Preventing unauthorized access to secure information systems using multi-push authentication techniques

US10855686B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10855686-B2
Application numberUS-201815948245-A
CountryUS
Kind codeB2
Filing dateApr 9, 2018
Priority dateApr 9, 2018
Publication dateDec 1, 2020
Grant dateDec 1, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Aspects of the disclosure relate to preventing unauthorized access to secured information systems using multi-push authentication techniques. A computing platform may receive an event request associated with a group of enrolled devices. The computing platform may load multi-push settings and identify one or more user devices linked to the group of enrolled devices. Then, the computing platform may generate one or more notifications for the one or more user devices, and each notification may be generated for a corresponding user device based on device-specific user account state information. After sending the one or more notifications, the computing platform may generate one or more event execution commands based on prompt response information received from the one or more user devices and may send the one or more event execution commands to an event management computer system, which may execute an event corresponding to the event request.

First claim

Opening claim text (preview).

What is claimed is: 1. A computing platform, comprising: at least one processor; a communication interface communicatively coupled to the at least one processor; and memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, from a requesting device, an event request associated with a group of enrolled devices; based on receiving the event request associated with the group of enrolled devices from the requesting device, load multi-push settings associated with the group of enrolled devices; identify one or more user devices linked to the group of enrolled devices based on the multi-push settings associated with the group of enrolled devices; generate one or more notifications for the one or more user devices linked to the group of enrolled devices, wherein each notification of the one or more notifications is generated for a corresponding user device of the one or more user devices linked to the group of enrolled devices based on device-specific user account state information maintained by the computing platform, and wherein generating the one or more notifications for the one or more user devices linked to the group of enrolled devices comprises: generating a first notification for a first user device of the one or more user devices linked to the group of enrolled devices based on first user account state information corresponding to the first user device, wherein sending the first notification to the first user device causes the first user device to require a first set of authenticators when authenticating a user of the first user device; and generating a second notification for a second user device of the one or more user devices linked to the group of enrolled devices based on second user account state information corresponding to the second user device, wherein sending the second notification to the second user device causes the second user device to require a second set of authenticators when authenticating a user of the second user device, wherein the second user account state information is different from the first user account state information, and wherein the second set of authenticators is different from the first set of authenticators; send, via the communication interface, to the one or more user devices linked to the group of enrolled devices, the one or more notifications generated for the one or more user devices linked to the group of enrolled devices; generate one or more event execution commands based on prompt response information received from the one or more user devices linked to the group of enrolled devices; and send, via the communication interface, to an event management computer system, the one or more event execution commands generated based on the prompt response information received from the one or more user devices linked to the group of enrolled devices, wherein sending the one or more event execution commands to the event management computer system causes the event management computer system to execute an event corresponding to the event request associated with the group of enrolled devices received from the requesting device. 2. The computing platform of claim 1 , wherein sending the one or more notifications generated for the one or more user devices linked to the group of enrolled devices comprises concurrently sending the one or more notifications to the one or more user devices linked to the group of enrolled devices. 3. The computing platform of claim 1 , wherein sending the one or more notifications generated for the one or more user devices linked to the group of enrolled devices comprises sequentially sending the one or more notifications to the one or more user devices linked to the group of enrolled devices. 4. The computing platform of claim 3 , wherein sending the one or more notifications generated for the one or more user devices linked to the group of enrolled devices comprises sending the one or more notifications to the one or more user devices linked to the group of enrolled devices in a specific order based on the multi-push settings associated with the group of enrolled devices. 5. The computing platform of claim 1 , wherein generating the one or more event execution commands based on the prompt response information received from the one or more user devices linked to the group of enrolled devices comprises generating the one or more event execution commands based on a quorum of the one or more user devices linked to the group of enrolled devices approving the event request. 6. The computing platform of claim 1 , wherein generating the one or more event execution commands based on the prompt response information received from the one or more user devices linked to the group of enrolled devices comprises generating the one or more event execution commands based on all of the one or more user devices linked to the group of enrolled devices approving the event request. 7. The computing platform of claim 1 , wherein sending the one or more notifications to the one or more user devices linked to the group of enrolled devices comprises sending the first notification to the first user device, and wherein sending the first notification to the first user device causes the first user device to present information associated with the first notification, authenticate the user of the first user device, present a first prompt corresponding to the event request, and send first prompt response information to the computing platform. 8. The computing platform of claim 7 , wherein sending the one or more notifications to the one or more user devices linked to the group of enrolled devices comprises sending the second notification to the second user device, and wherein sending the second notification to the second user device causes the second user device to present information associated with the second notification, authenticate the user of the second user device, present a second prompt corresponding to the event request, and send second prompt response information to the computing platform. 9. The computing platform of claim 8 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, from the first user device, validation information associated with the user of the first user device being authenticated. 10. The computing platform of claim 9 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, from the first user device, the first prompt response information; and update event request state information based on receiving the first prompt response information from the first user device. 11. The computing platform of claim 10 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, from the second user device, validation information associated with the user of the second user device being authenticated. 12. The computing platform of claim 11 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: receive, via the communication interface, from the second user device, the second prompt response information; and update the event request state information based on receiving the second prompt response information from

Assignees

Inventors

Classifications

  • Push-based network services · CPC title

  • H04L63/104Primary

    Grouping of entities · CPC title

  • using one-time-passwords · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10855686B2 cover?
Aspects of the disclosure relate to preventing unauthorized access to secured information systems using multi-push authentication techniques. A computing platform may receive an event request associated with a group of enrolled devices. The computing platform may load multi-push settings and identify one or more user devices linked to the group of enrolled devices. Then, the computing platform …
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification H04L63/104. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 01 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).