IP Library Granted Patent US 8,745,699
Granted Patent B2
US 8,745,699 · App. 13/081,150 · Granted Jun 3, 2014

Flexible quasi out of band authentication architecture

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,745,699
App. No.
13/081,150
Granted
Jun 3, 2014
Kind
B2
Abstract

To obtain user approval of network transactions at different levels of security, a network site selects a form in which a transaction with be presented to the user from a group of transaction presentation forms including presentation of the transaction in a browser pop-up window on a user network device, in a security software application window on the user network device, and in a security application window on another user network device. The network site also selects a type of approval of the transaction required from the user from a group of transaction approval types including approval requiring no action by the user after presentation of the transaction, the user to actively approve the presented transaction, and the user to sign the presented transaction. The transaction, the selected transaction presentation form, and the selected type of user transaction approval, are transmitted to obtain approval of the transaction by the user.

Claims (41)

1. A method of operating a network site to obtain approval of network transactions at different levels of security by a user, comprising:

selecting, based on a predetermined security level for a transaction, a form in which a transaction will be presented to the user from a group of transaction presentation forms including at least two of (i) a first form of presentation corresponding to presentation of the transaction in a browser pop-up window on a first network device associated with the user, (ii) a second form of presentation corresponding to presentation of the transaction in a security software application window on the first network device, and (iii) a third form of presentation corresponding to presentation of the transaction in a security application window on a second network device associated with the user and different than the first network device;

selecting, based on the predetermined security level for the transaction, a type of approval of the transaction required from the user from a group of transaction approval types including at least two of (i) a first type approval requiring no action by the user after presentation of the transaction, (ii) a second type approval requiring the user to actively approve the presented transaction, and (iii) a third type approval requiring the user to sign the presented transaction; and

transmitting the transaction, the selected transaction presentation form, and the selected type of user transaction approval, to obtain approval of the transaction by the user.

2. The method according to claim 1 , wherein the first network device is a computer and the second network device is a mobile communications device.

3. The method according to claim 1 , wherein the first network device is a desktop computer and the second network device is a smart mobile phone.

4. The method according to claim 1 , wherein the selected type of user transaction approval is the third type approval, and the transaction, the selected transaction presentation form, and the selected type of user transaction approval, are transmitted to the user via a security server to obtain authorization of a user, and further comprising:

receiving, from the user, a personal identification number (PIN) that serves as a signature of the user on the transaction;

computing a validation PIN based on a secret shared only by the network site and the security server, and not by the user;

comparing the received PIN and the computed PIN; and accepting the received PIN as approval of the transaction by the user only if the received PIN and the computed PIN match.

5. The method according to claim 1 , wherein the selected type of user transaction approval is the second type approval, and the transaction, the selected transaction presentation form, and the selected type of user transaction approval, are transmitted to the user via a security server to obtain authorization of a user, and further comprising: receiving, from the security server, an indication that the user has approved or denied approval of the presented transaction.

6. The method according to claim 1 , wherein the transaction, the selected transaction presentation form, and the selected type of user transaction approval, are transmitted to the user via a security server to obtain approval of the user, and further comprising: transmitting the transaction to the user for presentation in a browser window on the first network device;

receiving, from the security server, comfort indicia of the user; and

transmitting the received comfort indicia and the approved transaction to the user for presentation in the browser window.

7. An article of manufacture for obtaining approval of a user of network transactions with a network station at different levels of security, comprising:

non-transitory processor readable storage medium; and

logic stored on the storage medium, wherein the stored logic is configured to be readable by a processor and thereby cause the processor to operate so as to:

select, based on a predetermined security level for a transaction, a form in which a transaction will be presented to the user from a group of transaction presentation forms including at least two of (i) a first form of presentation corresponding to presentation of the transaction in a browser pop-up window on a first network device associated with the user, (ii) a second form of presentation corresponding to presentation of the transaction in a security software application window on the first network device, and (iii) a third form of presentation corresponding to presentation of the transaction in a security application window on a second network device associated with the user and different than the first network device;

select, based on the predetermined security level for the transaction, a type of approval of the transaction required from the user from a group of transaction approval types including at least two of (i) a first type approval requiring no action by the user after presentation of the transaction, (ii) a second type approval requiring the user to actively approve the presented transaction, and (iii) a third type approval requiring the user to sign the presented transaction; and

transmit the transaction, the selected transaction presentation form, and the selected type of user transaction approval, to obtain approval of the transaction by the user.

8. The article of manufacture according to claim 7 , wherein the selected type of user transaction approval is the third type approval, and the transaction, the selected transaction presentation form, and the selected type of user transaction approval, are transmitted to the user via a security server to obtain authorization of a user, and the stored logic is further configured to cause the processor to operate so as to:

receive, from the user, a personal identification number (PIN) that serves as a signature of the user on the transaction; compute a validation PIN based on a secret shared only by the network site and the security server, and not by the user; compare the received PIN and the computed PIN; and accept the received PIN as approval of the transaction by the user only if the received PIN and the computed PIN match.

9. The article of manufacture according to claim 7 , wherein the selected type of user transaction approval is the second type approval, and the transaction, the selected transaction presentation form, and the selected type of user transaction approval, are transmitted to the user via a security server to obtain authorization of a user, and the stored logic is further configured to cause the processor to operate so as to:

receive, from the security server, an indication that the user has approved or denied approval of the presented transaction.

10. The article of manufacture according to claim 7 , wherein the transaction, the selected transaction presentation form, and the selected type of user transaction approval, are transmitted to the user via a security server to obtain approval of the user, and the stored logic is further configured to cause the processor to operate so as to: transmit the transaction to the user for presentation in a browser window on the first network device; receive, from the security server, comfort indicia of the user; and transmit the received comfort indicia and the approved transaction to the user for presentation in the browser window.

11. A method of operating a security server to present network transactions requiring different levels of security for approval by a user, comprising:

receiving a transaction having a predetermined security level from a network site transacting with the user; presenting the transaction to the user in one of a group of presentation forms including at least two of (i) a first form of presentation corresponding to presentation of the transaction in a browser pop-up window on a first network device associated with the user, (ii) a second form of presentation corresponding to presentation of the transaction in a security software application window on the first network device, and (iii) a third form of presentation corresponding to presentation of the transaction in a security application window on a second network device associated with the user and different than the first network device, wherein the one presentation form corresponds to a predetermined security level for the transaction; and

requesting one of a group of transaction approval types including at least two of (i) a first type approval requiring no action by the user after presentation of the transaction, (ii) a second type approval requiring the user to actively approve the presented transaction, and (iii) a third type approval requiring the user to sign the presented transaction selecting, wherein the one transaction approval type corresponds to the predetermined security level for the transaction.

12. The method according to claim 11 , wherein the first network device is a computer and the second network device is a mobile communications device.

13. The method according to claim 11 , wherein the first network device is a desktop computer and the second network device is a smart mobile phone.

14. The method according to claim 11 , wherein the one transaction approval type is the third type approval, and further comprising: receiving an identifier of the one transaction presentation form and the one transaction approval type from the network site; computing a personal identification number (PIN) based on a secret shared only by the network site and the security server, and not by the user; and presenting the computed PIN to the user for use as a signature of the user on the transaction.

15. The method according to claim 11 , wherein the one transaction approval type is the second type approval, and further comprising: receiving an identifier of the one transaction presentation form and the one transaction approval type from the network site; receiving an indication of approval of the presented transaction from the user; and transmitting the received indication of approval to the network site.

16. The method according to claim 11 , further comprising: receiving comfort indicia from the user; and presenting the received comfort indicia to the user in the one presentation form, with the transaction.

17. An article of manufacture for presentation by a security server of network transactions requiring different levels of security for approval by a user, comprising:

non-transitory processor readable storage medium; and

logic stored on the storage medium, wherein the stored logic is configured to be readable by a processor and thereby cause the processor to operate so as to:

receive a transaction having a predetermined security level from a network site transacting with the user; present the transaction to the user in one of a group of presentation forms including at least two of (i) a first form of presentation corresponding to presentation of the transaction in a browser pop-up window on a first network device associated with the user, (ii) a second to form of presentation corresponding to presentation of the transaction in a security software application window on the first network device, and (iii) a third form of presentation corresponding to presentation of the transaction in a security application window on a second network device associated with the user and different than the first network device, wherein the one presentation form corresponds to a predetermined security level for the transaction; and

request one of a group of transaction approval types including at least two of (i) a first type approval requiring no action by the user after presentation of the transaction, (ii) a second type approval requiring the user to actively approve the presented transaction, and (iii) a third type approval requiring the user to sign the presented transaction selecting, wherein the one transaction approval type corresponds to the predetermined security level for the transaction.

18. The article of manufacture according to claim 17 , wherein the one transaction approval type is the third type approval, and the stored logic is further configured to cause the processor to operate so as to: receive an identifier of the one transaction presentation form and the one transaction approval type from the network site; compute a personal identification number (PIN) based on a secret shared only by the network site and the security server, and not by the user; and present the computed PIN to the user for use as a signature of the user on the transaction.

19. The article of manufacture according to claim 17 , wherein the one transaction approval type is the second type approval, and the stored logic is further configured to cause the processor to operate so as to: receive an identifier of the one transaction presentation form and the one transaction approval type from the network site; receive an indication of approval of the presented transaction from the user; and transmit the received indication of approval to the network site.

20. The article of manufacture according to claim 17 , wherein the stored logic is further configured to cause the processor to operate so as to: receive comfort indicia from the user; and present the received comfort indicia to the user in the one presentation form, with the transaction.

Assignments (12)
CHANGE OF NAME Recorded Feb 27, 2025
From: PAYFONE, INC.
To: PROVE IDENTITY, INC.
Reel/Frame 070361/0346 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2020
From: EARLY WARNING SERVICES, LLC
To: PAYFONE, INC.
Reel/Frame 053148/0191 →
CONFIRMATORY GRANT OF SECURITY INTEREST IN PATENTS Recorded Jun 18, 2020
From: PAYFONE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 052984/0061 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF THE RECEIVING PARTY ON THE RELEASE OF SECURITY INTEREST AGREEMENT FROM AUTHENTIFY INC. TO AUTHENTIFY, INC. PREVIOUSLY RECORDED ON REEL 037147 FRAME 0213. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Apr 20, 2020
From: JMI SERVICES, LLC
To: AUTHENTIFY, INC.
Reel/Frame 052448/0075 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME FROM AUTHENTIFY INC. TO AUTHENTIFY, INC. PREVIOUSLY RECORDED ON REEL 027252 FRAME 0647. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF ASSIGNORS INTEREST. Recorded Apr 20, 2020
From: HAWK AND SEAL INC.
To: AUTHENTIFY, INC.
Reel/Frame 052439/0416 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR NAME PREVIOUSLY RECORDED AT REEL: 041610 FRAME: 0944. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Aug 23, 2017
From: AUTHENTIFY, LLC
To: EARLY WARNING SERVICES, LLC
Reel/Frame 043649/0549 →
MERGER AND CHANGE OF NAME Recorded Jul 25, 2017
From: AUTHENTIFY, INC.; AUTHENTIFY, LLC
To: AUTHENTIFY, LLC
Reel/Frame 043325/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2017
From: AUTHENTIFY, INC.
To: EARLY WARNING SERVICES, LLC
Reel/Frame 041610/0944 →
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2015
From: JMI SERVICES , LLC
To: AUTHENTIFY, INC.
Reel/Frame 037147/0213 →
SECURITY INTEREST Recorded Mar 31, 2014
From: AUTHENTIFY, INC.
To: JMI SERVICES, LLC
Reel/Frame 032565/0531 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2011
From: HAWK AND SEAL INC.
To: AUTHENTIFY INC.
Reel/Frame 027252/0647 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2011
From: GANESAN, RAVI
To: HAWK AND SEAL INC.
Reel/Frame 026100/0065 →