Event-based authentication
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- MICROSOFT TECHNOLOGY LICENSING LLC
- Filing Date
- 2023-05-15
- Publication Date
- 2026-04-27
AI Technical Summary
Existing authentication methods rely heavily on devices that can be lost, forgotten, or compromised, and biometric information is difficult to change and vulnerable to data leakage, limiting the security of one-time passwords and two-factor authentication.
A system generates a custom personal identification number (PIN) based on an ordered series of user events, allowing users to authenticate by arranging a subset of these events in a non-chronological order, which is remembered and secure without relying on specific devices.
This method enhances security by making authentication more difficult for attackers to replicate, as it relies on the user's memory of personal events in a unique order, reducing reliance on device availability and minimizing data exposure risks.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field
[0001] Technical Field The present disclosure generally relates to methods and systems for providing a user with a user event-based authentication service according to some embodiments.
Background Art
[0002] Background As technology evolves, the use of software and hardware technologies for secure communication and financial transactions continues to increase. Protecting access to systems and confidential information related to such communication and financial transactions, such as by verifying a user's identification information, has become an additional technical challenge. Verification and authentication techniques need to be secure but not overly burdensome.
Summary of the Invention
[0003] Summary Embodiments of the present disclosure include methods and systems for determining a custom personal identification number (PIN) for a user based on an ordered series of user events. Based on a set of stored events, a custom PIN for the user can be generated, each event being associated with a particular point in time. A user can be authenticated by providing information that matches the custom PIN. Generating the custom PIN can include selecting a subset of user events from the set of the user's stored events, determining the chronological order of the selected subset of events based on the respective associated points in time of the selected subset of events, and assigning a chronological identifier representing the position of each event in the determined chronological order to each of the selected subset of events, and determining the custom PIN as an arrangement of the chronological identifiers in an arrangement order that is not chronological order. The selected subset of user events can be presented to the user in arrangement order for subsequent chronological arrangement by the user. In response to determining that the received indication of chronological arrangement matches the determined custom PIN, the user can be authenticated.
[0004] The subject matter recited in the claims can be implemented as a method, apparatus, or article of manufacture using standard programming and engineering techniques to produce software, firmware, hardware, or any combination thereof to control a computing device to implement the disclosed subject matter. As used herein, the term "article of manufacture" is intended to encompass a computer program accessible from any computer-readable storage device or medium. Computer-readable storage media can include, but are not limited to, magnetic storage devices, such as hard disks, floppy disks, magnetic strips; optical disks, such as compact discs (CDs), digital versatile discs (DVDs); smart cards; flash memory devices, etc. In contrast, computer-readable media (which is not a storage media) can further include communication media, such as transmission media for wireless signals, etc.
[0005] This summary is provided to introduce a series of concepts that are further described below in the detailed description. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0006] Brief Description of the Drawings The disclosed embodiments are described below with reference to the accompanying drawings, which are provided for illustration purposes and not to limit the disclosed embodiments.
Brief Description of the Drawings
[0007]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Mode for Carrying Out the Invention
[0008] Detailed Description Authentication and verification are related concepts in the field of information security and are often used interchangeably. Generally speaking, authentication is the act of proving a claim. For example, the act of logging into an online account by entering the correct combination of a username and password, the act of completing a credit card transaction by providing a multi-digit security code printed on a physical card related to the credit card number and expiration date, the act of unlocking a mobile device with the correct passcode, and the act of unlocking a computer with the correct password can each be regarded as authentication acts. However, there may be a case where a person has the correct combination of a username and password for an account that belongs to another person. There may be a case where a third party can access the multi-digit security code printed on a physical credit card belonging to another person. There may be a case where the passcode of a person's mobile device is shared with another person, or the password of a person's computer is shared with another person. There may be a case where specific information is correctly provided to authenticate an act without verifying the identifying information of the user who requests the act.
[0009] In contrast, verification is the act of verifying that a person is who the user claims to be, and often requires confirmation or interaction using some information first provided when initially accessing the requested resource. Verifying that the identification information of a person presenting a credit card in a face-to-face transaction matches the details on the card is an act of verification. Authentication often requires verification, and thus, authentication may include verification. In certain examples, a second authentication such as using additional information may be in the form of verification.
[0010] Authentication and verification fields such as two-factor authentication or verification techniques that require a user to perform coordinated actions across multiple devices, for example, by requesting access by the user on one account or device and verifying the action or requesting multiple pieces of information using the user's second known account or device, are constantly evolving. The success of two-factor authentication through successive first and second authentications, etc., reduces the likelihood that the first successful authentication was an attack, because it is less likely that an attacker can obtain multiple devices or additional correct information.
[0011] Other verification techniques require access to the user's biometric information, access to multiple secure systems, or different combinations of passwords or logins (e.g., login with username and password at a first point in time, text verification at a second point in time, etc.). For example, a user who requests access to a first system may be provided with a one-time password to a second system or an email account, etc., associated with the user, such as a mobile device (e.g., a mobile phone). The advantage of a one-time password or a time-based one-time password is that it expires after being used once or within a relatively short window after being requested, adding obfuscation by changing the password for each request, and allowing for a less secure password (e.g., fewer characters, etc.). Further verification techniques include an authenticator application that either supplements the first authentication by directly connecting to the first authentication source and exchanging public key / secret key information, or in response to a second authentication with a password, PIN, or biometric information, provides the user with a secret key that the user can provide to the first authentication source for subsequent authentication with the secret key.
[0012] However, biometric information cannot be reasonably changed by the user, and the damage caused by the risk of exposure due to data leakage or the like is significant. Therefore, using the user's biometric information can be a problem. Furthermore, as the use of mobile devices increases or communication is replicated across multiple devices (e.g., receiving SMS texts on both a mobile phone and a computer, accessing multiple email addresses on one device, accessing a secure account from a mobile device as a second device, one-time passwords are often sent to the device that requests the original authentication, which limits the advantages of one-time passwords when, for example, the device is not locked (as would be the case when it requests a one-time password, the original authentication, etc.) or the password is provided within a preview that can be viewed by a third party). In addition, the use of authenticator applications is generally tied to an individual device, which may be lost, forgotten, or misplaced, or may operate with limited battery power or connectivity, or may stop working for one or more other reasons.
[0013] Accordingly, the inventors recognized that it is necessary to further improve the security of one-time passwords, especially by using information regarding the user's events and, in certain examples, the relative chronological order of a larger subset of the user's stored events. Further advantages include performing verification without disclosing information that is easily reproducible while having the advantage of being reproducible by the user in any number of permutations or combinations, including using any device including a point-of-sale information management device, an automated teller machine (ATM). In particular, remembering an event or sequence of events that is relevant enough to provide (when prompted, for example), or is specifically provided as a challenge event during the setup of an authentication service or the creation of a new account, etc., is a relatively secure way to create a combinable set of repeatable information for the user that, in certain examples, can be difficult or nearly impossible for another person to recreate with respect to other times, durations, or other security measures, as described below.
[0014] Furthermore, events can be specific to a user but generally obfuscated. For example, when prompted, a user can provide a related event as having been bitten by a dog in high school. From that single piece of information, (1) a simple dog icon or an event related to a dog represented by the word "dog" can be created, followed by (2) two events in chronological order, a graduation certificate or graduation cap icon or the graduation represented by the word "graduation". The systems and methods disclosed herein can provide these events as two of a greater number of events for placement in the appropriate chronological order. For the user, the order and specific details of such events are memorable, especially in situations where the user sets up the events for use in authentication / verification. However, a third party does not have the context to accurately understand the meaning of such events or to place such events in chronological order relative to other events. Just as a third party does not know whether the graduation that is most memorable to the user is a high school graduation, a graduate school graduation, or a child's graduation, etc., there is no way to know whether the dog icon or word represents an event related to a childhood pet, a pet acquired for the first time as an adult, or any number of other dogs. Without context, it becomes even more difficult to understand or order the events.
[0015] The above examples of the dog and graduation involve only two events. The difficulty level increases by adding additional events. Additionally, to further increase the difficulty for a third party to infer the appropriate chronological order, other rules can be implemented for event selection that require, for example, at least two subsets of the selected events for display to occur within an absolute or relative time window (e.g., a relatively short time). For example, two additional chronological events can include a knee injury sustained immediately after the first trip to Paris that occurred within a specific (e.g., within a two-year range, but more than ten years ago, etc.) time window. The knee injury can generally be represented by a knee icon, and the first trip to Paris can be represented by an Eiffel Tower icon. The systems and methods disclosed herein can select these four events as icons (e.g., a dog, a graduation certificate, the Eiffel Tower, and a knee) and present them to the user in a random order on any device. Alternatively, these events can be represented by text descriptions (e.g., simple words or combinations such as "dog", "graduation certificate", "Eiffel Tower", and "knee"). The user can be authenticated by appropriately ordering the four events as words or icons within a challenge window (e.g., 15 seconds). Stealing the user's device provides no advantage in quickly ordering these simple icons.
[0016] In a relative chronological order or with any specific date information provided by the user, a larger set of events (e.g., ten or more, twenty, etc.) can be received, obfuscated, and stored by an authentication service or authentication application. In a specific example, specific data information can be used as additional verification after an initial failure or timeout, etc. A new PIN (e.g., four randomly selected events) can be selected at each request. The order and events can be presented to the user in various ways, and the user can provide the appropriate chronological order in various ways as described herein.
[0017] The technical solutions contemplated herein, in certain examples, address technical problems of improving data security by providing techniques for generating secure and memorable PINs that are independent of the delivery channel and subsequent systems and methods for authentication based on a specific temporal arrangement of stored user events, and techniques for improving highly reliable and secure access to communications, financial transactions, and other access to sensitive information while reducing reliance on controlling and maintaining specific devices having various power states and connectivity.
[0018] FIG. 1 shows an example of a computer system 100 for providing an authentication service that includes a first user device 101, a second user device 111, and an authentication service 110 coupled to a network 109.
[0019] The first user device 101, by way of example, may include a processor 102 (e.g., one or more processors), a memory 103, a transceiver 105, and one or more input / output (I / O) components 106. The memory 103 may, in certain examples, include an authentication application 104 configured to interact with or connect to the authentication service 110. The authentication application 104 may be executed on the first user device 101 (or one or more other user devices), although the authentication service 810 is separate and remote from the first user device and may include a server, network, or cloud-based service accessible on network 109.
[0020] The authentication service 110 may include one or more devices (e.g., one or more processors, transceivers, memories, storage, databases, servers, etc.) configured to manage authentication of one or more user accounts, devices (e.g., the first user device 101 and the second user device 102), or other secure functions, services, transactions, or information, or authentication related thereto.
[0021] In one example, one or more of authentication application 104 or authentication service 110 can be configured to determine a custom personal identification number (PIN) for a user based on an ordered series of events. In one example, authentication application 104 can be configured to receive a request for a custom PIN in response to actions by a user who is logged into an application, service, or system, or by a first user device 101 that is making a purchase or request through the first user device 101 or one or more other financial or retail services, where those applications, services, or systems request authentication of the purchase or request. Authentication application 104 can provide the received request to authentication service 110. In other examples, authentication service 110 can directly receive a request for a custom PIN through an application, service (such as a financial service, retail service, etc.), or system, etc.
[0022] In response to receiving a request for a custom PIN, authentication service 110 can generate a custom PIN for the user based on a set of stored events (such as stored events of the user ordered by the user, etc.), where each event is associated with a particular or relative point in time. In a particular example, the authentication service 110 or one or both of the authentication application 104 (such as an authentication service by the authentication application 104) can be configured to receive event information from the user, create a set of user events ordered by the user, obscure the personal details of the events, but provide sufficient specificity for the user to recognize the intended events based on the event information, and confirm such obscuring to the user.
[0023] Events can be remembered in the order in which they occurred to the user, from the oldest event to the newest event. In certain examples, it is possible to receive a specific time or period for each event or group of events, such as for use in additional verification if needed at a later time. A set of user-ordered user events can be stored in a database on a server by an authentication service 110 and associated with the user profile of an account, for example. In certain examples, the authentication service 110 can access the user profile information of a user and use information from the user profile to create a draft of user events for confirmation by the user.
[0024] In other examples, in response to receiving a custom PIN request, the authentication application 104 can generate a custom PIN for the user based on a set of user-ordered user events received from the authentication service 110 or a server or database associated with the authentication service 110, or use one or more stored events ordered by the user stored on the first user device 101 if the network 109 is unavailable to the first user device 101 or if the first user device 101 cannot access the authentication service 110. For example, if the authentication service 110 can access a first set of events ordered by the user (e.g., 10 or 20, etc.), the first user device 101 can receive and store, in certain examples, a minimum subset (e.g., 4, etc.) of the larger set, such as in the case where connectivity is lost. The minimum subset can be used limitedly before its expiration and connectivity is required for additional authentication or authentication attempts.
[0025] In one example, one or more of the authentication service 110 or the authentication application 104 can be configured to present a subset of the selected events to the user in an order. In a particular example, the order can potentially include a chronological order, such that the events can be selected randomly or arranged in an order that is already in chronological order (such as from the oldest occurring to the newest, etc.). In other examples, the order can exclude chronological order, such that the user must make at least one change for authentication. However, as discussed, certain presentations may still require the user input to be in any way necessary to be able to enter a 4-digit PIN as "1234", or for example, the subset of four images arranged in chronological order may still require all four images to be dragged and dropped in the same order as presented. In situations where user input is required and the order cannot be selected as presented initially, the order can optionally include a chronological order.
[0026] A subset of the events can be displayed by the first user device 101 or one or more other devices (e.g., a POS device, an ATM machine, one or more other user devices (e.g., the second user device 111, etc.)), and the chronological arrangement can be received from those devices. In a particular example, the device that displays the subset of the events can be the same as or different from the device that receives the chronological arrangement as discussed herein.
[0027] One or both of the authentication service 110 or the authentication application 104 (such as from the authentication service 110 to the authentication application 104, etc.) can be configured to authenticate the user by, for example, comparing the received chronological arrangement with the generated custom PIN. If the received chronological arrangement indicates an order different from the stored events ordered by the user, the system does not authenticate the user. Performing authentication by one or more devices, applications, or services can result in a positive result (e.g., authenticating the user) or a negative result (e.g., not being able to authenticate the user). An error during authentication results in a negative result.
[0028] FIG. 2 shows an example of an authentication technique 200 for generating a personal identification number (PIN) using one or both of an authentication service as described herein or an authentication application executed on a user device connected to the authentication service in a particular example, and the like.
[0029] A set of user events 202 can be stored, with each event being associated with a point in time and, in a particular example, stored in the order defined by the user from the oldest to the newest as they occurred to the user. The number of events within the set of events 202 can vary, but in a particular example, it needs to be more than at least 2. In one example, to balance security and setup cost in generating or receiving a set of events, if 4 events are required for a subset for ordering purposes (e.g., a 4 - digit PIN), at least 6 events (e.g., 1.5 times) may be required within the set of events 202, providing 15 unique combinations of time - series events and 360 unique presentation orders for the user to arrange in time - series order to recover the generated PIN. For example, if 4 events are required within a subset and at least 7 events are required within the set of events 202, 35 unique combinations of time - series events and 840 unique presentation orders for the user to arrange in time - series order to recover the generated PIN can be provided. As shown in Table 1, in other examples, other combinations of sets and subsets can provide other numbers of unique combinations and possible presentation orders.
[0030] [Table 1]
[0031] To present to the user for arranging in chronological order, the first subset 203 of the set of events 202 can be selected. However, the possibility of inferring the correct order of the presented subsets directly depends on the number of events presented within the subset. If the subset 203 of events has three events, the possible different combinations are only six, and the probability of correctly arranging the events in the appropriate order without knowledge of the events is 1 / 6 or 16.6%. If the first subset 203 of events has four events, the possible different combinations are 24, and the possibility of correctly identifying the appropriate order without knowledge of the events is 1 / 24 or 4.16%. If the first subset 203 of events has five events, the possibility of correctly identifying the appropriate order is 1 / 120 or 0.83%. If the first subset 203 of events has six events, the possibility of correctly identifying the appropriate order is 1 / 720 or 0.13%.
[0032] In other examples, to further enhance security, a first generated PIN and a second generated PIN can be generated and displayed for the user to arrange in chronological order, or in a specific example, a first generated PIN, a second generated PIN, and a third generated PIN can be generated and displayed, each of which must be compared for authentication. For example, sequentially selecting the first subset 203 of events consisting of three events can reduce the probability of arranging the events in the appropriate order from 16.6% to 2.7%. Selecting the first subset 203 of events consisting of three events three times in a row can further reduce the probability of arranging the events in the appropriate order to 0.4%. Selecting four events in a row can reduce the probability of arranging the events in the appropriate order from 4.16% to 0.17%.
[0033] In FIG. 2, the first subset 203 of events includes four events, namely Event 1, Event 3, Event 6, and Event 7, with respect to the set of events 202. These events are arranged in chronological order and have time series identifiers 206 as Subsets 1 to 4 with respect to the chronological order of the first subset 203 of the selected events. In one example, the first subset 203 of events can be randomly selected and arranged in chronological order. In other examples, the first subset 203 of events can be a specific selection based on past selections that enforce one or more time rules, etc. (for example, two events in the same year but both occurring more than five years ago, i.e., two events occurring within a preset interval).
[0034] In a specific example, for presentation or display to the user, etc., the first subset 203 of the selected events can be arranged in a second subset 204 of events that includes a subset order 207 (for example, Subset 4, Subset 1, Subset 3, Subset 2 or "4132") and a position identifier 208 (for example, Display 1 to Display 4). In a specific example, the arrangement can include random rearrangement or shuffling, etc., and forces the presentation or display not to be in chronological order for the relevant points in time of each event, such as when the user is tasked with in-situ adjustment of the events (for example, not dragging from separate display areas and approval areas but performing replacement, etc.). In one example, it may be desirable to require at least one move. In other examples, chronological presentation is allowed, so that the events can be approved in the order in which they are presented.
[0035] In Figure 2, the second subset 204 of events is arranged in the order of event 7, event 1, event 6, and event 3, and provides an adjusted subset order 207 of subset 4, subset 1, subset 3, and subset 2 as display 1 to display 4 of the position identifier 208, respectively. Since subset 1 is arranged at the second display position (display 2), subset 2 is arranged at the fourth display position (display 4), subset 3 is arranged at the third display position (display 3), and subset 4 is arranged at the first display position (display 1), the custom PIN 205 can be generated from the second subset 204 of events as a relative subset order 207 of "4132" or alternatively as a subset position 209 of "2431". The custom PIN 205 can be regarded as the subset order 207 ("4132") or the subset position 209 ("2431") depending on whether the order or the position of the order is required for the recovery or identification of the custom PIN 205.
[0036] In other examples, a custom PIN can be determined, such as the arrangement of several identifiers that are not in sequential order (e.g., random arrangement), and according to the custom PIN determined for display, a subset of events can be selected for display.
[0037] Figure 3 shows an example of an authentication process 300 for recovering or identifying a generated PIN, including a display 301 configured to present a subset 304 of selected events in the order of arrangement. For example, the selected subset 304 may include the second subset 204 of the events shown in Figure 2. In a specific example, the display 301 may include a touch screen display, and the user may be instructed to drag the individual events of the selected subset 304, for example, in chronological order as a third subset 305. In this example, the user selects the first event (Display 1) at 306A, drags the selected first event to the fourth position (Subset 4) within the third subset 305 at 306B, and can correctly identify Display 1 and Subset 4. In a specific example, the system can compare the order of the third subset 305 with the order of the first subset 203 of the events in Figure 2 or an equal order based on the generated PIN, etc., and authenticate the user if they match.
[0038] As an additional challenge, if known, the user can be asked one or more other challenge questions based on the specific year or years in which one or more of the displayed or other events occurred or information regarding one or more of the displayed or other events. Instead of dragging the events to the third subset 305, in a specific example, the user can replace the position of the selected subset 304 in place without a completely separate display subset.
[0039] In one example, the display 301 may optionally include a PIN section 307 so as to display the equivalent of the PIN of the time series arrangement 308 of the third subset 305 for input by another device or the like. In other examples, the PIN section 307 may be included instead of or in addition to the third subset 305, for example, to receive from the user the time series arrangement 308 of the selected subset 304 that is input on a numeric keypad 309 or by one or more I / O components of the user device or the like. For example, the time series arrangement 308 in FIG. 3 is 2431, where the oldest event in the selected arrangement (the first event in chronological order relative to the other events in the selected subset 304) is in the second position, the second event is in the fourth position (in chronological order), the third event is in the fourth position (in chronological order), and the fourth event is in the first position.
[0040] In other examples, the display of the selected subset 304 of events can be provided by a first device, and the PIN section 307 can be input on a second device. For example, the selected subset 304 of events can be displayed to the user on a first user device (e.g., a mobile device), and the PIN section 307 can be provided on a second device for input (e.g., a POS terminal, an ATM, an application running on the second device, etc.). In a particular example, the selected subset 304 of events is provided by an authentication application on a first user device, and can be input on another application of the first user device or one or more other devices to authenticate or verify the user on the second application or the like.
[0041] In a particular example, the events displayed on an authentication application running on a user's personal user device (e.g., a mobile phone, etc.) may include more personal information than the equivalent events displayed on a web application or the like in one or more other devices such as a point-of-sale information management device.
[0042] Figure 4 shows an example of a system 400 for authentication. The system 400 includes a first device, a second device, and a third device 401-403. The first device 401 and the second device 402 include devices controlled by a user who requests an access or action that triggers authentication. The third device 401 is controlled by a third party such as a retailer's POS device or an ATM, rather than the user. Each of the first device, the second device, and the third device 401-403 can be coupled to an authentication service 110 over a network 109.
[0043] A subset 304 of the selected events as shown in Figure 3 can be displayed to the user, for example, using one or more of the first device, the second device, and the third device 401-403. In addition, a numeric keypad 309 can be optionally included in one or more of the first device, the second device, and the third device 401-403. In a particular example, the subset 304 of the selected events can be displayed on a device that includes the numeric keypad 309. In other examples, the subset 304 of the selected events can be displayed on one device, and the numeric keypad 309 can be displayed on another device.
[0044] In a particular example, the authentication service 110 can control the delivery of the subset 304 of the selected events and compare the received input with the generated PIN. In other examples, an authentication application executed on a user device can control the delivery of the subset 304 of the selected events and compare the received input with the generated PIN.
[0045] Figure 5 shows an example of a user event 500 that includes a first event 501 to a twelfth event 512, each showing various information about the user event as an icon. Alternatively, each event can be alternatively shown as a simple text description or as a combination of an icon, other image, or text description.
[0046] For example, when a user provides information about a trip to Australia at a specific time, a simple icon of a kangaroo, which is the first event 501, can be selected to represent that event. The second event 502 is an icon of a dog. Although it is unknown to a virtual attacker, the user can provide information about the dog, such as the time when the user had the dog during childhood or the first time when the user had a dog as an adult. The third event 503 may include an icon of a child, which can represent the user's own childhood or, in some cases, the birth of the user's child or the user's first grandchild, etc. Without more context, it is difficult to know the order in which the user assigned the events.
[0047] The fourth event 504 is a graduation cap. Here too, it is unknown whether the graduation belongs to the user or to a child or grandchild. The fifth event 505 is a basketball, which can represent the year when the user's favorite team won or, alternatively, the time when the user played basketball as a child. The sixth event 506 is a cake, which can represent the date of the user's wedding or, in some cases, the wedding of the user's child, etc. The remaining events 507 - 512 generally refer to icons that can have different meanings and attributable periods for different people. Without knowing the complete context and meaning of those events for the user, it is difficult even for a person with detailed knowledge about the user to determine what the chronological arrangement of the icons should be.
[0048] FIG. 6 shows an example of a method 600 for requesting a custom PIN from a user and authenticating the user using the custom PIN.
[0049] In step 601, regarding a request for access to a secure resource or the like, a request for a custom PIN can be received. This request can be received by an authentication application on the user device or, in a specific example, by an authentication service connected to the authentication application via a network.
[0050] In step 602, a custom PIN can be generated based on the set of stored events ordered by the user. The set of stored events ordered by the user can be generated, received, or stored by the authentication service, and the custom PIN can be generated using the set of stored events ordered by the user. To create a custom PIN, a subset of events can be selected and arranged, and the custom PIN can be generated using the arranged order of the selected subset of events.
[0051] In step 603, a subset of events can be selected from the set of stored events ordered by the user or the like. This subset can include a number of events less than the set, such as 3 - 5 events, 4 events, etc. In a specific example, the events can be selected randomly or selected to meet specific conditions. For example, in order to ensure that the events are not already presented to the user in chronological order (e.g., with respect to the subset), that two or more events within the subset occur within a specific time window (e.g., within 1 year, within 2 years, etc.), that the subset includes both recent events and events that are not recent events (e.g., more than 5 years ago, more than 10 years ago, etc.), or a combination thereof, specific filters or rules can be applied to the selection and arrangement.
[0052] In step 604, the selected subset can be arranged in an order other than chronological order. In one example, the arrangement can be random, but ensures that the chronological order is not presented to the user for authentication. In other examples, such as when asking the user to enter a numerical representation of the order or to move all events regardless of whether they were presented in the initial chronological order, the order can be presented as chronological for the other events within the subset.
[0053] In step 605, a custom PIN can be created using the arrangement order, etc. of a subset of the selected events. In a specific example, as described herein, the custom PIN may represent the arrangement position of an event relative to the chronological order of the events within the subset.
[0054] In step 606, the subset of events arranged at the arrangement positions used to generate the custom PIN can be displayed to the user. In one example, the display may include being performed by one or more devices according to the instructions of an authentication application or authentication service.
[0055] In step 607, in response to, for example, displaying the subset of events arranged to the user, a chronological arrangement can be received. In a specific example, presenting an event on a touch screen interface and receiving the chronological arrangement of the event (such as by replacing the position of the displayed event, dragging the event to a subset with a different chronological order from the initially displayed subset, etc.) can be used to receive the chronological arrangement by the device that displays the subset of events arranged. In other examples, the chronological arrangement may include a numerical response to the provided display, using the device that displays the subset of events arranged or using one or more other devices individually.
[0056] In step 608, the received chronological arrangement can be compared with the generated custom PIN to determine whether the received chronological arrangement matches or is equivalent to the generated custom PIN. In one example, the received chronological arrangement may include the received position of the displayed event. Based on the received chronological arrangement, a received PIN can be created. In other examples, the received chronological arrangement may include a numerical representation of the received chronological arrangement that includes or is equivalent to the received PIN. The received PIN can be compared with the custom PIN.
[0057] For example, in step 608, if the received time series arrangement does not match the generated custom PIN, the method can proceed to step 609 and optionally determine whether the authentication attempt has timed out. In one example, if the time required for the user to provide the time series arrangement exceeds a threshold, the authentication attempt can time out. In other examples, if the time series arrangement fails multiple times, the authentication attempt can time out. In certain examples, such as when enhanced security is required, the user may have to pass multiple authentication attempts to be authenticated. In certain examples, step 609 can be performed before step 608, such as as part of step 607 or immediately after it, by determining the time it takes for the user to provide the time series arrangement and the method of receiving the time series arrangement.
[0058] In other examples, the time until a time series arrangement is received after displaying an arranged subset of events can determine whether the user must succeed in multiple authentication attempts to proceed. For example, if the threshold for receiving a time series arrangement from the user after displaying an authentication timer or an arranged subset of events is 20 seconds, a match response less than a first sub-threshold (e.g., 10 seconds, etc.) may authenticate the user, while a match response between the first sub-threshold and the authentication timer (e.g., 10 seconds to 20 seconds, etc.) may require repeating the authentication attempt before authentication succeeds. The times disclosed herein are exemplary, and in other examples, other time thresholds of the same or other ratios can be used.
[0059] If the authentication attempt times out, such as by exceeding the authentication timer, or fails more than a threshold number of times, the authentication attempt can fail in step 610. In certain examples, each authentication attempt can include using a different subset of events and thus a different custom PIN.
[0060] If the received time series configuration matches the generated custom PIN at step 608, the user can be authenticated at step 611 and access to the requested resource can be provided, or an indication that authentication has succeeded can be provided to the requested resource.
[0061] Method 600 can be executed by the user device, by the authentication service, or by a combination thereof, such as using an authentication application, executed on the user device and connected to the authentication service, by an authentication server, etc.
[0062] FIG. 7 shows an example of method 700 for receiving user event information, generating and storing a set of user events, using an authentication application or an authentication service, etc.
[0063] At step 701, event information from or about the user can be received. In a particular example, the event information can be received by an authentication application of the user device or, in a particular example, by an authentication service, etc., connected to the authentication application via a network. In one example, specific user information can be received from a user profile, etc., stored by a database. In other examples, user information, such as that provided by the user in response to a query (e.g., a set of questions, a question library, etc.) presented using a display, can be received from the user. In a particular example, the event information can include keywords related to individual events, or icons or representative images of individual events, and in a particular example, can include individual dates associated with each of the individual events.
[0064] In step 702, events can be generated using the received user information. In a specific example, event icons can be detected, such as using a library of general-purpose icons. In one example, draft events can be presented to the user for approval, modification, or confirmation. In other examples, a library of general-purpose icons can be presented to the user for selection. Additionally, using the information received from the user, or by arranging the icons or event information selected or approved by the user in chronological order from the oldest to the newest, the chronological order of the generated events can be determined such that it is for other generated events such as sets, subsets, etc.
[0065] In step 703, the generated set of events is stored in chronological order as a set of events stored ordered by the user and can be used as discussed herein.
[0066] FIG. 8 shows an example of a system 800 including a first user device 801 and a second user device 811 in a network environment including an authentication service 810 and a user database 835 communicating on a network 809.
[0067] The first user device 801 is exemplary and can include a processor 802 (e.g., one or more processors), a memory 803, a transceiver 805, input / output (I / O) components 806, one or more presentation components 807, and one or more I / O ports 808. The first user device 801 can take the form of a mobile computing device or other portable device such as a cellular phone, laptop, tablet, computing pad, notebook, gaming device, portable media player, etc. In other examples, the first user device 801 can include less portable devices such as a desktop personal computer, kiosk, desktop device, industrial control device, etc. Other examples can incorporate the first user device 801 as part of a multi-device system where two separate physical devices share or otherwise provide access to the illustrated components of the first user device 801.
[0068] The processor 802 may include any number of processing units and is programmed to execute computer-executable instructions for implementing aspects of the present disclosure. These instructions may be executed by a processor or multiple processors within the computing device or by a processor external to the first user device 801. In some examples, the processor 802 is programmed to execute methods such as one or more of the methods illustrated herein. Additionally or alternatively, the processor 802 may be programmed to present an experience within a user interface (“UI”). For example, the processor 802 may represent an implementation of a technique for performing the operations described herein.
[0069] The transceiver 805 may include an antenna capable of transmitting and receiving radio frequency (“RF”) signals, various antennas, and corresponding chip sets to provide a communication function between the first user device 801 and one or more other remote devices. However, the example is not limited to the RF signal scheme since various other communication modes may be used instead.
[0070] The prompt component 807 may include, without limitation, a computer monitor, a television, a projector, a touch screen, a telephone display, a tablet display, a screen of a wearable device, a television, a speaker, a vibration device, and any other device configured to display image search results, convey them verbally, or indicate them in another way to the user of the first user device 801, or to provide information visually or auditorily on the first user device 801. For example, the first user device 801 may include a smartphone or a mobile tablet including a speaker capable of reproducing audible search results for the user. In another example, the first user device 801 may include an in-vehicle computer that audibly presents a search response through an in-vehicle speaker system, an in-vehicle computer that visually presents a search response on an in-vehicle display screen (e.g., one within the vehicle's dashboard, within a headrest, or a pull-out screen, etc.), or a combination thereof. Another example is to present the disclosed search results through various other display or audio presentation components 807.
[0071] The I / O port 808 enables the first user device 801 to be logically coupled to other devices and I / O components 816, some of which may be incorporated into the user device 801 and others may be external. The I / O component 806 may include a microphone 823, one or more sensors 824, a camera 825, and a touch device 826. The microphone 823 can capture speech from the user and / or speech by or of the user. The sensors 824 can include an accelerometer, a magnetometer, a pressure sensor, a photometer, a thermometer, a Global Positioning System (GPS) chip or circuit, a bar scanner, a biometric scanner for scanning fingerprints, palm prints, blood, eyeballs, etc., a gyroscope, a Near Field Communication (NFC) receiver, or any other sensors configured to capture data from the user or the environment, including any number of sensors on or included in a mobile computing device, an electronic toy, a gaming console, a wearable device, a television, a vehicle, or other user devices 801. The camera 825 can capture an image or video of or by the user. The touch device 826 can include a touch pad, a track pad, a touch screen, or other touch capture devices. In other examples, the I / O component 806 may include one or more of a sound card, a vibration device, a scanner, a printer, a wireless communication device, or any other components configured to capture information related to the user or the environment.
[0072] Memory 803 can include any amount of memory associated with or accessible by the first user device 801. Memory 803 can be internal to the first user device 801, external to the first user device 801, or a combination thereof. Memory 803 can include random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory, or other memory technologies, CDROM, digital versatile disk (DVD), or other optical or holographic media, magnetic cassettes, magnetic tapes, magnetic disk storage, or other magnetic storage devices, memory wired to an analog computing device, or any other medium for encoding desired information and accessible by the first user device 801 without limitation. The terms computer-readable medium, machine-readable medium, and storage device do not include carrier waves as long as the carrier waves are considered to be overly transient. Memory 803 can take the form of volatile and / or non-volatile memory, can be removable, non-removable, or a combination thereof, and can include various hardware devices, such as solid state memory, hard drives, optical disk drives, etc. Additionally or alternatively, in a virtualized environment where the processing of instructions is executed on a plurality of the first user devices 801, memory 803 can be distributed among a plurality of user devices. Memory 803 can store various device applications that, when executed by the processor 802, operate to perform functions on the first user device 801, among other data. Examples of applications can include search applications, instant messaging applications, email application programs, web browsers, calendar application programs, address book application programs, messaging programs, media applications, location information services, search programs, etc. The applications can communicate with corresponding applications or services, such as web services accessible via the network 809.For example, the application may include a client operating application corresponding to a server-side application that runs on a remote server or computing device within the cloud.
[0073] The instructions stored in the memory 803 may include, among other things, one or more of an authentication application 804, a communication application 821, and a user interface application 822 that run on the first user device 801. The communication application 821 may include one or more computer-executable instructions for operating a network interface card and one or more drivers for operating the network interface card. Communication between the first user device 801 and other devices may be performed using any protocol or mechanism over a wired or wireless connection or across the network 809. In some examples, the communication application 821 is operable with RF and short-range communication technologies that use electronic tags such as NFC tags, Bluetooth® brand tags, and the like.
[0074] In some examples, the user interface application 822 includes a graphic application for displaying data to the user and receiving data from the user. The user interface application 822 may include computer-executable instructions for operating a graphics card to display search results and corresponding images or utterances on or by the presentation component 807. The user interface application 822 can interact with various sensors 824 and a camera 825 for both capturing and presenting information by the presentation component 807.
[0075] The authentication service 810 may be configured to receive user data and environmental data such as that received on the network 809 from the first user device 801 and the second user device 811 or one or more other devices. In a particular example, the authentication service 810 may include one or more servers, memories, databases, or processors configured to execute computer-executable instructions of various web services, and may be configured to provide and manage one or more authentication services for one or more users or user groups such as the users of the first user device 801 and the second user device 811. The authentication service 810 may be capable of providing and receiving messages or other information including images, videos, audio, text, and other communication media on the network 809 between the first user device 801 and the second user device 811.
[0076] The network environment shown in FIG. 8 is an example of a suitable computing system environment and is not intended to suggest any limitation as to the scope of use or functionality of the examples disclosed herein. The illustrated network environment should not be construed as having any dependency or requirement related to any single component, module, index, or combination thereof, and other network environments may be envisioned in other examples.
[0077] The network 809 may include the Internet, a private network, a local area network (LAN), a wide area network (WAN), or any other computer network including various network interfaces, adapters, modems, and other network devices for communicatively connecting the first user device 801 and the second user device 811 to the authentication service 810. The network 809 may also include a configuration for point-to-point connections.
[0078] The authentication service 810 includes a processor 812 that processes executable instructions, a memory 813 that is embodied with the executable instructions, and a transceiver 815 for communicating on a network 809. The memory 813 may include one or more of an authentication application 814, a communication application 831, a stored event application 832, a selection application 833, a PIN application 834, or one or more other applications, modules, or devices, etc. Although the authentication service 810 is illustrated as a single box, it is not so limited and is extensible. For example, the authentication service 810 may include multiple servers that operate various portions of software that collectively generate composite icons or templates for users of a first user device 801 and a second user device 811.
[0079] The user database 835 can be accessed on the network 809 by the authentication service 810 or the first user device 801 and can provide backend storage for web, user, and environmental data that can be used by the authentication service 810 to combine subsequent data within a communication stream. The web, user, and environmental data stored within the database can include, for example, one or more user profiles 836 and user events 837 without limitation. The user events 837 can include one or more events and associated times for or related to a particular date or range of dates, as well as a textual description, or summary image, or icon of such events. Additionally, although not illustrated for clarity, the server of the user database 835 can include its own processor, transceiver, and memory. Further, the network environment is depicted as a collection of devices separate from the authentication service 810. However, in an example, the web, user, and environmental data discussed above shown within the user database 835 can be stored on the authentication service 810.
[0080] The user profile 836 may include an electronically stored collection of information related to the user. Such information may be stored based on the user's explicit consent or an "opt-in" to the storage of such personal information, and the information includes the user's name, age, gender, height, weight, demographics, current location, place of residence, nationality, family, friends, education, occupation, hobbies, skills, interests, web searches, health information, birthday, anniversary, holiday, mood, the user's physical condition, and any other personalized information related to the user. The user profile includes static profile elements, such as name, place of birth, etc., and dynamic profile elements that change over time, such as place of residence, age, physical condition, etc. The user profile may be constructed by scrutinizing questions to the user or analyzing the user's behavior on one or more user devices. The user event 837 may, in certain instances, include information regarding an individual user's personal event, including information from the user profile or other information related to or from the user as described above.
[0081] In addition, the user profile 836 may include static and / or dynamic data parameters related to an individual user. Examples of user profile data include, without limitation, the user's age, gender, race, name, location, interests, web search history, social media connections and interactions, purchase history, daily activities, occupation, or virtually any unique data point specific to the user. The user profile 836 may be extended to encompass various other aspects of the user.
[0082] The present disclosure relates to systems and methods for providing command-based personalized composite templates within a communication stream, by way of examples provided in at least the following sections. (A1)In one aspect, some embodiments or examples involve generating a custom personal identification number (PIN) for a user in response to receiving a request for a custom PIN, based on a set of stored events, where each event is associated with a time point, and generating includes selecting a subset of events from the set of stored events, determining a chronological order of the selected subset of events based on the respective associated time points of the selected subset of events, and assigning a chronological identifier representing the position of each event in the determined chronological order to each of the selected subset of events, and determining the custom PIN as an arrangement of the chronological identifiers in an order other than chronological order, and presenting the selected subset of events to the user in an arranged order, and in response to presenting the selected subset of events to the user, receiving an indication of the chronological arrangement of the selected subset of events from the user, and authenticating the user in response to determining that the received indication of the chronological arrangement matches the determined custom PIN, including determining a custom PIN for the user based on an ordered series of events. (A2)In some embodiments of A1, determining the custom PIN as an arrangement of the chronological identifiers includes determining the custom PIN as a random arrangement of the chronological identifiers in an order other than chronological order. (A3)In some embodiments of A1 - A2, some embodiments or examples include receiving event information from the user, using the received event information to generate a set of events and the chronological order of the set of events to be stored, and storing the generated set of events in chronological order as the set of events to be stored. (A4)In some embodiments of A1 - A3, some embodiments or examples include presenting a first set of questions to the user through a display, and receiving the event information includes receiving responses to the provided set of questions. In some embodiments of (A5) A1 - A4, the custom PIN has a digit count greater than 2, and determining the custom PIN involves using the order of arrangement of a subset of the selected events. In some embodiments of (A6) A1 - A5, selecting a subset of events includes selecting three or more of the stored events, including selecting two of the stored events that occurred within a threshold time or within a threshold position in a set of stored events. In some embodiments of (A7) A1 - A6, presenting the selected subset of events to the user includes presenting to the user an image representing each of the selected subset of events in the order of the selected subset of events. Receiving an indication of the time - series arrangement includes receiving a sequence of positions in the time - series order of the presented selected subset of events. Determining that the received indication of the time - series arrangement matches the custom PIN includes determining that the sequence of positions in the received time - series order of the presented selected subset of events matches the custom PIN. In some embodiments of (A8) A1 - A7, receiving an indication of the time - series arrangement includes receiving, by number, the order of the presented selected subset of events. Determining that the received indication of the time - series arrangement matches the custom PIN includes determining that the received order in the numbers of the presented selected subset of events matches the custom PIN. Authenticating the user includes providing the user access to the requested resource or providing an indication of the user's authentication to the requested resource. In some embodiments of (A9) A1 - A8, the received order includes a user - input number based on the presented selected subset of events. Authenticating the user includes comparing the determined custom PIN with the received user - input number and, in response to determining that the determined custom PIN matches the received user - input number based on the comparison, providing an indication of the user's authentication. (A10)In some embodiments of A1 - A9, authenticating a user involves receiving a time - series arrangement within a presentation threshold time for presenting a subset of selected events to the user, and in response to the received time - series arrangement matching a determined custom PIN.
[0083] In yet another aspect, some embodiments include a system comprising a processor and a memory device coupled to the processor and storing a program for the processor to perform operations including any of the embodiments of A1 - A9 above in various combinations or permutations. In yet another aspect, some embodiments include a non - transitory computer - readable storage medium storing one or more programs for execution by one or more processors of a storage device, the one or more programs including instructions for performing any of the embodiments of A1 - A9 above in various combinations or permutations. In yet another aspect, some embodiments include a method or system including means for performing any of the embodiments of A1 - A9 above in various combinations or permutations.
[0084] In the above, several embodiments have been described in detail, but other modifications are possible. For example, the illustrated logical flow does not require the specific order or sequential order shown to achieve the desired result. Other steps may be added or steps may be deleted from the described flow, and other components may be added to or removed from the described system. Other embodiments may also be included within the scope of the appended claims.
[0085] In the description herein, reference has been made to the accompanying drawings which form a part hereof and which illustrate specific embodiments as examples for practicing the invention. These embodiments have been described in sufficient detail to enable those skilled in the art to practice the invention, and it is to be understood that other embodiments may be utilized and structural, logical, and electrical changes may be made without departing from the scope of the invention. Accordingly, the description of the example embodiments included should not be construed in a limiting sense, and the scope of the invention is defined by the appended claims.
[0086] The functions can be configured to perform operations using, for example, software, hardware, firmware, etc. For example, the phrase "configured to ~" can refer to the logical circuit structure of the hardware elements implementing the related functions. The phrase "configured to ~" can also refer to the logical circuit structure of the hardware elements implementing the coding design of the related functions of the firmware or software. The term "module" refers to a structural element that can be implemented using any suitable hardware (e.g., especially a processor), software (e.g., especially an application), firmware, or any combination of hardware, software, and firmware. The term "logic" encompasses any function for performing a task. For example, each operation shown in the flowchart corresponds to the logic for performing that operation. The operation can be executed using software, hardware, firmware, etc. Terms such as "component", "system", etc. can refer to computer-related entities, hardware, and software in execution, firmware, or combinations thereof. A component can be a process, object, executable file, program, function, subroutine, computer, or a combination of software and hardware running on a processor. The term "processor" can refer to a hardware component such as a processing unit of a computer system.
[0087] Furthermore, the subject matter recited in the claims can be implemented as a method, apparatus, or article of manufacture using standard programming and engineering techniques to produce software, firmware, hardware, or any combination thereof to control a computing device to implement the disclosed subject matter. As used herein, the term "article of manufacture" is intended to include a computer program accessible from any computer-readable storage device or medium. Computer-readable storage media can include, but are not limited to, magnetic storage devices, such as hard disks, floppy disks, magnetic strips; optical disks, such as compact disks (CDs), digital versatile disks (DVDs); smart cards; flash memory devices. In contrast, computer-readable media that are not storage media may additionally include communication media, such as transmission media for wireless signals, and the like.
Claims
1. A system for determining a custom personal identification number (PIN) for a user based on a sequence of events, One or more processors, Memory, which, when executed, is used by one or more processors, In response to receiving a request for the custom PIN, the process involves generating the custom PIN for the user based on a stored set of events, where each event in the stored set of events relates to the time when the event occurred, and the process involves generating the custom PIN. Selecting a subset of events from the aforementioned stored set of events, For each of the selected subsets of events, the chronological order of the selected subset of events is determined based on the relevant time point in which the event occurred, and a chronological identifier representing the position of each event in the determined chronological order is assigned to each of the selected subsets of events. The custom PIN is determined as the arrangement of the assigned time-series identifiers in a non-chronological order. Including generating, To present the user with a subset of the selected events in the order described above, In response to presenting the user with a subset of the selected events, the system receives a series of numbers from the user as instructions for the chronological arrangement of the subset of events according to the order or position of the subset of events, Authenticating the user in response to determining that a series of numbers representing the received time-series arrangement matches the determined custom PIN, wherein the time-series arrangement includes the determined custom PIN or includes a numerical representation of a time-series arrangement that is equivalent thereto. A memory that stores computer executable instructions that cause the system to perform operations including the above, A system that includes this.
2. The system according to claim 1, wherein determining the custom PIN as the arrangement of the time series identifiers includes determining the custom PIN as a random arrangement of the time series identifiers in an order that is not in chronological order.
3. The aforementioned operation is, Receiving event information from the aforementioned user, Using the received event information, generate a set of events and a chronological order of the stored set of events, The set of events to be stored is to store the set of generated events in the chronological order. The system according to claim 1, including the following:
4. The operation includes presenting the first set of questions to the user through the display, The system according to claim 3, wherein receiving event information includes receiving responses to a first set of questions provided.
5. The aforementioned custom PIN has more than 2 digits, The system according to claim 1, wherein determining the custom PIN includes using the arrangement order of the selected subset of events.
6. The system according to claim 1, wherein selecting a subset of the events includes selecting three or more sets of the stored events, including selecting two sets of the stored events that occurred within a threshold time or within a threshold position in the set of stored events.
7. Presenting a subset of the selected events to the user includes presenting images representing each of the subsets of the selected events to the user in the order of the subsets of the selected events. Receiving the instructions for the time-series arrangement includes receiving a sequence of positions in time order of the subset of the presented selected events, The system according to claim 1, wherein determining that the received time-series arrangement instruction matches the custom PIN includes determining that the sequence of positions of the presented subset of selected events in the received time-series order matches the custom PIN.
8. Receiving the instructions for the aforementioned time-series arrangement includes receiving the order of the presented subset of selected events by number, Determining that the received time-series arrangement instruction matches the custom PIN includes determining that the received order in the numbering of the subset of selected events presented matches the custom PIN. The system according to claim 1, wherein authenticating the user includes providing the user with access to the requested resource or providing the requested resource with instructions for authenticating the user.
9. The received order includes user input numbers based on the subset of the selected events presented, Authenticating the aforementioned user is The determined custom PIN is compared with the received user input number. In response to determining, based on the comparison, that the determined custom PIN matches the received user input number, instructions for user authentication are provided. The system according to claim 8, including the above.
10. The system according to claim 1, wherein authenticating the user includes receiving the time-series arrangement within a presentation threshold time that causes the user to be presented with a subset of the selected events, and the received time-series arrangement matches the determined custom PIN.
11. A method for determining a custom Personal Identifier (PIN) for a user based on a sequence of events, In response to receiving a request for the custom PIN, the process involves generating the custom PIN for the user based on a set of stored events, wherein each event in the set of stored events relates to a specific point in time, and the generation is performed accordingly. Selecting a subset of events from the aforementioned stored set of events, For each of the selected subsets of events, the chronological order of the selected subset of events is determined based on the relevant time point, and a chronological identifier representing the position of each event in the determined chronological order is assigned to each of the selected subsets of events. The custom PIN is determined as the arrangement of the assigned time-series identifiers in a non-chronological order. Including generating, To present the user with a subset of the selected events in the order described above, In response to presenting the user with a subset of the selected events, the system receives a series of numbers from the user as instructions for the chronological arrangement of the subset of events according to the order or position of the subset of events, Authenticating the user in response to determining that a series of numbers representing the received time-series arrangement matches the determined custom PIN, wherein the time-series arrangement includes the determined custom PIN or includes a numerical representation of a time-series arrangement that is equivalent thereto. A method that includes this.
12. The method according to claim 11, wherein determining the custom PIN as the arrangement of the time series identifiers includes determining the custom PIN as a random arrangement of the time series identifiers in an order that is not in chronological order.
13. Receiving event information from the aforementioned user, Using the received event information, generate a set of events and a chronological order of the stored set of events, The set of events to be stored is to store the set of generated events in the chronological order. The method according to claim 11, including the method described in claim 11.
14. The aforementioned custom PIN has more than 2 digits, The method according to claim 11, wherein determining the custom PIN involves using the arrangement order of the selected subset of events.
15. The method according to claim 11, wherein selecting a subset of the events includes selecting three or more sets of the stored events, including selecting two sets of the stored events that occurred within a threshold time or within a threshold position in the set of stored events.
16. Presenting a subset of the selected events to the user includes presenting images representing each of the subsets of the selected events to the user in the order of the subsets of the selected events, Receiving the instructions for the time-series arrangement includes receiving a sequence of positions in time order of the subset of the presented selected events, The method according to claim 11, wherein determining that the received time-series arrangement instruction matches the custom PIN includes determining that the sequence of positions of the presented subset of selected events in the received time-series order matches the custom PIN.
17. Receiving the instruction for the time-series arrangement includes receiving the order of the selected subset of the presented events by number, Determining that the received time-series arrangement instruction matches the custom PIN includes determining that the received order in the numbering of the subset of selected events presented matches the custom PIN. The method according to claim 11, wherein authenticating the user includes providing the user with access to the requested resource or providing the requested resource with instructions for authenticating the user.
18. The received order includes user input numbers based on the subset of the presented selected events, Authenticating the aforementioned user is The determined custom PIN is compared with the received user input number. In response to determining, based on the comparison, that the determined custom PIN matches the received user input number, instructions for user authentication are provided. The method according to claim 17, including the method described in claim 17.
19. The method according to claim 11, wherein authenticating the user includes receiving the time series arrangement within a presentation threshold time that causes the user to be presented with a subset of the selected events, and the received time series arrangement matches the determined custom PIN.
20. A system for determining a custom personal identification number (PIN) for a user based on a sequence of ordered events, Processor and It is memory, A module that, in response to receiving a request for the custom PIN, generates the custom PIN for the user based on a set of stored events, wherein each event in the set of stored events relates to a certain point in time, and the generating module, Select a subset of events from the aforementioned stored set of events, For each of the selected subsets of events, determine the chronological order of the selected subset of events based on the relevant time point, and assign a chronological identifier to each of the selected subsets of events that represents the position of each event in the determined chronological order. The custom PIN is determined as the arrangement of the assigned time-series identifiers in a non-chronological order. The modules to be generated, including the modules themselves, A module that presents a subset of the selected events to the user in the order of arrangement, A module that, in response to presenting the user with a subset of the selected events, receives a series of numbers from the user as instructions for the chronological arrangement of the subset of events according to the order or position of the subset of events, A module that authenticates the user in response to determining that a series of numbers representing the received time-series arrangement matches the determined custom PIN, wherein the time-series arrangement includes the determined custom PIN or a numerical representation of the time-series arrangement that is equivalent thereto. memory including A system equipped with these features.