Multi-Factor User Authentication
US-2024394695-A1 · Nov 28, 2024 · US
US2016019547A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016019547-A1 |
| Application number | US-201414331628-A |
| Country | US |
| Kind code | A1 |
| Filing date | Jul 15, 2014 |
| Priority date | Jul 15, 2014 |
| Publication date | Jan 21, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
To improve security for processing of financial transactions on a customer's account, particularly for users of mobile devices, the examples authenticate the customer or user in an effective manner and/or transfer funds upon successful authentication, using intelligence of the customers' mobile devices. The present approach uses an identifier of the mobile device or user at the mobile device. The user is authenticated for a particular desired transaction based on some number of authentication factors, one or more of which is a biometric input. The user authentication technique, e.g. factors used and/or precision of matching of received user authentication factors to reference factors, can be varied based on a variety of parameters, such as transaction amount, time, device location, history of prior transactions or history of other aspects of device usage. The processing avoids storage of sensitive customer data, e.g. account number at a merchant and/or at the customer's mobile device.
Opening claim text (preview).
What is claimed is: 1 . A computer, comprising: a network communication interface; a processor; a memory accessible to the processor; and programming in the memory, wherein execution of the programming by the processor configures the computer to perform functions, including functions to: receive a parameter of a first financial transaction via a network and the communication interface; receive a user or device identification, other than a financial account identifier, from a mobile device via the network and the communication interface; receive, from the mobile device via the network and the communication interface, at least two user authentication factors obtained by the mobile device from a current user of the mobile device for authentication relative to the first financial transaction, at least one of the received factors being a biometric factor; based at least in part on the parameter of the first financial transaction, identify a first rule set, from among a plurality of rule sets of a financial transaction entity defining requirements for user authentications; identify an authentication file based on the received identification, the authentication file corresponding to but not including an identification of any financial account maintained by the financial transaction entity corresponding to the received identification; based on the first rule set, obtain one or more reference factors from the identified authentication file for authentication relative to the first financial transaction, at least one obtained reference factor corresponding to a valid user of the corresponding financial account; authenticate the current user of the mobile device as the valid user based on a successful comparison of the one or more obtained reference factors to a corresponding one or more of the user authentication factors received for authentication relative to the first financial transaction; and in response to the authentication of the current user as the valid user, transmit data via the communication interface and the network to enable completion of the first financial transaction with respect to the corresponding financial account by the financial entity. 2 . The computer of claim 1 , wherein: execution of the programming by the processor configures the computer to perform a further function to store data regarding, transaction parameters, factors used or activities of the mobile device from processing of financial transactions involving the corresponding financial account to form a transaction history relative to the mobile device or user; and at least one difference between requirements of the rule sets is based on the transaction history. 3 . The computer of claim 1 , wherein: execution of the programming by the processor configures the computer to perform a further function to store data regarding activities of the mobile device to form a history relative to the mobile device or user, at least some of the activities of the mobile device occurring at times when the mobile device is not involved in processing of any financial transaction; and at least one difference between requirements of the rule sets is based on the history. 4 . The computer of claim 1 , wherein execution of the programming by the processor configures the computer to perform further functions, including functions to: receive, via the network and the communication interface, a parameter of a second financial transaction different from the parameter of the first financial transaction; receive, from the mobile device via the network and the communication interface, two user authentication factors obtained by the mobile device from a current user of the mobile device for authentication relative to the second financial transaction, at least one of the received factors received the second financial transaction being a biometric factor; based at least in part on the parameter of the second financial transaction, identify a second rule set, from among the plurality of rule sets of the financial transaction entity defining requirements for user authentication, the requirements defined by the second rule set being different from the requirements defined by the first rule set; based on the second rule set, identify one or more reference factors for authentication relative to the second financial transaction, at least one reference factor identified based on the second rule set corresponding to the valid user of the corresponding financial account; authenticate the current user of the mobile device as the valid user based on a successful comparison of the one or more reference factors identified based on the second rule set to a corresponding one or more of the user authentication factors received for authentication relative to the second financial transaction; and in response to the authentication of the current user as the valid user using the second rule set, transmitting data via the communication interface and the network to complete the second financial transaction with respect to the corresponding financial account. 5 . The computer of claim 4 , wherein: the first and second rule sets apply to different ranges of monetary transaction value; and the requirements of the first and second rule sets differ as to the number of factors required to match and/or degree of matching of a factor, such that authentication for a transaction having value in a higher transaction value range requires matching of more factors and/or more precise factor matching than for a transaction having value in a lower value transaction value range. 6 . The computer of claim 4 , wherein: the first and second rule sets apply to different locations of the mobile device when involved in transaction processing; and the requirements of the first and second rule sets differ as to the number of factors required to match and/or degree of matching of a factor, such that authentication for a transaction when the mobile device is at a location known from prior transaction processing resulting in a successful user authentication requires matching of fewer factors and/or less precise factor matching than for a transaction when the mobile device is at another location not known from prior transaction processing resulting in a successful user authentication. 7 . The computer of claim 4 , wherein: the first and second rule sets apply to different types of financial transactions; and the requirements of the first and second rule sets differ as to the number of factors required to match and/or degree of matching of a factor, such that authentication for a first type of financial transaction requires matching of more factors and/or more precise factor matching than for second type of financial transaction of lower risk to the financial entity that the first type of financial transaction. 8 . The computer of claim 4 , wherein: the first and second rule sets apply to different conditions in relation to historical usage of the mobile device in financial transactions; and the requirements of the first and second rule sets differ as to the number of factors required to match and/or degree of matching of a factor, such that authentication for a financial transaction corresponding to a historical record of financial transactions involving the mobile device requires matching of fewer factors and/or less precise factor matching than for a transaction that does not correspond to a historical record of financial transactions involving the mobile device. 9 . The computer of claim 4 , wherein: the first and second rule sets apply to different conditions in relation to historical usage of the mobile device for non-transactional device usage; and the requirements of the first and seco
Realising banking transactions through M-devices · CPC title
Biometric identity checks · CPC title
Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists · CPC title
Transactions dependent on location of M-devices · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.