IP Library Granted Patent US 9,077,538
Granted Patent B1
US 9,077,538 · App. 13/326,745 · Granted Jul 7, 2015

Systems and methods for verifying user identities

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,077,538
App. No.
13/326,745
Granted
Jul 7, 2015
Kind
B1
Abstract

A computer-implemented method for verifying user identities may include (1) identifying a request to ascertain whether a user account corresponds to a physical person, and, in response to the request, (2) identifying a password vault configured to store login information for at least one third-party Internet site for the user account, the third-party Internet site requiring a physical validation factor to log in to the third-party Internet site, (3) determining, based at least in part on the login information for the third-party Internet site, that the user account corresponds to the physical person, and (4) responding to the request with an indicator that the user account corresponds to the physical person. Various other methods, systems, and computer-readable media are also disclosed.

Claims (80)

1. A computer-implemented method for verifying user identities, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

identifying a request from a requesting Internet site to ascertain whether an entity represented by a user account, via which the entity has attempted to access the requesting Internet site, corresponds to a physical person;

in response to the request:

identifying a password vault configured to store login information for at least one third-party Internet site for the user account, the third-party Internet site requiring a physical validation factor that confirms that the user account corresponds to the physical person in order for the entity to establish an account with the third-party Internet site;

inferring, based on the login information for the third-party Internet site stored in the password vault and based on the third-party Internet site requiring the physical validation factor, that the entity previously provided the physical validation factor to the third-party Internet site to establish the account with the third-party Internet site;

determining, based at least in part on inferring that the entity previously provided the physical validation factor to the third-party Internet site, and not based on direct input from the entity, that the user account corresponds to the physical person by:

identifying a weight assigned to the third-party Internet site;

applying the weight in a multi-factor determination of whether the user account corresponds to the physical person;

determining, in the multi-factor determination, that a likelihood that the user account corresponds to the physical person exceeds a predetermined threshold;

responding to the request with an indicator to the requesting Internet site that the user account corresponds to the physical person.

2. The computer-implemented method of claim 1 , wherein the login information comprises information indicating that a user of the user account has successfully logged in to the third-party Internet site.

3. The computer-implemented method of claim 2 , wherein the password vault is configured to reset the information indicating that the user of the user account has successfully logged in to the third-party Internet site when the login information changes.

4. The computer-implemented method of claim 1 , wherein the login information comprises information indicating a number of times that a user of the user account has successfully logged in to the third-party Internet site.

5. The computer-implemented method of claim 1 , wherein:

the indicator comprises an authentication token;

responding to the request comprises:

transmitting the authentication token to the user account for submission by the user account to a validating system;

transmitting the authentication token to the validating system for verification of the user account.

6. The computer-implemented method of claim 1 , wherein the physical validation factor comprises at least one of:

credit card information;

in-person authentication;

phone number authentication;

a document scan;

a home address verification;

biometric data.

7. The computer-implemented method of claim 1 , wherein determining, based at least in part on inferring that the entity previously provided the physical validation factor to the third-party Internet site, that the user account corresponds to the physical person comprises determining that the third-party Internet site requires the physical validation factor by:

identifying a database of third-party Internet sites that require physical validation factors;

querying the database to determine that the third-party Internet site requires the physical validation factor.

8. A system for verifying user identities, the system comprising:

an identification module, stored in memory, programmed to identify a request from a requesting Internet site to ascertain whether a user account, via which the entity has attempted to access the requesting Internet site, corresponds to a physical person;

a vault module, stored in memory, programmed to, in response to the request, identify a password vault configured to store login information for at least one third-party Internet site for the user account, the third-party Internet site requiring a physical validation factor that confirms that the user account corresponds to the physical person in order for the entity to establish an account with the third-party Internet site;

an inference module, stored in memory, programmed to infer, based on the login information for the third-party Internet site stored in the password vault and based on the third-party Internet site requiring the physical validation factor, that the entity previously provided the physical validation factor to the third-party Internet site to establish the account with the third-party Internet site;

a determination module, stored in memory, programmed to determine, based at least in part on inferring that the entity previously provided the physical validation factor to the third-party Internet site, and not based on direct input from the entity, that the user account corresponds to the physical person by:

identifying a weight assigned to the third-party Internet site;

applying the weight in a multi-factor determination of whether the user account corresponds to the physical person;

determining, in the multi-factor determination, that a likelihood that the user account corresponds to the physical person exceeds a predetermined threshold;

a response module, stored in memory, programmed to respond to the request with an indicator to the requesting Internet site that the user account corresponds to the physical person;

at least one physical processor configured to execute the identification module, the vault module, the inference module, the determination module, and the response module.

9. The system of claim 8 , wherein the login information comprises information indicating that a user of the user account has successfully logged in to the third-party Internet site.

10. The system of claim 9 , wherein the password vault is configured to reset the information indicating that the user of the user account has successfully logged in to the third-party Internet site when the login information changes.

11. The system of claim 8 , wherein the login information comprises information indicating a number of times that a user of the user account has successfully logged in to the third-party Internet site.

12. The system of claim 8 , wherein:

the indicator comprises an authentication token;

the response module is programmed to respond to the request by:

transmitting the authentication token to the user account for submission by the user account to a validating system;

transmitting the authentication token to the validating system for verification of the user account.

13. The system of claim 8 , wherein the physical validation factor comprises at least one of:

credit card information;

in-person authentication;

phone number authentication;

a document scan;

a home address verification;

biometric data.

14. The system of claim 8 , wherein the determination module is programmed to determine, based at least in part on inferring that the entity previously provided the physical validation factor to the third-party Internet site, that the user account corresponds to the physical person by determining that the third-party Internet site requires the physical validation factor by:

identifying a database of third-party Internet sites that require physical validation factors;

querying the database to determine that the third-party Internet site requires the physical validation factor.

15. A non-transitory computer-readable-storage medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

identify a request from a requesting Internet site to ascertain whether a user account, via which the entity has attempted to access the requesting Internet site, corresponds to a physical person;

in response to the request:

identify a password vault configured to store login information for at least one third-party Internet site for the user account, the third-party Internet site requiring a physical validation factor that confirms that the user account corresponds to the physical person in order for the entity to establish an account with the third-party Internet site;

infer, based on the login information for the third-party Internet site stored in the password vault and based on the third-party Internet site requiring the physical validation factor, that the entity previously provided the physical validation factor to the third-party Internet site to establish the account with the third-party Internet site; determine, based at least in part on inferring that the entity previously provided the physical validation factor to the third-party Internet site, and not based on direct input from the entity, that the user account corresponds to the physical person by:

identifying a weight assigned to the third-party Internet site;

applying the weight in a multi-factor determination of whether the user account corresponds to the physical person;

determining, in the multi-factor determination, that a likelihood that the user account corresponds to the physical person exceeds a predetermined threshold;

respond to the request with an indicator to the requesting Internet site that the user account corresponds to the physical person.

16. The non-transitory computer-readable-storage medium of claim 15 , wherein the login information comprises information indicating that a user of the user account has successfully logged in to the third-party Internet site.

17. The non-transitory computer-readable-storage medium of claim 16 , wherein the password vault is configured to reset the information indicating that the user of the user account has successfully logged in to the third-party Internet site when the login information changes.

18. The non-transitory computer-readable-storage medium of claim 15 , wherein the login information comprises information indicating a number of times that a user of the user account has successfully logged in to the third-party Internet site.

19. The non-transitory computer-readable-storage medium of claim 15 , wherein:

the indicator comprises an authentication token;

responding to the request comprises:

transmitting the authentication token to the user account for submission by the user account to a validating system;

transmitting the authentication token to the validating system for verification of the user account.

20. The non-transitory computer-readable-storage medium of claim 15 , wherein the physical validation factor comprises at least one of:

credit card information;

in-person authentication;

phone number authentication;

a document scan;

a home address verification;

biometric data.

Assignments (5)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →