Verification system for omnichannel end-user verification
Examples are disclosed related to using verification channels for end-user verification. One example provides a method comprising, in a first verification channel, receiving a first verification request and an end-user mobile number from an enterprise computing system, sending a first-time sign-in request to an end-user computing device, and receiving a first end-user authentication message in response to the first-time sign-in request, and in response, associating a passkey with the end-user mobile number. The method further comprises, in a second verification channel, receiving a second verification request and the end-user mobile number from the enterprise computing system, sending a sign-in message, receiving a second end-user authentication message in response to the sign-in message, and in response to receiving a verification approved response from the end-user computing device, sending the verification approved response to the end-user computing device and/or the enterprise computing system.
1 . A method on a verification computing system comprising a verification agent and a verification web-application, the method comprising:
in a first verification channel including an offline channel in which a verification API (application programing interface) sends a first verification request in response to an input initiating an end-user verification on a first computing device of an enterprise computing system:
receiving the first verification request and an end-user mobile number from the verification API;
sending a first-time sign-in request to an end-user computing device associated with the end-user mobile number, the first-time sign-in request indicating a state of a first user verification session in the verification web-application on the verification computing system, the first user verification session being in communication with the verification agent and a first user web-application on the end-user computing device;
receiving, from the first user web-application, a first end-user authentication message after detecting a connection with the end-user computing device, the first end-user authentication message including a passkey, and in response, associating the passkey with the end-user mobile number;
in a second verification channel including an online channel in which the verification API sends a second verification request in response to a verification API request from a second computing device of the enterprise computing system:
receiving the second verification request and the end-user mobile number from the verification API;
sending a sign-in message to the end-user computing device, the sign-in message indicating a state of a second user verification session in the verification web-application on the verification computing system, the second user verification session being in communication with the verification agent and a second user web-application on the end-user computing device;
receiving, from the second user web-application, a second end-user authentication message in response to the sign-in message from the end-user computing device, the second end-user authentication message including the passkey to sign-in with the second user verification session;
sending, utilizing the second user web-application, an end-user verification message to the end-user computing device upon receiving the passkey; and
in response to receiving a verification approved response from the second user web-application on the end-user computing device, sending the verification approved response to one or more of the end-user computing device or the enterprise computing system using the verification agent.
2 . The method of claim 1 , wherein sending the first-time sign-in request to the end-user computing device associated with the end-user mobile number includes sending the first-time sign-in request when the end-user mobile number is in a pre-enrollment list.
3 . The method of claim 1 , wherein one or more of the first-time sign-in request or the sign-in message is sent via Short Message Service (SMS) to the end-user mobile number of the end-user computing device.
4 . The method of claim 1 , wherein one or more of the first-time sign-in request or the sign-in message is sent via a push notification using the verification agent to the end-user computing device.
5 . The method of claim 1 , wherein one or more of the first-time sign-in request or the sign-in message is sent via an in-application notification using a client application on the end-user computing device, the in-application notification includes one or more of a popup window, an integrated sign-in, or a quick-response (QR) code.
6 . The method of claim 1 , wherein
one or more of the first-time sign-in request or the sign-in message includes
a hyperlink to a URL having a URL parameter indicating the state of a corresponding user verification session in the verification web-application for an end-user of the end-user computing device, and
upon selection of the URL by the end-user, is configured to launch a corresponding user web-application via a browser program and display a verification interface via the browser program on the end-user computing device,
the verification interface including a message requesting the end-user to sign-in to the corresponding user verification session; and
the passkey is received upon a successful sign-in of the end-user computing device to the corresponding user verification session.
7 . The method of claim 1 , wherein receiving the first end-user authentication message in response to the first-time sign-in request from the end-user computing device includes sending a Silent Network Authentication (SNA) request to the end-user computing device, and the first end-user authentication message further including an SNA response.
8 . The method of claim 1 , wherein receiving the first end-user authentication message in response to the first-time sign-in request from the end-user computing device includes sending a short message service one time passcode (SMS-OTP) request to the end-user computing device, and the first end-user authentication message further including an OTP response.
9 . The method of claim 1 , wherein the second verification channel includes a verification application-programing-interface (API) request from a client application on the end-user computing device.
10 . The method of claim 1 , wherein the sign-in message is a first sign-in message; and
the method further comprises
receiving a third verification request and the end-user mobile number from the enterprise computing system;
sending a second sign-in message to the end-user computing device;
receiving a third end-user authentication message in response to the second sign-in message from the end-user computing device, the third end-user authentication message including the passkey.
11 . A verification computing system comprising:
one or more processors; and
a storage subsystem including a verification agent, a verification web-application, and instructions operable by the one or more processors to
in a first verification channel including an offline channel in which a verification API (application programming interface) sends a first verification request in response to an input initiating an end-user verification on a first computing device of an enterprise computing system:
receive the first verification request and an end-user mobile number from the verification API,
send a first-time sign-in request to an end-user computing device associated with the end-user mobile number, the first-time sign-in request indicating a state of a first user verification session in the verification web-application, the first user verification session being in communication with the verification agent and a first user web-application on the end-user computing device,
receive, from the first user web-application, a first end-user authentication message after detecting a connection with the end-user computing device, the first end-user authentication message including a passkey, and in response, associating the passkey with the end-user mobile number,
in a second verification channel including an online channel in which the verification API sends a second verification request in response to a verification API request from a second computing device of the enterprise computing system:
receive the second verification request and the end-user mobile number from the verification API,
send a sign-in message to the end-user computing device, the sign-in message indicating a state of a second user verification session in the verification web-application, the second user verification session being in communication with the verification agent and a second user web-application on the end-user computing device,
receive a second end-user authentication message from the second user web-application on the end-user computing device, the second end-user authentication message including the passkey to sign-in with the second user verification session;
send, utilizing the second user web-application, an end-user verification message to the end-user computing device upon receiving the passkey, and
in response to receiving a verification approved response to the sign-in message from the second user web-application on the end-user computing device, send the verification approved response to one or more of the end-user computing device or the enterprise computing system using the verification agent.
12 . The verification computing system of claim 11 , wherein the instructions operable to send the first-time sign-in request to the end-user computing device associated with the end-user mobile number include instructions operable to send the first-time sign-in request when the end-user mobile number is in a pre-enrollment list.
13 . The verification computing system of claim 11 , wherein one or more of the first-time sign-in request or the sign-in message is sent via Short Message Service (SMS) to the end-user mobile number of the end-user computing device.
14 . The verification computing system of claim 11 , wherein one or more of the first-time sign-in request or the sign-in message is sent via an in-application notification using a client application on the end-user computing device, the in-application notification includes one or more of a popup window, an integrated sign-in, or a quick-response (QR) code.
15 . The verification computing system of claim 11 , wherein
the sign-in message includes
a hyperlink to a URL having a URL parameter indicating the state of the second user verification session for an end-user of the end-user computing device, and
upon selection of the URL by the end-user, is configured to launch the second user web-application via a browser program and display a verification interface via the browser program on the end-user computing device,
the verification interface including a message requesting the end-user to sign-in to the second user verification session.
16 . The verification computing system of claim 11 , wherein the instructions operable to receive the first end-user authentication message in response to the first-time sign-in request from the end-user computing device include instructions operable to send a Silent Network Authentication (SNA) request to the end-user computing device, and the first end-user authentication message further includes an SNA response.
17 . A verification computing system comprising:
one or more processors; and
a storage subsystem comprising a verification agent, a verification web-application, and instructions operable by the one or more processors to
receive a list of new-users from a new account API on an enterprise computing system, each new-user having an end-user mobile number,
store a plurality of end-user mobile numbers from the list of new-users as a pre-enrollment list,
in a first verification channel in which a verification API (application programming interface) sends a first verification request that is initiated from a first computing device of the enterprise computing system:
receive the first verification request and an end-user mobile number associated with an end-user from the verification API,
send a first-time sign-in request to an end-user computing device associated with the end-user mobile number when the end-user mobile number is in the pre-enrollment list, the first-time sign-in request indicating a state of a first user verification session in the verification web-application, the first user verification session being in communication with the verification agent and a first user web-application on the end-user computing device,
receive, from the first user web-application, a first end-user authentication message after detecting a connection with the end-user computing device, the first end-user authentication message including a passkey, and in response, send a first end-user verification message to the end-user computing device utilizing the first user web-application,
in response to receiving a first verification approved response to the first end-user verification message from the first user web-application on the end-user computing device, send the first verification approved response to one or more of the end-user computing device or the enterprise computing system using the verification agent,
in a second verification channel in which the verification API sends a second verification request that is initiated from a second computing device of the enterprise computing system,
in response to receiving the second verification request, send a sign-in message to the end-user computing device, the sign-in message indicating a state of a second user verification session in the verification web-application, the second user verification session being in communication with the verification agent and a second user web-application on the end-user computing device,
utilizing the second user web-application on the end-user computing device, receive a second verification approved response in response to a second end-user verification message, and
send, using the verification agent, the second verification approved response to the verification API on the enterprise computing system.
18 . The verification computing system of claim 17 , wherein the instructions operable to send the first-time sign-in request comprise instructions operable to send the first-time sign-in request to the end-user computing device via one or more of Short Message Service (SMS), a push notification using the verification agent, or a client application on the end-user computing device.
19 . The verification computing system of claim 17 , wherein the instructions operable to receive the end-user authentication message in response to the first-time sign-in request from the end-user computing device include instructions operable to send a Short Message Service One-Time-Passcode (SMS-OTP) message to the end-user computing device, and the end-user authentication message further including a one-time-passcode response.
20 . The verification computing system of claim 17 , wherein the instructions operable to receive the end-user authentication message in response to the first-time sign-in request from the end-user computing device include instructions operable to send a Silent Network Authentication (SNA) request to the end-user computing device, and the end-user authentication message further including an SNA response.