Safe logon

US11924191B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11924191-B2
Application numberUS-202117519049-A
CountryUS
Kind codeB2
Filing dateNov 4, 2021
Priority dateJul 23, 2019
Publication dateMar 5, 2024
Grant dateMar 5, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods, computer-readable media, software, and apparatuses are provided to assist a user and vendor in completing an online trusted transaction. Trusted vendor websites are verified and user identities are confirmed through a cyber-security safe logon credentialing system. The vendor can be confident that the user identity has been verified to be who they say they are and the user can be confident that they are using a trusted verified vendor website.

First claim

Opening claim text (preview).

What is claimed is: 1. An apparatus, comprising: one or more processors configured to: receive a login request, resulting from activation of a login button displayed on a requesting site, to perform a transaction between a user and the requesting site; access a previously stored database record associated with the requesting site, the record indicating a required specified number of authentication factors associated with the requesting site; verify an identity of the user of the transaction, including confirming that at least the required specified number of authentication factors are predefined in a verified user profile; generate an encrypted token including verification information resulting from the verification of the identity of the user; determine whether the requesting site is a trusted site; and based on both the trusted site determination and the identity verification of the user, transmit the generated token to the requesting site. 2. The apparatus of claim 1 , wherein the one or more processors are further configured to communicate with the requesting site to obtain requirements defining at least the required specified number of authentication factors. 3. The apparatus of claim 2 , wherein the verification of the identity includes verifying the presence of user credentials, predefined in the verified user profile, of at least a specified type specified as being required by the requesting site based on the requirements obtained via the communication. 4. The apparatus of claim 3 , wherein the one or more processors are further configured to prompt the user for at least one specified type of credential, required by the requesting site, responsive to at least one specified type of credential not being included in the verified user profile. 5. The apparatus of claim 1 , wherein the one or more processors are further configured to prompt the user for additional credentials, up to at least the required specified number of authentication factors, responsive to the required number of credentials included in the verified user profile being less than the required specified number of authentication factors. 6. The apparatus of claim 5 , wherein the credentials include user biometrics. 7. The apparatus of claim 5 , wherein the credentials include user personal information. 8. The apparatus of claim 5 , wherein the credentials include accumulated user reputation, accumulated through successful prior transactions. 9. A method comprising: receiving a login request, resulting from activation of a login button displayed on a requesting site, to perform a transaction between a user and the requesting site; verifying an identity of the user of the transaction, including confirming that at least a required number of authentication factors of one or more required types are predefined in a verified user profile, the required number and required types defined by the requesting site; and generating an encrypted token including verification information resulting from the verification of the identity of the user. 10. The method of claim 9 , wherein at least one of the required number and required types are obtained via communication with the requesting site. 11. The method of claim 9 , further comprising: prompting the user for at least one type of credential, required by the requesting site, responsive to at least one type of credential not being included in the verified user profile; and prompting the user for additional credentials, up to at least the required number of authentication factors, responsive to the required number of credentials included in the verified user profile being less than the required authentication factors. 12. The method of claim 11 , wherein the credentials include at least one of user biometrics, user personal information, or accumulated user reputation, accumulated through successful prior transactions.

Assignees

Inventors

Classifications

  • providing single-sign-on or federations · CPC title

  • using tickets, e.g. Kerberos (cryptographic mechanisms or cryptographic arrangements for entity authentication using tickets or tokens H04L9/3213) · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

  • for achieving mutual authentication (cryptographic mechanisms or cryptographic arrangements for mutual authentication H04L9/3273) · CPC title

  • above the transport layer · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11924191B2 cover?
Methods, computer-readable media, software, and apparatuses are provided to assist a user and vendor in completing an online trusted transaction. Trusted vendor websites are verified and user identities are confirmed through a cyber-security safe logon credentialing system. The vendor can be confident that the user identity has been verified to be who they say they are and the user can be confi…
Who is the assignee on this patent?
Allstate Insurance Co
What technology area does this patent fall under?
Primary CPC classification H04L63/0815. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 05 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).