Knowledge based verification of the identity of a user

US9633355B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9633355-B2
Application numberUS-201414149003-A
CountryUS
Kind codeB2
Filing dateJan 7, 2014
Priority dateJan 7, 2014
Publication dateApr 25, 2017
Grant dateApr 25, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

According to certain embodiments of the disclosure, a system receives a request from a user device to conduct an activity with an enterprise and determines an authentication level associated with the activity. The system receives information associated with the user from a plurality of disparate channels and calculates a risk score associated with the user based on the received information associated with the user. The system generates a token based on the authentication level and risk score and communicates the token to the user device.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for verifying an identity of a user, comprising: receiving a request from a user device for a user to conduct an activity with an enterprise; determining, by a processor, an authentication level associated with the activity; determining, by a processor, a first channel from which the interface received the request from the user device to conduct the activity with the enterprise; receiving information associated with the user from a self-service channel, the self-service channel being a channel operated by the user; receiving information associated with the user from an associate-assisted channel, the associate-assisted channel being a channel operated by an associate of the enterprise; associating, by the processor, a first risk with the user based on the information associated with the user received from the self-service channel; associating, by the processor, a second risk with the user based on the information associated with the user received from the associate-assisted channel; determining, by the processor, an authentication mechanism based on the first risk, second risk, and the authentication level, the authentication mechanism being information provided by the user that verifies the identity of the user; generating, by the processor a token based on the authentication mechanism, authentication level, the first risk, and the second risk; and communicating the token to the user device, the token instructing the user to provide the authentication mechanism that complies with the first risk, second risk, and the authentication level. 2. The method of claim 1 , wherein the user is a selected one of an existing customer of the enterprise, a new customer of the enterprise, and a potential customer of the enterprise. 3. The method of claim 1 , further comprising receiving information associated with a selected one of a current activity of the user with the enterprise and a previous activity of the user with the enterprise. 4. The method of claim 1 , further comprising: receiving information from third-party data sources; and associating, by the processor, a third risk with the user based at least in part on the information received from third-party data sources. 5. The method of claim 1 , further comprising receiving a notification from the user device that the user provides an authentication mechanism that complies with the first risk, the second risk and the authentication level. 6. The method of claim 1 , further comprising: receiving the authentication mechanism from the user device; determining, by the processor, whether the received authentication mechanism complies with the first risk, the second risk and the authentication level. 7. The method of claim 1 , further comprising: determining, by the processor, whether a transfer occurs during a current session between the user device and the enterprise; determining, by the processor, whether the user provides the authentication mechanism prior to the transfer; determining, by the processor, whether the transfer requires an update to the first risk; in response to determining that the transfer requires an update to the first risk, updating, by the processor, the first risk and updating, by the processor, the token based on the first risk and the authentication level; determining, by the processor, whether the transfer requires an update to the second risk; and in response to determining that the transfer requires an update to the second risk, updating, by the processor, the second risk and updating, by the processor, the token based on the second risk and the authentication level. 8. A system for verifying an identity of a user, comprising: an interface operable to receive a request from a user device to conduct an activity with an enterprise; and one or more processors communicatively coupled to the interface and operable to: determine an authentication level associated with the activity; determine a first channel from which the interface received the request from the user device to conduct the activity with the enterprise; receive information associated with the user from a self-service channel, the self-service channel being a channel operated by the user; receive information associated with the user from an associate-assisted channel, the associate-assisted channel being a channel operated by an associate of the enterprise; associate a first risk with the user based on the information associated with the user received from the self-service channel; associate a second risk with the user based on the information associated with the user received from the associate-assisted channel; determine an authentication mechanism based on the first risk, second risk, and the authentication level, the authentication mechanism being information provided by the user that verifies the identity of the user; generate a token based on the authentication mechanism, authentication level, the first risk, and the second risk; and the interface further operable to communicate the token to the user device, the token instructing the user to provide the authentication mechanism that complies with the first risk, second risk, and the authentication level. 9. The system of claim 8 , wherein the user is a selected one of an existing customer of the enterprise, a new customer of the enterprise, and a potential customer of the enterprise. 10. The system of claim 8 , wherein the interface is further operable to receive information associated with a selected one of a current activity of the user with the enterprise and a previous activity of the user with the enterprise. 11. The system of claim 8 , wherein the interface is further operable to receive information from third-party data sources; and the one or more processors are further operable to associate a third risk with the user based at least in part on the information received from third-party data sources. 12. The system of claim 8 , the interface further operable to receive a notification from the user device that the user provides an authentication mechanism that complies with the first risk, the second risk and the authentication level. 13. The system of claim 8 , the one or more processors further operable to: receive the authentication mechanism from the user device; determine whether the received authentication mechanism complies with the first risk, the second risk and the authentication level. 14. The system of claim 8 , the one or more processors further operable to: determine whether a transfer occurs during a current session between the user device and the enterprise; determine whether the user provides the authentication mechanism prior to the transfer; determine whether the transfer requires an update to the first risk; in response to determining that the transfer requires an update to the first risk, update the first risk and update the token based on the first risk and the authentication level; determine whether the transfer requires an update to the second risk; and in response to determining that the transfer requires an update to the second risk, update the second risk and update the token based on the second risk and the authentication level. 15. A non-transitory computer readable storage medium comprising logic, the logic, when executed by a processor, operable to: receive a request from a user device for a user to conduct an activity with an enterprise; determine an authentication level associated with the activity; determine a first channel from which the interface received the request from the user device to conduct the a

Assignees

Inventors

Classifications

  • using tickets, e.g. Kerberos (cryptographic mechanisms or cryptographic arrangements for entity authentication using tickets or tokens H04L9/3213) · CPC title

  • Product, service or business identity fraud · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9633355B2 cover?
According to certain embodiments of the disclosure, a system receives a request from a user device to conduct an activity with an enterprise and determines an authentication level associated with the activity. The system receives information associated with the user from a plurality of disparate channels and calculates a risk score associated with the user based on the received information asso…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification G06Q30/0185. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 25 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).