Enhanced security authentication system

US10623402B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10623402-B2
Application numberUS-201715492968-A
CountryUS
Kind codeB2
Filing dateApr 20, 2017
Priority dateApr 20, 2017
Publication dateApr 14, 2020
Grant dateApr 14, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method, a computer system, and a computer program product for authenticating a transaction are provided. An authentication system receives the transaction over a particular channel of a plurality of support channels. A risk score is determined for the transaction based on a number of contextual risk factors. An authentication scheme is determined from a number of authentication schemes for authenticating an identity of the user within an authentication context. The authentication scheme is determined based on the particular channel and the risk score. In response to successfully authenticating the identity of the user within the authentication context, the authentication system determines whether the transaction is a permitted transaction based on an assurance level associated with the authentication context. In response to determining that the transaction is the permitted transaction, the transaction is authenticated.

First claim

Opening claim text (preview).

What is claimed is: 1. A method, comprising: authenticating transactions of a user across multiple interaction channels using an authentication service executing on a computer system, the authentication service: receiving a first transaction over a first interaction channel, wherein the first interaction channel is one of the multiple interaction channels; determining a numeric risk score for the first transaction based on a number of contextual risk factors; determining a first authentication scheme from a number of authentication schemes for authenticating an identity of the user within a first authentication context, wherein the first authentication scheme is determined based on the first interaction channel and the numeric risk score; using the first authentication scheme to authenticate the identity of the user within the first authentication context; in response to successfully authenticating the identity of the user within the first authentication context, determining whether the first transaction is a permitted transaction based on an assurance level associated with the first authentication context; in response to determining that the first transaction is the permitted transaction, authenticating the first transaction; receiving a second transaction over a second interaction channel, wherein: the second interaction channel is one of the multiple interaction channels; and the second interaction channel is different than the first interaction channels; and using a second authentication scheme to authenticate the user within a second authentication context different than the first authentication context, wherein the second authentication scheme is a same authentication scheme as the first authentication scheme. 2. The method of claim 1 , wherein the multiple interaction channels include a web-based authentication channel, a mobile authentication channel, a biometric authentication channel, a voice channel, and a risk-based authentication channel. 3. The method of claim 1 , wherein the same authentication context is selected from an identity management context, an organizational context, and a social context. 4. The method of claim 1 , wherein authenticating the transactions further includes the authentication service: identifying the number of contextual risk factors based on context parameters of the first transaction; and wherein the context parameters include a transaction type, and at least one of a current authentication context, a time of day that the first transaction is received, a geographic location from which the first transaction is received, a device type used by the user to submit the first transaction, prior access behavioral patterns of the user, a keyword, and a quality of network. 5. The method of claim 4 , wherein the transaction type is selected from a lookup transaction, the transaction for authenticating the user, and managing privileges of an account of the user. 6. The method of claim 4 , wherein the first transaction is a lookup transaction, and further comprising the authentication service: identifying a number of accounts based on information and the context parameters of the first transaction; returning an authentication prompt for information to disambiguate a user account from the number of accounts; and using the same authentication scheme to authenticate the identity of the user within the first authentication context, wherein the first authentication context is associated with the user account. 7. The method of claim 6 , wherein the number of accounts comprises the user account, a second account of the user, an account of a different user, and combinations thereof. 8. The method of claim 4 , wherein determining the first authentication scheme further comprises: determining the first authentication scheme from the number of authentication schemes based on the first interaction channel, the numeric risk score, and a policy associated with a user profile. 9. The method of claim 8 , wherein the policy is based on one or more of a user preference, a risk level, and an organizational preference. 10. The method of claim 8 , further comprising the authentication service: receiving the first transaction over the first interaction channel, wherein the first transaction includes the keyword that is associated with the user, wherein the keyword comprises one or more of a username, an email address, a name of an employer, a client identifier, or a company registration code; determining the user profile for the user based on the keyword; and returning an authentication prompt for credentials to authenticate the user according to the same authentication scheme. 11. The method of claim 1 , wherein authenticating the transactions further includes the authentication service: generating a token in response to successfully authenticating the identity of the user within the first authentication context; sending the token to a user device; and storing the token on the user device, wherein the second transaction, is authenticated using the stored token with the second authentication context. 12. The method of claim 1 , wherein authenticating the transactions further includes the authentication service: in response to determining that the first transaction is not the permitted transaction based on an identity assurance level of the first authentication context, determining a step-up authentication scheme for authenticating the identity of the user within a step-up authentication context, wherein the first transaction is the permitted transaction based on an identity assurance level associated with the step-up authentication context; and returning an authentication prompt for credentials to authenticate the identity of the user according to the step-up authentication scheme. 13. A computer system comprising: a hardware processor; and an authentication system in communication with the hardware processor, the authentication system consistently authenticating a user across multiple interaction channels by: a first authentication for a first interaction channel for the user performed by: receiving a first transaction over the first interaction channel, wherein the first interaction channel is one of the multiple interaction channels; determining a risk score for the first transaction based on a number of contextual risk factors; determining an authentication scheme from a number of authentication schemes for authenticating an identity of the user within a first authentication context, wherein the authentication scheme is determined based on the first interaction channel and the risk score; using the authentication scheme to authenticate the identity of the user within the first authentication context; in response to successfully authenticating the identity of the user within the first authentication context, determining whether the first transaction is a permitted transaction based on an assurance level associated with the first authentication context, wherein the assurance level is a classification of a certainty of identity that is selected based on the first authentication context; and in response to determining that the first transaction is the permitted transaction, authenticating the first transaction; and a second authentication for a second interaction channel for the user performed by: receiving a second transaction over the second interaction channel, wherein: the second interaction channel is one of the multiple interaction channels; and the second interaction channel is different than the first interaction channel; and using the authentication scheme to authenticate the identity of t

Assignees

Inventors

Classifications

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • Vulnerability analysis · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • using biometrical features, e.g. fingerprint, retina-scan (cryptographic mechanisms or cryptographic arrangements for entity authentication using biological data H04L9/3231) · CPC title

  • Electricity · mapped topic

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10623402B2 cover?
A method, a computer system, and a computer program product for authenticating a transaction are provided. An authentication system receives the transaction over a particular channel of a plurality of support channels. A risk score is determined for the transaction based on a number of contextual risk factors. An authentication scheme is determined from a number of authentication schemes for au…
Who is the assignee on this patent?
Adp Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/0853. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 14 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).