IP Library Granted Patent US 11,595,816
Granted Patent B2
US 11,595,816 · App. 15/138,315 · Granted Feb 28, 2023

System and method to support identity theft protection as part of a distributed service oriented ecosystem

Inventors: Mamdouh Ibrahim (Rochester Hills, MI); Sri Ramanathan (Lutz, FL); Tapas K. Som (Germantown, MD); Matthew B. Trevathan (Roswell, GA)
Assignee: Workday, Inc.
H04W12/06G06Q20/4014G06Q30/00G06Q50/265H04L63/1433H04L65/1016H04L65/1104H04W4/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,816
App. No.
15/138,315
Granted
Feb 28, 2023
Kind
B2
Abstract

A system and method to support identity theft protection and, in particular, to a system and method for supporting identity theft protection as part of a distributed service oriented ecosystem in Internet protocol (IP) multimedia subsystem (IMS) and non-IMS networks. The system includes an identity session initiation protocol (SIP) application server configured to act as a security assertion markup language (SAML) bridge, which allows an SIP enabled device or a non-SIP enabled device to attach to a telecommunications service provider network. A user may accept or reject an authorization request using the SIP enabled device or non-SIP enabled device.

Claims (54)

1. A computer program product for preventing identity theft, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving one or more credentials via a login attempt by a first device;

processing the one or more credentials to identify a subscriber having the one or more credentials;

providing a plurality of services to the subscriber, comprising:

sending a notification to a second device associated with the subscriber to notify the subscriber of the login attempt, comprising:

generating a risk rating associated with the login attempt, wherein the risk rating is a likelihood that the login attempt is fraudulent, wherein generating the risk rating comprises:

determining a device location of the first device based on information about the location of the first device published in a presence document;

determining a subscriber location based on information on the subscriber's physical location in a user profile;

determining whether the device location and the subscriber location is a same location; and

in response to a determination that the device location and the subscriber location is not the same location:

 assigning a higher risk rating to the risk rating; and

 sending the notification to the second device, wherein a priority for delivery of the notification to the second device is based at least in part on the risk rating, wherein the sending of the notification to the second device comprises:

  determining whether the subscriber is an Internet protocol (IP) multimedia subsystem (IMS) subscriber or a non-IMS subscriber; and

  in response to a determination that the subscriber is the IMS subscriber:

   converting the notification to an identity session initiation protocol (SIP) publish request; and

   sending the SIP publish request to the second device.

2. The computer program product of claim 1 , further comprising receiving from the subscriber confirmation that the login attempt is of the subscriber.

3. The computer program product of claim 1 , wherein at least one of the receiving, the processing, and the sending are implemented based on authentication requests when a trusted card without two-factor authentication is used.

4. The computer program product of claim 1 , wherein at least one of the receiving, the processing, and the sending are implemented in association with credit card authorization.

5. The computer program product of claim 1 , wherein the plurality of services further includes a timeout service which allows the subscriber to specify a maximum period of time for a successful authentication.

6. The computer program product of claim 1 , wherein the plurality of services further includes requiring an authorization code prior to processing the login attempt.

7. The computer program product of claim 6 , wherein the authorization code is a master pin.

8. The computer program product of claim 1 , wherein the plurality of services further includes a blackout period which allows the subscriber to disable the login attempt during a blackout period of time.

9. The computer program product of claim 8 , further comprising automatically rejecting the login attempt in response to the login attempt being received during the blackout period of time.

10. The computer program product of claim 1 , wherein the notification is from an IMS control plane.

11. The computer program product of claim 1 , further comprising denying the login attempt in response to the subscriber indicating to deny the login attempt.

12. The computer program product of claim 1 , further comprising receiving from the subscriber one of an indication to accept the login attempt and an indication to reject the login attempt.

13. The computer program product of claim 1 , wherein the plurality of services is associated with a carrier.

14. A method for preventing identity theft, comprising:

receiving one or more credentials via a login attempt by a first device;

processing the one or more credentials to identify a subscriber having the one or more credentials;

providing a plurality of services to the subscriber, comprising:

sending a notification to a second device associated with the subscriber to notify the subscriber of the login attempt, comprising:

generating a risk rating associated with the login attempt, wherein the risk rating is a likelihood that the login attempt is fraudulent, wherein generating the risk rating comprises:

determining a device location of the first device based on information about the location of the first device published in a presence document;

determining a subscriber location based on information on the subscriber's physical location in a user profile;

determining whether the device location and the subscriber location is a same location; and

in response to a determination that the device location and the subscriber location is not the same location:

 assigning a higher risk rating to the risk rating; and

 sending the notification to the second device, wherein a priority for delivery of the notification to the second device is based at least in part on the risk rating, wherein the sending of the notification to the second device comprises:

  determining whether the subscriber is an IMS subscriber or a non-IMS subscriber; and

  in response to a determination that the subscriber is the IMS subscriber:

   converting the notification to an SIP publish request; and

   sending the SIP publish request to the second device.

15. The method of claim 14 , wherein the notification is from an IMS control plane.

16. The method of claim 14 , further comprising receiving confirmation from the subscriber that the login attempt is by the subscriber.

17. The method of claim 14 , further comprising denying the login attempt in response to the subscriber indicating to deny the login attempt.

18. The method of claim 14 , wherein at least one of the receiving, the processing, and the sending are implemented for authentication requests when a trusted card without two factor authentication is used.

19. The method of claim 14 , wherein at least one of the receiving, the processing, and the sending are implemented for credit card authorization.

20. The method of claim 14 , wherein the plurality of services further includes requiring an authorization code prior to processing the login attempt.

21. The method of claim 20 , wherein the authorization code is a master pin.

22. The method of claim 14 , wherein the plurality of services further includes a blackout period which allows the subscriber to disable the login attempt during a blackout period of time.

23. The method of claim 22 , further comprising automatically rejecting the login attempt in response to the login attempt being received during the blackout period of time.

24. The method of claim 14 , wherein the plurality of services further includes a timeout service which allows the subscriber to specify a maximum period of time for a successful authentication.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2025
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: WORKDAY, INC.
Reel/Frame 073051/0916 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: WORKDAY, INC.
Reel/Frame 051658/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2016
From: IBRAHIM, MAMDOUH; RAMANATHAN, SRI; SOM, TAPAS K.; TREVATHAN, MATTHEW B.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038380/0888 →
Continuity (2)
Continuation 12367619 · Feb 9, 2009
Related Publication 20160239845A1 · Aug 18, 2016