which user equipment 104(1) was authenticated). Based on this comparison, the state component 124 may identify one or more transitions 140 between the current state of the environment and the state of the environment during the previous session when the user equipment 104(1) was authenticated by one or more authentication devices 108, as described above. In this case, information 122 may represent one or more transitions 140.

[0048] When information 122 represents one or more characteristics 126 associated with the environment, one or more authentication devices 108 may perform a process similar to that of state component 124 to identify one or more transitions 140. For example, one or more authentication devices 108 may store additional information 122 representing one or more previous characteristics 126 associated with the environment. In some cases, one or more authentication devices 108 store such information 122 whenever they receive such information 122 from user equipment 104 (1) and / or whenever they authenticate user equipment 104. One or more authentication devices 108 may then compare the one or more characteristics 126 associated with the current state of the environment represented by the received information 122 with the previous characteristics 126 associated with the previous states of the environment represented by the previous information 122 to identify one or more transitions 140 between the current state of the environment and the previous states of the environment.

[0049] Then, one or more authentication devices 108 can use one or more transitions 140 to determine the duration 120. For example, if this is the first time user device 104(1) is authenticated for a session, the one or more authentication devices 108 can use the set duration 120. As mentioned above, the set duration 120 can include, but is not limited to, one hour, twelve hours, one day, one week, and / or any other time period. The one or more authentication devices 108 can then update the duration 120 each time the authentication device 108 authenticates user device 104(1) for a new session. In some cases, the one or more authentication devices 108 update the duration 120 by increasing or decreasing the previous duration 120 of the previous session.

[0050] For example, if transition(s) 140 indicate that the current state of the environment is similar to one or more previous states of the environment, then authentication device 108 can determine duration 120 by increasing the previous duration 120 associated with the previous session. In some cases, the greater the similarity between the current state of the environment and one or more previous states of the environment, the greater the increase used by authentication device 108 in determining duration 120. For example, if transition(s) 140 indicate that the current state of the environment is different from one or more previous states of the environment, then authentication device 108 can determine duration 120 by decreasing the previous duration 120 associated with the previous session. In some cases, the greater the difference between the current state of the environment and one or more previous states of the environment, the greater the decrease used by authentication device 108 in determining duration 120.

[0051] In some cases, authentication device 108 may analyze information 122 and / or transitions 140 to identify “triggering events” associated with the environment of user device 104(1). As described herein, triggering events may include, but are not limited to, changes in the user of the user device (determined using image data, biometric data, etc.), malicious hardware / software (e.g., malware) identified on the user device, changes in a unique device identifier, changes in an IP address, etc. In some cases, when authentication device 108 identifies a triggering event, authentication device 108 may require user device 104(1) to re-authenticate (using credentials and / or by performing multi-factor authentication). Additionally or alternatively, in some cases, when authentication device 108 identifies a triggering event, authentication device 108 may determine duration 120 as a set duration 120 and / or determine duration 120 by reducing the previous duration.

[0052] Furthermore, in the example above, state component 124 and / or (one or more) authentication devices 108 may use one or more machine learning models to identify (one or more) transitions 140 associated with the current state of the environment. For example, (one or more) machine learning models may be configured to analyze (one or more) characteristics 126 associated with the environment of user device 104(1), such as whenever state component 124 determines (one or more) characteristics 126. Based on this analysis, (one or more) machine learning models identify (e.g., learn) (one or more) characteristics 140 that remain substantially constant. For example, (one or more) machine learning models may identify that user device 104(1) typically uses the same IP address, typically uses the same unique device identifier, includes CPU usage falling within a given range, includes (one or more) applications typically active on user device 104(1), etc. State component 124 and / or (one or more) authentication devices 108 may then compare the new (one or more) characteristics 126 with the learned (one or more) characteristics 126 in order to identify (one or more) transitions 140.

[0053] exist Figure 1 In the example, and in some cases, after generating authentication data 118, one or more authentication devices 108 may send authentication data 118 to user device 104 (1). Additionally, or alternatively, in some cases, after generating authentication data 118, one or more authentication devices 108 may send authentication data 118 to one or more server devices 106, which may then send authentication data 118 to user device 104 (1). In either case, user device 104 (1) may then use authentication data 118 to access services provided by one or more server devices 106 for duration 120.

[0054] like Figure 1As also shown in the example, user equipment 104(1) includes one or more processors 142 and memory 136, authentication device 108 includes one or more processors 144 and memory 146, and user equipment 104(2) includes one or more processors 148 and memory 150. As used herein, a processor may include multiple processors and / or a processor having multiple cores. Furthermore, a processor may include one or more cores of different types. For example, a processor may include an application processor unit, a graphics processing unit, etc. In one instance, a processor may include a microcontroller and / or a microprocessor. One or more processors may include a graphics processing unit (GPU), a microprocessor, a digital signal processor, or other processing units or components known in the art. Alternatively or additionally, the functions described herein may be performed at least in part by one or more hardware logic components. Illustrative types of hardware logic components that may be used include, but are not limited to, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SOCs), complex programmable logic devices (CPLDs), etc. Additionally, (one or more) processors may process their own local memory, which may also store program components, program data, and / or one or more operating systems.

[0055] Memory may include volatile and non-volatile memory, removable and non-removable media implemented in any method or technology, for storing information such as computer-readable instructions, data structures, program components, or other data. Memory includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical storage, magnetic tape cassette, magnetic tape, disk storage or other magnetic storage devices, RAID storage systems, or any other medium that can be used to store desired information and is accessible by a computing device. Memory may be implemented as a computer-readable storage medium (“CRSM”), which may be any available physical medium accessible to one or more processors to execute instructions stored on the memory. In a basic example, CRSM may include random access memory (“RAM”) and flash memory. In other cases, CRSM may include, but is not limited to, read-only memory (“ROM”), electrically erasable programmable read-only memory (“EEPROM”), or any other tangible medium that can be used to store desired information and is accessible by one or more processors.

[0056] Figure 2A-2BAn example is shown of updating the session duration using information associated with the environment of user equipment 104(1) according to the concepts of this disclosure. For example, for a first session 202, authentication device(s) 108 may receive first information 122(1) from user equipment 104(1). As shown, the first information 122(1) indicates a first state of the environment, including 100MB of CPU usage, 100MB of memory usage, a unique device identifier for identifier 1, an IP address for address 1, and three active software applications (e.g., software 1-3). Figure 2A-2B In the example, the first session 202 may correspond to one or more authentication devices 108 for the first authentication device 104 (1) of the session. Thus, the one or more authentication devices 108 can determine that there are no one or more first transitions 140 (1) associated with the environment. Thus, the one or more authentication devices 108 can determine that the set duration is used as the first duration 120 (1) of the first session 202. Figure 2A-2B In the example, the first session 202 lasts for 12 hours.

[0057] At the second session 204, one or more authentication devices 108 can receive second information 122 (2) from user equipment 104 (1). As shown, the second information 122 (2) indicates a second state of the environment, including 110 MB of CPU usage, 90 MB of memory usage, a unique device identifier for identifier 1, an IP address for address 1, and three active software applications (e.g., software 1-3). Thus, one or more authentication devices 108 can compare the second information 122 (2) with the first information 122 (1) to identify one or more second transitions 140 (2). One or more second transitions 140 (2) may include an increase of 10 MB of CPU usage and a decrease of 10 MB of memory usage. Thus, one or more authentication devices 108 can determine that the second state of the environment is similar to the first state of the environment. Therefore, one or more authentication devices 108 can determine the second duration 120 by increasing the first duration 120 (1). Figure 2A-2B As shown in the example, the second duration 120(2) includes 24 hours.

[0058] At the third session 206, one or more authentication devices 108 may receive third information 122 (3) from user equipment 104 (1). As shown, the third information 122 (3) indicates a third state of the environment, including 170 MB of CPU usage, 120 MB of memory usage, a unique device identifier for identifier 1, an IP address for address 1, and three active software applications (e.g., software 1-3). Thus, one or more authentication devices 108 may compare the third information 122 (3) with the second information 122 (2) to identify one or more third transitions 140 (3). One or more third transitions 140 (3) may include an increase of 60 MB of CPU usage and an increase of 120 MB of memory usage. Thus, one or more authentication devices 108 may determine that the third state of the environment is similar to the second state of the environment. Therefore, one or more authentication devices 108 may determine the third duration 120 by increasing the second duration 120 (2). However, since the third state of the environment is less similar to the second state of the environment compared to the first state, the authentication device (one or more) 108 can determine to increase the third duration 120(3) by a small amount. Figure 2A-2B As shown in the example, the third duration 120(3) includes 30 hours.

[0059] At the fourth session 208, one or more authentication devices 108 may receive fourth information 122 (4) from user equipment 104 (1). As shown, the fourth information 122 (4) indicates a fourth state of the environment, including 300 MB of CPU usage, 400 MB of memory usage, a unique device identifier for identifier 1, an IP address for address 1, and four active software applications (e.g., software 1-4). Thus, one or more authentication devices 108 may compare the fourth information 122 (4) with the third information 122 (3) to identify one or more fourth transitions 140 (4). One or more fourth transitions 140 (4) may include an increase of 130 MB of CPU usage, an increase of 280 MB of memory usage, and new activated software (e.g., software 4). Thus, one or more authentication devices 108 may determine that the fourth state of the environment differs from the third state of the environment. Therefore, one or more authentication devices 108 may determine the fourth duration 120 by reducing the third duration 120 (3). Figure 2A-2B As shown in the example, the fourth duration 120(4) includes 18 hours.

[0060] Finally, at the fifth session 210, one or more authentication devices 108 can receive fifth information 122 (5) from user equipment 104 (1). As shown, the fifth information 122 (5) indicates the fifth state of the environment, including 310 MB of CPU usage, 410 MB of memory usage, a unique device identifier for identifier 2, an IP address for address 2, and four active software applications (e.g., software 1-4). Thus, one or more authentication devices 108 can compare the fifth information 122 (5) with the fourth information 122 (4) to identify one or more fifth transitions 140 (5). One or more fifth transitions 140 (5) may include an increase of 10 MB of CPU usage, an increase of 10 MB of memory usage, a new unique device identifier (e.g., identifier 2), and a new IP address (e.g., IP address 2). Thus, one or more authentication devices 108 can determine that a triggering event has occurred and determine the reuse setting duration 120 for the fifth session 210. Figure 2A-2B As shown in the example, the fifth duration 120(5) includes 12 hours.

[0061] It should be noted that, although Figure 2A-2B The example describes one or more authentication devices 108 as receiving information 122 and using information 122 to determine transition 140, but in other examples, the state component 124 of user equipment 104(1) may first use information 122 to determine transition 140. In such an example, the information 122 sent by user equipment 104(1) to one or more authentication devices 108 may represent transition 140.

[0062] Figure 3 A flowchart is shown for a first example method 300 for determining the duration associated with an authenticated user device during a session. Operation 302 represents determining a first duration associated with an authenticated user device during a first session. For example, one or more authentication devices 108 may determine the first duration for the user device. In some cases, one or more authentication devices 108 may determine the first duration as the duration of a setting initially used by one or more authentication devices 108 when authenticating a new device. In some cases, one or more authentication devices 108 use information representing the environment of the user device to determine the first duration. For example, one or more authentication devices 108 may use this information to determine the first duration by increasing or decreasing a previous duration associated with a previous session.

[0063] Operation 304 indicates receiving credentials associated with a user account, while operation 306 indicates authenticating the user device for a second session based at least in part on the credentials. For example, authentication device(s) 108 may use credentials to authenticate the user device for a second session. In some cases, authentication device(s) 108 may provide single sign-on authentication to the user device. Furthermore, in some cases, authentication device(s) 108 may perform multi-factor authentication to authenticate the user device.

[0064] Operation 308 indicates receiving information associated with the user equipment's environment. For example, authentication device(s) 108 may receive this information from the user equipment. In some cases, this information may represent one or more characteristics associated with the current state of the user equipment's environment. Additionally, or alternatively, in some cases, this information may represent one or more transitions between the current state of the environment and one or more previous states associated with the environment.

[0065] Operation 310 indicates that a second duration for authenticating the user equipment during the second session is determined at least in part based on the first duration and the information described above. For example, authentication device(s) 108 may use the information described above and the first duration to determine the second duration. In some cases, authentication device(s) 108 first identifies one or more transitions between the current state of the environment and one or more previous states of the environment. Authentication device(s) 108 then uses the transitions to determine the second duration. For example, if the transitions indicate that the current state of the environment is similar to one or more previous states of the environment, authentication device(s) 108 may determine the second duration by increasing the first duration. Alternatively, if the transitions indicate that the current state of the environment is different from one or more previous states of the environment, authentication device(s) 108 may determine the second duration by decreasing the first duration.

[0066] Operation 312 represents generating data representing at least a second duration, and operation 314 represents sending the data. For example, one or more authentication devices 108 may generate data representing at least a second duration (e.g., tokens, cookies, etc.). In some cases, one or more authentication devices 108 then send the data to the user device. Additionally or alternatively, in some cases, one or more authentication devices 108 send the data to one or more service devices. In either case, the user device uses the data to gain access to services provided by one or more service devices. For example, one or more service devices may use the data to determine that the user device includes a trusted device during the second duration.

[0067] Figure 4 A flowchart of a second example method 400 for determining the duration associated with an authenticated user equipment during a session is shown. Operation 402 represents storing first information associated with the environment of the user equipment during the first session. For example, one or more authentication devices 108 may have previously authenticated the user equipment for the first session. During and / or after authenticating the user equipment, one or more authentication devices 108 may have received first information associated with the environmental state of the user equipment during the first session. One or more authentication devices 108 may then have used the first information to determine the duration of the first session. Furthermore, one or more authentication devices 108 may have stored the first information for subsequent determination of the duration of subsequent sessions associated with the user equipment.

[0068] Operation 404 indicates receiving credentials associated with a user account, while operation 406 indicates authenticating the user device for a second session based at least in part on the credentials. For example, authentication device(s) 108 may use credentials to authenticate the user device for a second session. In some cases, authentication device(s) 108 may provide single sign-on authentication to the user device. Furthermore, in some cases, authentication device(s) 108 may perform multi-factor authentication to authenticate the user device.

[0069] Operation 408 indicates receiving second information associated with the environment of the user equipment. For example, authentication device(s) 108 may receive information for a second session from the user equipment. In some cases, the second information may represent one or more characteristics associated with the current state of the user equipment's environment.

[0070] Operation 410 represents determining the duration of the authenticated user device during the second session based at least in part on the first information and the second information. For example, authentication device(s) 108 may use at least the first information and the second information to determine the duration. In some cases, authentication device(s) 108 first identifies one or more transitions between the current state of the environment as represented by the second information and a previous state of the environment as represented by the first information. Authentication device(s) 108 then uses the transition(s) to determine the duration. For example, if the transition(s) indicates that the current state of the environment is similar to the previous state(s) of the environment, authentication device(s) 108 may determine the duration by increasing the previous duration. Alternatively, if the transition(s) indicates that the current state of the environment is different from the previous state(s) of the environment, authentication device(s) 108 may determine the duration by decreasing the previous duration.

[0071] Operation 412 represents generating data that at least indicates a duration, and operation 414 represents sending the data. For example, one or more authentication devices 108 may generate data indicating at least a duration (e.g., tokens, cookies, etc.). In some cases, one or more authentication devices 108 then send the data to the user device. Additionally or alternatively, in some cases, one or more authentication devices 108 send the data to one or more service devices. In either case, the user device uses the data to gain access to services provided by one or more service devices. For example, one or more service devices may use the data to determine that the user device includes trusted devices during that duration.

[0072] Figure 5 A flowchart of a third example method 500 for determining the duration associated with an authenticated user equipment during a session is shown. Operation 502 represents determining first information representing a first state of the user equipment's environment. For example, one or more authentication devices 108 may have previously authenticated the user equipment for the first session. Based at least in part on the authentication of the user equipment, one or more authentication devices 108 may receive first information representing a first state of the user equipment's environment during the first session. One or more authentication devices 108 may then have used the first information to determine a first duration of the first session.

[0073] Operation 504 indicates receiving second information representing a second state of the user equipment's environment. For example, one or more authentication devices 108 may authenticate the user equipment for a second session. Based at least in part on the authentication of the user equipment, one or more authentication devices 108 may receive second information representing a second state of the user equipment's environment during the second session.

[0074] Operation 506 represents determining one or more transitions between a second state of the environment and a first state of the environment. For example, authentication device(s)108 may analyze first information relative to second information to determine one or more transitions. As described herein, one or more transitions may include, but are not limited to, changes to a unique device identifier, changes to hardware associated with a user device, changes to software installed on a user device, changes to one or more applications active on the user device, changes to memory usage associated with the user device, changes to the IP address associated with the user device, changes to power consumption associated with the user device (e.g., whether the user device continuously receives power or whether the user device stops receiving power for a period of time), changes to the type of network connection associated with the user device, or changes to the user of the user device (such as those determined using sensor data).

[0075] Operation 508 indicates determining whether one or more transitions indicate that a second state is similar to a first state. For example, authentication device 108 may analyze one or more transitions to determine whether a second state of the environment is similar to a first state of the environment. In some cases, when the transitions represent small changes between states, such as small changes in CPU usage, memory usage, etc., authentication device 108 may determine that the second state is similar to the first state. Furthermore, in some cases, when the transitions represent large changes between states, such as changes in unique device identifiers, IP addresses, users, etc., authentication device 108 may determine that the second state is not similar to the first state.

[0076] At 508, if it is determined that one or more transitions indicate that the second state is similar to the first state, then operation 510 indicates that the duration is determined by increasing the previous duration. For example, if authentication device(s) ...

[0077] However, if at 508, it is determined that one or more transitions indicate that the second state is dissimilar to the first state, then operation 512 indicates that the duration is determined by reducing the previous duration. For example, if authentication device(s) ...

[0078] It should be noted that, although Figure 5 The example describes authentication device 108 as performing 502-506, but in other examples, user equipment may perform 502-506. In this case, authentication device 108 may then receive information from user equipment representing one or more transitions.

[0079] Figure 6 This is a computing system diagram illustrating the configuration of a data center 600, which can be used to implement various aspects of the technologies disclosed herein. Figure 6The example data center 600 shown includes several computers 602A-602F (which may be referred to herein as a "single computer 602" in the singular or "multiple computers 602" in the plural) for providing computing resources. In some examples, the resources and / or computers 602 may include or correspond to any type of networking device described herein, such as one or more server devices 106 and / or one or more authentication devices 108. Nevertheless, computer 602 may include any type of networking device, such as servers, switches, routers, hubs, bridges, gateways, modems, repeaters, access points, hosts, etc.

[0080] Computer 602 may be a standard tower, rack, or blade server computer, appropriately configured to provide computing resources. In some examples, computer 602 may provide computing resources 604, including data processing resources (e.g., virtual machine (VM) instances or hardware computing systems, database clusters, compute clusters, storage clusters), data storage resources, database resources, network resources, etc. Some computers 602 may also be configured to execute a resource manager 606 capable of instantiating and / or managing computing resources. For example, in the case of VM instances, resource manager 606 may be a hypervisor or another type of program configured to enable the execution of multiple VM instances on a single computer 602. Computer 602 in data center 600 may also be configured to provide network services and other types of services.

[0081] exist Figure 6 In the example data center 600 shown, computers 602A-602F are also interconnected using a suitable local area network (LAN) 608. It should be understood that the configuration and network topology described herein have been greatly simplified, and many more computing systems, software components, networks, and networking devices can be used to interconnect the various computing systems disclosed herein and provide the aforementioned functionality. Suitable load balancing devices or other types of network infrastructure components can also be used to balance the load between data centers 600, between each computer 602A-602F in each data center 600, and potentially between the computing resources in each computer 602. This should be considered merely illustrative, and other implementations may be utilized.

[0082] In some examples, computer 602 may each execute one or more application containers and / or virtual machines to perform the techniques described herein. For example, containers and / or virtual machines may be used as server devices, user devices, and / or routers in cloud computing network 102.

[0083] In some cases, data center 600 can provide computing resources, such as application containers, VM instances, and repositories, permanently or as needed. In other types of functions, computing resources provided by the cloud computing network can be used to implement the various services and technologies mentioned above. The computing resources 604 provided by the cloud computing network can include various types of computing resources, such as data processing resources (e.g., application containers and VM instances), data storage resources, network resources, data communication resources, network services, etc.

[0084] Each type of computing resource 604 provided by the cloud computing network can be general-purpose or available in many specific configurations. For example, data processing resources can be used as physical computers or VM instances in many different configurations. VM instances can be configured to run applications, including web servers, application servers, media servers, database servers, some or all of the aforementioned network services, and / or other types of programs. Data storage resources can include file storage devices, block storage devices, etc. The cloud computing network can also be configured to provide other types of computing resources 604 not specifically mentioned herein.

[0085] In one embodiment, the computing resources 604 provided by the cloud computing network can be enabled by one or more data centers 600 (referred to herein as a "single data center 600" in the singular case or a "multiple data centers 600" in the plural case). A data center 600 is a facility for housing and operating computer systems and related components. A data center 600 typically includes redundant and backup power, communication, cooling, and security systems. Data centers 600 may also be located in geographically distinct locations. References will follow below. Figure 7 An illustrative embodiment of a data center 600 that can be used to implement the techniques disclosed herein is described.

[0086] Figure 7 This is a computer architecture diagram illustrating an illustrative computer hardware architecture for implementing a server computing device 700, which can be used to implement various aspects of the various technologies presented herein. The server device(s) 106(s) and / or authentication device(s) 108(s) discussed above may include some or all of the components discussed below with reference to the server computing device 700.

[0087] First, server computer 700 can be a standard tower, rack, or blade server computer, appropriately configured to provide the computing resources described herein. As mentioned above, the computing resources provided by cloud computing networks, data centers, etc., can be data processing resources (e.g., VM instances or hardware computing systems, database clusters, computing clusters, storage clusters), data storage resources, database resources, network resources, etc. Some of the servers 700 can also be configured to execute resource managers capable of instantiating and / or managing computing resources. For example, in the case of VM instances, the resource manager can be a hypervisor or another type of program configured to enable the execution of multiple VM instances on a single server computer 700. Server computers 700 in data centers can also be configured to provide network services and other types of services.

[0088] Server computer 700 includes a baseboard 702 or “motherboard,” a printed circuit board to which numerous components or devices can be connected via a system bus or other electrical communication path. In an illustrative configuration, one or more central processing units (CPUs) 704 operate in conjunction with a chipset 706. The CPU 704 may be a standard programmable processor that performs arithmetic and logical operations required for the operation of computer 700.

[0089] The CPU 704 performs operations by manipulating switching elements that distinguish and change physical states, thus transitioning from one discrete physical state to the next. Switching elements typically include electronic circuitry, such as flip-flops, that maintains one of two binary states, and electronic circuitry (such as logic gates) that provides an output state based on a logical combination of the states of one or more other switching elements. These basic switching elements can be combined to create more complex logic circuits, including registers, adders, subtractors, arithmetic logic units, floating-point units, and more.

[0090] Chipset 706 provides an interface between CPU 704 and the remaining components and devices on substrate 702. Chipset 706 may provide an interface to RAM 708, which serves as the main memory in computer 700. Chipset 706 may also provide an interface to computer-readable storage media such as read-only memory (ROM) 710 or non-volatile RAM (NVRAM), which stores basic routines that facilitate the startup of computer 700 and the transfer of information between various components and devices. ROM 710 or NVRAM may also store other software components required for the operation of computer 700 according to the configuration described herein.

[0091] Computer 700 can operate in a networked environment using a logical connection to remote computing devices and computer systems via a network (e.g., local area network 724). Chipset 706 may include functionality for providing network connectivity via a network interface card (NIC) 712 (e.g., a Gigabit Ethernet adapter). NIC 712 enables computer 700 to connect to other computing devices via a network. It should be understood that multiple NICs 712 may exist in computer 700, connecting the computer to other types of networks and remote computer systems.

[0092] Computer 700 can be connected to storage device 718, which provides non-volatile storage for the computer. Storage device 718 can store operating system 720, programs 722, and data, which have been described in more detail herein. Storage device 718 can be connected to computer 700 via storage controller 714 connected to chipset 706. Storage device 718 can consist of one or more physical storage units. Storage controller 714 can interface with physical storage units via a Serial Attached SCSI (SAS) interface, a Serial Advanced Technology Attached (SATA) interface, an FC interface, or other types of interfaces used for physical connection and data transfer between the computer and physical storage units.

[0093] Computer 700 can store data on storage device 718 by changing the physical state of physical storage units to reflect the stored information. In different embodiments of this specification, the specific changes in physical state can depend on various factors. Examples of such factors may include, but are not limited to, the technology used to implement the physical storage units, whether storage device 718 is characterized as a primary storage device or a secondary storage device, etc.

[0094] For example, computer 700 can store information in storage device 718 by issuing instructions through storage controller 714 to change the magnetic properties of a specific location within a disk drive unit, the reflection or refraction properties of a specific location in an optical storage unit, or the electrical properties of a specific capacitor, transistor, or other discrete component in a solid-state storage unit. Other variations of the physical medium are possible without departing from the scope and spirit of this specification; the examples provided above are merely for illustrative purposes. Computer 700 can also read information from storage device 718 by detecting the physical state or characteristics of one or more specific locations within the physical storage unit.

[0095] In addition to the aforementioned high-capacity storage device 718, computer 700 may also access other computer-readable storage media to store and retrieve information, such as program modules, data structures, or other data. Those skilled in the art will understand that a computer-readable storage medium is any available medium that provides non-transitory storage of data and can be accessed by computer 700. In some examples, operations performed by computer 700 and / or any components included therein may be supported by one or more devices similar to computer 700.

[0096] By way of example and not limitation, computer-readable storage media can include volatile and non-volatile, removable and non-removable media implemented in any method or technology. Computer-readable storage media include, but are not limited to, RAM, ROM, erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory or other solid-state storage technologies, optical disc ROM (CD-ROM), digital versatile disc (DVD), high-definition DVD (HD-DVD), Blu-ray or other optical storage, magnetic tape cassettes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information in a non-transitory manner.

[0097] As described above, storage device 718 can store operating system 720 for controlling the operation of computer 700. According to one embodiment, the operating system includes a LINUX operating system. According to another embodiment, the operating system includes one from Microsoft Corporation in Redmond, Washington. SERVER operating system. In another embodiment, the operating system may include one of the UNIX operating systems or variants thereof. It should be understood that other operating systems may also be used. Storage device 718 may store other systems, applications, and data used by computer 700.

[0098] In one embodiment, storage device 718 or other computer-readable storage medium is encoded with computer-executable instructions that, when loaded into computer 700, transform the computer from a general-purpose computing system into a special-purpose computer capable of implementing the embodiments described herein. As described above, these computer-executable instructions transform computer 700 by specifying how CPU 704 transitions between states. According to one embodiment, computer 700 can access the computer-readable storage medium storing the computer-executable instructions, which, when executed by computer 700, perform the above-described... Figure 3-6 The various processes described herein. The computer 700 may also include a computer-readable storage medium having instructions stored thereon for performing operations of any other computer implementation described herein.

[0099] Computer 700 may also include one or more input / output controllers 716 for receiving and processing input from multiple input devices (e.g., keyboard, mouse, touchpad, touchscreen, electronic stylus, or other types of input devices). Similarly, input / output controllers 716 may output to a display (e.g., computer monitor, flat panel display, digital projector, printer, or other types of output devices). It should be understood that computer 700 may not include... Figure 7 All components shown may include Figure 7 Other components not explicitly shown, or those that can be used with Figure 7 The architecture shown is completely different from the one described above.

[0100] The server computer 700 may also store the authentication request 114, authentication data 118, information 122 and (one or more) transitions 140 as described above in the storage device 718.

[0101] In summary, this disclosure describes techniques for authenticating a user device for a session. For example, an authentication entity may use single sign-on authentication and / or multi-factor authentication to authenticate the user device. The authentication entity can then determine the duration for which the user device is authenticated for a session. For example, the authentication entity may receive information representing the state of the user device's environment. The authentication entity can then use this information to identify one or more transitions in the environment associated with the session and previous sessions. Using one or more transitions, the authentication entity can determine the duration of the current session by increasing or decreasing the previous duration associated with the previous session.

[0102] While the invention has been described with reference to specific embodiments, it should be understood that the scope of the invention is not limited to these specific embodiments. Since other modifications and alterations to suit specific operational requirements and environments will be apparent to those skilled in the art, the invention is not to be considered limited to the examples chosen for the purposes of disclosure, and covers all modifications and alterations that do not constitute a departure from the true spirit and scope of the invention.

[0103] Although this application describes embodiments with specific structural features and / or methodological actions, it should be understood that the claims are not necessarily limited to the specific features or actions described. Rather, the specific features and actions are merely illustrative of some embodiments falling within the scope of the claims of this application.

Claims

1. One or more devices, including: One or more processors; and One or more computer-readable media store instructions that, when executed by the one or more processors, cause the one or more processors to perform operations, the operations including: Determine the first duration associated with the authenticated user equipment during the first session; Receive credentials associated with a user account; The user equipment is authenticated for the second session based at least in part on the credentials; Receive information associated with the environment of the user equipment; The information indicates one or more transitions associated with a first state of the environment during the first session and a second state of the environment during the second session; A second duration associated with authenticating the user equipment during the second session is determined, at least in part based on the first duration and the information, wherein determining the second duration includes: determining the second duration by increasing or decreasing the first duration at least in part based on the one or more transitions; Generate data representing at least the second duration; and The data is sent to the user equipment.

2. The operation further comprises: (The first part of the description is missing from the original text.) Send an authentication request associated with the second session; Receive a response to the authentication request; as well as Verify the response in response to the authentication request. Furthermore, the authentication of the user equipment for the second session is at least partially based on verifying the response.

3. The operation further comprises: Determining that the one or more transitions indicate that the second state of the environment is similar to the first state of the environment And wherein determining the second duration includes: determining the second duration by increasing the first duration by at least in part based on the similarity between the second state of the environment and the first state of the environment.

4. The operation further comprises: Determining that the one or more transitions indicate that the second state of the environment is different from the first state of the environment, Furthermore, determining the second duration includes: determining the second duration by reducing the first duration at least in part based on the fact that the second state of the environment is different from the first state of the environment.

5. One or more devices according to any one of claims 1 to 4, wherein the information is first information representing the second state of the environment, and wherein the operation further comprises: Store second information representing the first state of the environment. Furthermore, determining that the first information indicates the one or more transitions includes: analyzing the first information relative to the second information to determine the one or more transitions associated with a first state of the environment during the first session and a second state of the environment during the second session.

6. One or more devices according to any one of claims 1 to 4, wherein the information is first information, the data is first data, and wherein the operation further comprises: Receive second information associated with the environment of the user equipment; The first duration is determined at least in part based on the set duration and the second information; Generate second data representing the first duration; as well as The second data is sent to the user equipment.

7. One or more devices according to any one of claims 1 to 4, wherein the information is first information, and wherein the operation further comprises: During the second duration, second information associated with the environment of the user equipment is received; The second information indicates the triggering event; as well as The re-authentication of the user equipment is determined at least in part based on the second information indicating the triggering event.

8. One or more devices according to any one of claims 1 to 4, wherein, The information associated with the environment indicates at least one of the following: A unique device identifier associated with the user equipment; Hardware associated with the user equipment; Software installed on a user's device; One or more applications active on the user device; Central processing unit usage associated with the user equipment; Memory usage associated with the user equipment; Internet Protocol address; Power consumption associated with the user equipment; The type of network connection associated with the user equipment; or This refers to the sensor data of the user of the user equipment.

9. A method comprising: Store first information associated with the environment of the user device during the first session, the first session being associated with a first duration; Receive credentials associated with a user account; The user equipment is authenticated for the second session based at least in part on the credentials; For the second session, second information associated with the environment of the user equipment is received; The first information is analyzed relative to the second information to determine one or more transitions between the first session and the second session that are associated with the environment; Determine a second duration associated with authenticating the user equipment during the second session, wherein determining the second duration includes increasing or decreasing the first duration at least in part based on the one or more transitions; Generate data representing at least the second duration; and The data is sent to the user equipment.

10. The method of claim 9, further comprising: Send an authentication request associated with the second session; Receive a response to the authentication request; as well as Verify the response in response to the authentication request. Furthermore, the authentication of the user equipment for the second session is at least partially based on verifying the response.

11. The method of claim 9, further comprising: Determining that the one or more transitions indicate that the second state of the environment during the second session is similar to the first state of the environment during the first session. And wherein determining the second duration includes: determining the second duration by increasing the first duration by at least in part based on the similarity between the second state of the environment and the first state of the environment.

12. The method according to claim 9, further comprising: The determination that the one or more transitions indicate that the second state of the environment during the second session is different from the first state of the environment during the first session. Furthermore, determining the second duration includes: determining the second duration by reducing the first duration at least in part based on the fact that the second state of the environment is different from the first state of the environment.

13. The method according to any one of claims 9 to 12, wherein, The one or more transitions associated with the environment between the first session and the second session include at least one of the following: Change of the unique device identifier associated with the user equipment; Changes to the hardware associated with the user equipment; Changes to the software installed on the user equipment; Changes to one or more applications active on the user device; Changes in the usage of the central processing unit associated with the user equipment; Changes in memory usage associated with the user equipment; Changes in Internet Protocol (IP) addresses; Changes in power consumption associated with the user equipment; or A change in the type of network connection associated with the user equipment.

14. The method according to any one of claims 9 to 12, further comprising: During the second duration, third information associated with the environment of the user equipment is received; The third information indicates the triggering event; as well as The re-authentication of the user equipment is determined at least in part based on the third information indicating the triggering event.

15. A method comprising: Determine the first duration associated with the authenticated user equipment during the first session; Receive credentials associated with a user account; The user equipment is authenticated for the second session based at least in part on the credentials; Receive information associated with the environment of the user equipment; The information indicates one or more transitions between the first session and the second session that are associated with the environment; A second duration associated with authenticating the user equipment during the second session is determined, at least in part based on the first duration and the information, wherein determining the second duration includes: determining the second duration by increasing or decreasing the first duration at least in part based on the one or more transitions; Generate data representing at least the second duration; and Send the data.

16. The method of claim 15, further comprising: Send an authentication request associated with the second session; Receive a response to the authentication request; as well as Verify the response in response to the authentication request. Furthermore, the authentication of the user equipment for the second session is at least partially based on verifying the response.

17. An apparatus comprising: Means for storing first information associated with the environment of a user device during a first session, the first session being associated with a first duration; A device for receiving credentials associated with a user account; A means for authenticating the user equipment for a second session based at least in part on the credentials; A means for receiving, in connection with the environment of the user equipment, second information for the second session; A means for analyzing the first information relative to the second information to determine one or more transitions between the first session and the second session that are associated with the environment; A means for determining a second duration associated with authenticating the user equipment during the second session, wherein determining the second duration includes: increasing or decreasing the first duration based at least in part on the one or more transitions; A means for generating data representing at least the second duration; and A means for sending the data to the user equipment.

18. The apparatus of claim 17, further comprising: Apparatus for carrying out the method according to any one of claims 10 to 14.

19. An apparatus comprising: Means for determining a first duration associated with an authenticated user equipment during a first session; A device for receiving credentials associated with a user account; A means for authenticating the user equipment for a second session based at least in part on the credentials; A means for receiving information associated with the environment of the user equipment; A means for determining one or more transitions associated with the environment between the first session and the second session indicated by the information; A means for determining a second duration associated with authenticating the user equipment during the second session based at least in part on the first duration and the information, wherein determining the second duration includes: determining the second duration by increasing or decreasing the first duration at least in part based on the one or more transitions; A means for generating data representing at least the second duration; and A means for transmitting the data.

20. The apparatus of claim 19, further comprising means for carrying out the method of claim 16.

21. A computer program product comprising instructions that, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 9 to 16.

22. A computer-readable medium comprising instructions that, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 9 to 16.

Citation Information

Patent Citations

  • Authentication Frequency and Challenge Type Based on Environmental and Physiological Properties

    US20150178486A1