IP Library Granted Patent US 11,122,034
Granted Patent B2
US 11,122,034 · App. 15/970,796 · Granted Sep 14, 2021

Method and apparatus for an identity assurance score with ties to an ID-less and password-less authentication system

Inventor: Nelson A. Cicchitto (San Ramon, CA)
Assignee: Nelson A. Cicchitto
H04L63/083H04L63/0815H04W12/068H04L2463/082H04W12/68
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,122,034
App. No.
15/970,796
Granted
Sep 14, 2021
Kind
B2
Abstract

A technique is provided by which a user goes to a site and instead of the authentication system of the site going to their own databases to match an ID and password given by the user, because doing so is not secure, the site companies makes a call to an identity assurance score server (with ties to the ID-less and password-less system) and send a parameter such as a number. Then, based on that parameter (e.g., number or score), the identity assurance score server (with ties to the ID-less and password-less system, such as described hereinabove) sends a corresponding login protocol or factors to be satisfied to authenticate the user.

Claims (79)

1. A computer-implemented method, comprising:

receiving, at an identity assurance server, a first request initiated from a company server for an identity assurance score corresponding to an entity requesting the company server for access to an asset of the company, wherein the entity is a user and wherein the identity assurance score is computed independently of a device used by the user for requesting access;

generating, in response to the request, the identity assurance score and determining, based on the generated identity assurance score, a collection of requirements that the entity must satisfy to access the asset;

transmitting by the identity assurance server for delivery to the company server, the identity assurance score and the collection of requirements for the entity to satisfy;

receiving, at the identity assurance server and originating from the company server, informational data corresponding to the collection of requirements completed by the entity;

confirming, at the identity assurance server, that the received informational data matches data previously saved on a database at the identity assurance server; and

notifying the company that the received information data has been confirmed;

wherein one or more steps are performed on at least a processor coupled to at least a memory; and

wherein a hierarchy of levels comprises the following levels of requirements for granting access to the asset:

first level—ID of user and No Password;

second level—ID and Password;

third level—Description of something the entity knows;

fourth level—Description of something the entity has;

fifth level—Number of social network connections the entity has;

sixth level—Location of the entity;

seventh level—One biometric identifier;

eighth level—Two biometric identifiers;

ninth level—Three biometric identifiers;

tenth level—Financial information corresponding to the entity;

eleventh level—One health identifier;

twelfth level—Second health identifier; and

thirteenth level—DNA (Deoxyribonucleic acid) of the entity.

2. The method of claim 1 , wherein the asset of the company is any of a computer-related account or service or a room or building under control of the company.

3. The method of claim 1 , wherein the identity assurance score is based on a predetermined hierarchy of levels of requirements to be satisfied for the request to be approved.

4. The method of claim 3 , wherein the requirements of the level are cumulative, meaning that the identity assurance score causes the requirements for the current level and the previous levels to be checked for satisfaction before approving the request.

5. The method of claim 3 , wherein the identity assurance score for the current level does not have to incorporate requirements of any other level of any other identity assurance score before approving the request.

6. The method of claim 1 , wherein a biometric identifier is fingerprint or voice of the entity.

7. The method of claim 6 , wherein financial information comprises any of: current bank balances; the number of bank accounts; whether the entity is a homeowner; or whether the entity has any personal loans.

8. The method of claim 7 , wherein a health identifier is 1 Blood Type; dental information; or type of surgeries.

9. An apparatus, comprising:

a first receiving processor configured to receive, at an identity assurance server, a first request initiated from a company server for an identity assurance score corresponding to an entity requesting the company server for access to an asset of the company, wherein the entity is a user and wherein the identity assurance score is computed independently of a device used by the user for requesting access;

a generating processor configured to generate, in response to the request, the identity assurance score and determine, based on the generated identity assurance score, a collection of requirements that the entity must satisfy to access the asset;

a transmitting processor configured to transmit by the identity assurance server for delivery to the company server, the identity assurance score and the collection of requirements for the entity to satisfy;

a second receiving processor configured to receive, at the identity assurance server and originating from the company server, informational data corresponding to the collection of requirements completed by the entity;

a confirming processor configured to confirm, at the identity assurance server, that the received informational data matches data previously saved on a database at the identity assurance server;

a notifying processor configured to notify the company that the received information data has been confirmed; and

at least one memory operable to store computer program instructions a by at least one of said processors;

wherein a hierarchy of levels comprises the following levels of requirements for granting access to the asset:

first level—ID of user and No Password;

second level—ID and Password;

third level—Description of something the entity knows;

fourth level—Description of something the entity has;

fifth level—Number of social network connections the entity has;

sixth level—Location of the entity;

seventh level—One biometric identifier;

eighth level—Two biometric identifiers;

ninth level—Three biometric identifiers;

tenth level—Financial information corresponding to the entity;

eleventh level—One health identifier;

twelfth level—Second health identifier; and

thirteenth level—DNA (Deoxyribonucleic acid) of the entity.

10. The apparatus of claim 9 , wherein the asset of the company is any of a computer-related account or service or a room or building under control of the company.

11. The apparatus of claim 9 , wherein the identity assurance score is based on a predetermined hierarchy of levels of requirements to be satisfied for the request to be approved.

12. The apparatus of claim 11 , wherein the requirements of the level are cumulative, meaning that the identity assurance score causes the requirements for the current level and the previous levels to be checked for satisfaction before approving the request.

13. The apparatus of claim 11 , wherein the identity assurance score for the current level does not have to incorporate requirements of any other level of any other identity assurance score before approving the request.

14. The apparatus of claim 9 , wherein a biometric identifier is fingerprint or voice of the entity.

15. The apparatus of claim 14 , wherein financial information comprises any of: current bank balances; the number of bank accounts; whether the entity is a homeowner; or whether the entity has any personal loans.

16. The apparatus of claim 15 , wherein a health identifier is 1 Blood Type; dental information; or type of surgeries.

17. A non-transitory computer readable medium having stored thereon a computer program, said computer program comprising a program code which, when executed by a processor, performs the steps of:

receiving, at an identity assurance server, a first request initiated from a company server for an identity assurance score corresponding to an entity requesting the company server for access to an asset of the company, wherein the entity is a user and wherein the identity assurance score is computed independently of a device used by the user in requesting access;

generating, in response to the request, the identity assurance score and determining, based on the generated identity assurance score, a collection of requirements that the entity must satisfy to access the asset;

transmitting by the identity assurance server for delivery to the company server, the identity assurance score and the collection of requirements for the entity to satisfy;

receiving, at the identity assurance server and originating from the company server, informational data corresponding to the collection of requirements completed by the entity;

confirming, at the identity assurance server, that the received informational data matches data previously saved on a database at the identity assurance server; and

notifying the company that the received information data has been confirmed;

wherein a hierarchy of levels comprises the following levels of requirements for granting access to the asset:

first level—ID of user and No Password;

second level—ID and Password;

third level—Description of something the entity knows;

fourth level—Description of something the entity has;

fifth level—Number of social network connections the entity has;

sixth level—Location of the entity;

seventh level—One biometric identifier;

eighth level—Two biometric identifiers;

ninth level—Three biometric identifiers;

tenth level—Financial information corresponding to the entity;

eleventh level—One health identifier;

twelfth level—Second health identifier; and

thirteenth level—DNA (Deoxyribonucleic acid) of the entity.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Mar 25, 2025
From: AVATIER IP, LLC
To: PICCADILLY PATENT FUNDING LLC, AS SECURITY HOLDER
Reel/Frame 070613/0769 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2025
From: AVATIER CORPORATION
To: AVATIER IP, LLC
Reel/Frame 070184/0820 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2024
From: CICCHITTO, NELSON A., MR.
To: AVATIER CORPORATION
Reel/Frame 069710/0819 →
Continuity (5)
Continuation In Part 15626997 · Jun 19, 2017
Division 15052747 · Feb 24, 2016
Provisional Application 62120153 · Feb 24, 2015
Provisional Application 62501027 · May 3, 2017
Related Publication 20180255047A1 · Sep 6, 2018
Cited By (20)
US 12,205,081 US 12,223,684 US 12,250,207 US 12,271,929 US 12,300,059 US 12,321,965 US 12,322,259 US 12,380,420 US 12,462,635 US 12,475,756 US 12,536,643 US 12,541,745 US 12,597,004 US 12,608,687 US 12,621,291 US 12,646,041 US 12,676,045 US 12,725,131 US 12,725,187 US 12,725,200