App profile verification across computing devices using transaction context
Methods, systems, and machine-readable mediums that enhance transaction authentication of a transaction of a first application by checking that a state of one or more other applications matches prespecified states or that one or more of those applications transition states within a prespecified period of time. For example, the prespecified states may correspond to the application being installed on a specified device (e.g., of the user) and having an authenticated session with a specified user.
1 . A method for authenticating a transaction on a computing device, comprising:
at a first application or an application server of the first application, using one or more processors, automatically:
identifying a request for the transaction corresponding to the first application installed on the computing device, the transaction associated with a first user account of the first application;
responsive to identifying the request:
selecting, based on a property of the transaction, and from a transaction authorization data record corresponding to the transaction, both a subset of a plurality of other applications from a prespecified set of other applications and for each application in the subset, an authentication state, where each authentication state is indicative of at least the application being resident on a specified computing device and the application having an active authentication state of a prespecified user account associated with the application, the prespecified user account prespecified for use in authenticating the transaction for the first user account of the first application, the selected subset different that than a second subset that would be selected based upon a property of a second transaction different than the property of the transaction;
according to the transaction authorization data record, determining, for each particular application in the subset, by communicating with the particular application, an application state service, or the application server of the particular application, whether a current state of the particular application corresponds to the authentication state specified in the transaction authorization data record for the particular application, the determination verifying that the particular application is resident on the specified computing device and the particular application having an active authentication state of the prespecified user account associated with the application; and
responsive to determining that the current states of all applications in the subset correspond to their authentication states:
authenticating the transaction based on a verification that all applications in the subset are in their authentication states; and
processing the transaction upon successful authentication.
2 . The method of claim 1 , wherein the property of the transaction is a transaction time, and wherein the property of the second transaction is a different transaction time.
3 . The method of claim 2 , wherein aside from transaction time, the transaction and the second transaction are identical.
4 . The method of claim 1 , wherein the property of the first transaction is a prior indication of fraudulent activity on the first user account, the property of the second transaction is no prior indication of fraudulent activity on the first user account, and wherein the selected subset includes more applications than the second subset.
5 . The method of claim 1 , wherein selecting, based on the property of the transaction, and from the transaction authorization data record corresponding to the transaction, both the subset of the plurality of other applications from the prespecified set of other applications and for each application in the subset, the authentication state comprises also using historical application usage data of a user to select applications normally in-use by the user during the transaction.
6 . The method of claim 1 , wherein selecting, based on the property of the transaction, and from the transaction authorization data record corresponding to the transaction, both the subset of the plurality of other applications from the prespecified set of other applications and for each application in the subset, the authentication state comprises also using application security rankings.
7 . The method of claim 1 , wherein at least one of the subset of the plurality of other applications is executing on a second computing device different than the specified computing device.
8 . The method of claim 7 , wherein a different at least one of the subset of the plurality of other applications is executing on the specified computing device.
9 . A computing device for authenticating a transaction, the computing device comprising:
a hardware processor;
a memory, storing instructions, which when executed by the hardware processor, causing the hardware processor to perform operations comprising:
at a first application or an application server of the first application, automatically:
identifying a request for the transaction corresponding to the first application installed on the computing device, the transaction associated with a first user account of the first application;
responsive to identifying the request:
selecting, based on a property of the transaction, and from a transaction authorization data record corresponding to the transaction, both a subset of a plurality of other applications from a prespecified set of other applications and for each application in the subset, an authentication state, where each authentication state is indicative of at least the application being resident on a specified computing device and the application having an active authentication state of a prespecified user account associated with the application, the prespecified user account prespecified for use in authenticating the transaction for the first user account of the first application, the selected subset different than a second subset that would be selected based upon a property of a second transaction different than the property of the transaction;
according to the transaction authorization data record, determining, for each particular application in the subset, by communicating with the particular application, an application state service, or the application server of the particular application, whether a current state of the particular application corresponds to the authentication state specified in the transaction authorization data record for the particular application, the determination verifying that the particular application is resident on the specified computing device and the particular application having an active authentication state of the prespecified user account associated with the application; and
responsive to determining that the current states of all applications in the subset correspond to their authentication states:
authenticating the transaction based on a verification that all applications in the subset are in their authentication states; and
processing the transaction upon successful authentication.
10 . The computing device of claim 9 , wherein the property of the transaction is a transaction time, and wherein the property of the second transaction is a different transaction time.
11 . The computing device of claim 10 , wherein aside from transaction time, the transaction and the second transaction are identical.
12 . The computing device of claim 9 , wherein the property of the first transaction is a prior indication of fraudulent activity on the first user account, the property of the second transaction is no prior indication of fraudulent activity on the first user account, and wherein the selected subset includes more applications than the second subset.
13 . The computing device of claim 9 , wherein selecting, based on the property of the transaction, and from the transaction authorization data record corresponding to the transaction, both the subset of the plurality of other applications from the prespecified set of other applications and for each application in the subset, the authentication state comprises also using historical application usage data of a user to select applications normally in-use by the user during the transaction.
14 . The computing device of claim 9 , wherein selecting, based on the property of the transaction, and from the transaction authorization data record corresponding to the transaction, both the subset of the plurality of other applications from the prespecified set of other applications and for each application in the subset, the authentication state comprises also using application security rankings.
15 . The computing device of claim 9 , wherein at least one of the subset of the plurality of other applications is executing on a second computing device different than the specified computing device.
16 . The computing device of claim 15 , wherein a different at least one of the subset of the plurality of other applications is executing on the specified computing device.
17 . A non-transitory computer-readable medium, storing instructions for authenticating a transaction at a first application or an application server of the first application, the instructions, when executed by a computing device, cause the computing device to perform operations comprising:
identifying a request for the transaction corresponding to the first application installed on the computing device, the transaction associated with a first user account of the first application;
responsive to identifying the request:
selecting, based on a property of the transaction, and from a transaction authorization data record corresponding to the transaction, both a subset of a plurality of other applications from a prespecified set of other applications and for each application in the subset, an authentication state, where each authentication state is indicative of at least the application being resident on a specified computing device and the application having an active authentication state of a prespecified user account associated with the application, the prespecified user account prespecified for use in authenticating the transaction for the first user account of the first application, the selected subset different that than a second subset that would be selected based upon a property of a second transaction different than the property of the transaction;
according to the transaction authorization data record, determining, for each particular application in the subset, by communicating with the particular application, an application state service, or the application server of the particular application, whether a current state of the particular application corresponds to the authentication state specified in the transaction authorization data record for the particular application, the determination verifying that the particular application is resident on the specified computing device and the particular application having an active authentication state of the prespecified user account associated with the application; and
responsive to determining that the current states of all applications in the subset correspond to their authentication states:
authenticating the transaction based on a verification that all applications in the subset are in their authentication states; and
processing the transaction upon successful authentication.
18 . The non-transitory computer-readable medium of claim 17 , wherein the property of the transaction is a transaction time, and wherein the property of the second transaction is a different transaction time.
19 . The non-transitory computer-readable medium of claim 18 , wherein aside from transaction time, the transaction and the second transaction are identical.
20 . The non-transitory computer-readable medium of claim 17 , wherein the property of the transaction is a prior indication of fraudulent activity on the first user account, the property of the second transaction is no prior indication of fraudulent activity on the first user account, and wherein the selected subset includes more applications than the second subset.