Multi-factor authentication using confidant verification of user identity

US2022255945A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2022255945-A1
Application numberUS-202117173882-A
CountryUS
Kind codeA1
Filing dateFeb 11, 2021
Priority dateFeb 11, 2021
Publication dateAug 11, 2022
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In some implementations, a server device may receive, from a client device, a login credential associated with a user and a request to access a resource. The server device may identify a confidant associated with the user and a confidant device associated with the confidant, wherein the confidant device is different from a user device associated with the user. The server device may transmit, to the confidant device, a request to verify an identity of the user. The server device may determine whether a verification of the identity of the user is received from the confidant device. The server device may grant or deny access to the resource based on determining whether the verification of the identity of the user is received from the confidant device.

First claim

Opening claim text (preview).

What is claimed is: 1 . A system for authenticating a user for access to a resource, the system comprising: one or more memories; and one or more processors, communicatively coupled to the one or more memories, configured to: receive, from a client device, a login credential associated with the user and a request to access the resource; transmit, to a confidant device associated with a confidant registered with a user account of the user, a request to verify an identity of the user, wherein the confidant is different from the user, and wherein the confidant device is different from a user device associated with the user and registered with the user account of the user; determine whether a verification of the identity of the user is received from the confidant device; and grant or deny access to the resource based on determining whether the verification of the identity of the user is received from the confidant device. 2 . The system of claim 1 , wherein the one or more processors, when transmitting the request to verify the identity of the user to the confidant device, are configured to transmit a verification code to the confidant device, and wherein the one or more processors, when determining whether the verification of the identity of the user is received from the confidant device, are configured to: determine whether a response including the verification code is received from the confidant device. 3 . The system of claim 1 , wherein the one or more processors, when transmitting the request to verify the identity of the user to the confidant device, are configured to transmit a challenge to the confidant device, and the one or more processors are further configured to: transmit a first challenge response to the user device associated with the user; receive, from the confidant device, a second challenge response based on transmitting the challenge to the confidant device; and determine whether the verification of the identity of the user is received from the confidant device based on a comparison of the first challenge response and the second challenge response. 4 . The system of claim 1 , wherein the one or more processors, when transmitting the request to verify the identity of the user to the confidant device, are configured to transmit, to the confidant device, a challenge question relating to temporal verification information associated with the user, and the one or more processors are further configured to: transmit, to the user device associated with the user, the challenge question relating to the temporal verification information associated with the user; receive, from the user device, a first challenge answer indicating the temporal verification information associated with the user; receive, from the confidant device, a second challenge answer indicating the temporal verification information associated with the user; and determine whether the verification of the user identify is received from the confidant device based on a comparison of the first challenge answer and the second challenge answer. 5 . The system of claim 1 , wherein the one or more processors, when transmitting the request to verify the identity of the user to the confidant device, are configured to transmit a challenge to the confidant device, and the one or more processors are further configured to: initiate a communication session between the confidant device and the user device associated with the user; receive a challenge response from the confidant device based on initiating the communication session between the confidant device and the user device; and determine whether the verification of the user identify is received from the confidant device based on the challenge response received from the confidant device. 6 . The system if claim 5 , wherein the one or more processors, when determining whether the verification of the identity of the user is received from the confidant device, are configured to: acquire a voice sample of the confidant during the communication session between the confidant device and the user device; compare the voice sample of the confidant to voice biometric information associated with the confidant; and determine whether the verification of the user identify is received from the confidant device based on the challenge response received from the confidant device and based on comparing the voice sample of the confidant to the voice biometric information associated with the confidant. 7 . The system if claim 5 , wherein the communication session is a video call, and the one or more processors, when determining whether the verification of the identity of the user is received from the confidant device, are configured to: acquire an image of the confidant during the video call between the confidant device and the user device; compare the image of the confidant to a stored image of the confidant; and determine whether the verification of the user identify is received from the confidant device based on the challenge response received from the confidant device and based on comparing the image of the confidant to the stored image of the confidant. 8 . The system of claim 1 , wherein the one or more processors, when granting or denying access to the resource, are configured to: deny access to the resource based on determining the verification of the identity of the user is not received from the confidant device within a time threshold. 9 . The system of claim 1 , wherein the one or more processors are further configured to detect an enhanced authorization event relating to the login credential and the request to access the resource, and wherein the one or more processors, when transmitting the request to verify the identity of the user to the confidant device, are configured to: transmit the request to verify the identity of the user to the confidant device based on detecting the enhanced authorization event. 10 . The system of claim 9 , wherein the one or more processors, when detecting the enhanced authorization event, are configured to: detect the enhanced authorization event based on determining that a subscriber identity module (SIM) of the user device associated with the user has changed within a time window. 11 . A method for multi-factor authentication, comprising: receiving, by a server device and from a client device, a login credential associated with a user and a request to access a resource; identifying, by the server device, a confidant associated with the user and a confidant device associated with the confidant, wherein the confidant device is different from a user device associated with the user; transmitting, by the server device and to the confidant device, a request to verify an identity of the user; determining, by the server device, whether a verification of the identity of the user is received from the confidant device; and granting or denying access to the resource based on determining whether the verification of the identity of the user is received from the confidant device. 12 . The method of claim 11 , wherein identifying the confidant associated with the user and the confidant device associated with the confidant comprises: identifying one or more confidants registered with a user account of the user; transmitting, to the client device, a list of the one or more confidants; receiving, from the client device, a selection of the confidant from the list of the one or more confidants; and identifying the confidant device based on a device identifier associated with the confidant in account information associated with the user account. 13 . The method of claim 1

Assignees

Inventors

Classifications

  • applying multi-factor authentication · CPC title

  • H04L63/102Primary

    Entity profiles · CPC title

  • by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity · CPC title

  • using biometrical features, e.g. fingerprint, retina-scan (cryptographic mechanisms or cryptographic arrangements for entity authentication using biological data H04L9/3231) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2022255945A1 cover?
In some implementations, a server device may receive, from a client device, a login credential associated with a user and a request to access a resource. The server device may identify a confidant associated with the user and a confidant device associated with the confidant, wherein the confidant device is different from a user device associated with the user. The server device may transmit, to…
Who is the assignee on this patent?
Capital One Services Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/102. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Aug 11 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).