IP Library Granted Patent US 11,005,839
Granted Patent B1
US 11,005,839 · App. 16/298,990 · Granted May 11, 2021

System and method to identify abnormalities to continuously measure transaction risk

Inventors: Nahal Shahidzadeh (Portland, OR); Shahrokh Shahidzadeh (Portland, OR); Haitham Akkary (Portland, OR)
Assignee: Acceptto Corporation
H04L63/0853H04L63/0861H04L63/0876H04L63/18G06Q20/4016H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,005,839
App. No.
16/298,990
Granted
May 11, 2021
Kind
B1
Abstract

Aspects of the disclosure provide techniques for using behavior based information for providing and restricting access to a secure website, or computer network and its assets to a user. Components of the system may include the following. Client remote computing device, network and browser unique attribute data collection and fingerprinting. Method for capturing user habits and fingerprinting with ability to detect abnormalities through AIML using mobile and wearable device applications. System for detection of normality of user behavior based on habits, and cyber transactions, device access and determining a confidence score associated with each transaction. Method for calculating individual transaction risk based on contextual factors such as user behavior, device, browser and the network traffic and request for authentication by account owner when risk greater than allowed threshold. Method and system to identify user device, browser, and behavior unique attributes, storing and later matching to infer change upon consequent transactions and measuring transaction risk through a search and match against classified set of static and dynamic attributes using a user, browser traffic, device search and match engine.

Claims (31)

1. A system for using user entity behavior based information for providing and restricting access to a secure computer network comprising:

a processor coupled to a network interface, the processor configured to:

capture contextual factors of a user entity interacting with a mobile device, wherein the contextual factors include user entity behavior, characteristics of the mobile device, characteristics of a browser, and network traffic;

receive a transaction request from the mobile device;

calculate a transaction risk and confidence score for the transaction request based on the contextual factors; and

compare the transaction risk and confidence score to a predetermined threshold risk score to determine whether the transaction request is approved.

2. The system of claim 1 , wherein a plurality of contextual factors required are increased depending on the level of risk of the transaction request.

3. The system of claim 1 , wherein the contextual factors include at least one from the group consisting of: network unique attribute data collection and fingerprinting; browser unique attribute data collection and fingerprinting; and device fingerprinting.

4. The system of claim 1 , further comprising:

measuring the transaction risk through a search and match against a set of static and dynamic attributes using a user, browser traffic, device search and match engine.

5. The system of claim 1 , further comprising

verifying the identity of the user entity using out-of-band confirmation.

6. The system of claim 5 , wherein the out-of-band confirmation is performed using at least one from a group consisting of:

email, short message service (sms), voice, push, and voice call.

7. The system of claim 1 , wherein the contextual factors may further include at least one of the group of egocentric or allocentric factors consisting of:

mobile device model, mobile device hardware configuration, mobile device operating system, mobile device applications, mobile device web browser version, service set identifier (SSID) of the network WiFi, network information such as IP address, object classes transferred, screen size, font size, language, user entity habits including speed and style of user keyboard entry, mouse strokes, screen touch, adjacent companion mobile device in proximity, biobehavioral data derived from the user entity such as walking gait, trusted locations of the user, haptic-tactic factors derived from hardware sensors embedded inside the device, various specialized sensor data captured by the hardware such as ambient noise, temperature, discrete movement and location of the mobile device, walking and exercise habits of owner, user entity location and user entity driving, transactions on mobile including services, applications used and their frequency and duration including calls, browsing, use of various applications, and exercise routines.

8. A method for using user entity behavior based information for providing and restricting access to a secure computer network comprising:

capturing contextual factors of a user entity interacting with a mobile device, wherein the contextual factors include user entity behavior, characteristics of the mobile device, characteristics of a browser, and network traffic;

receiving a transaction request from the mobile device;

calculating a transaction risk and confidence score for the transaction request based on the contextual factors; and

comparing the transaction risk and confidence score to a predetermined threshold risk score to determine whether the transaction request is approved.

9. The method of claim 8 , wherein a plurality of contextual factors required are increased depending on the level of risk of the transaction request.

10. The method of claim 8 , wherein the contextual factors include at least one from the group consisting of: network unique attribute data collection and fingerprinting; browser unique attribute data collection and fingerprinting; and device fingerprinting.

11. The method of claim 8 , further comprising:

measuring the transaction risk through a search and match against a set of static and dynamic attributes using a user, browser traffic, device search and match engine.

12. The method of claim 8 , further comprising:

verifying the identity of the user entity using out-of-band confirmation.

13. The method of claim 12 , wherein the out-of-band confirmation is performed using at least one from a group consisting of:

email, short message service (sms), voice, push, and voice call.

14. The method of claim 1 , wherein the contextual factors may further include at least one of the group of egocentric or allocentric factors consisting of:

mobile device model, mobile device hardware configuration, mobile device operating system, mobile device applications, mobile device web browser version, service set identifier (SSID) of the network WiFi, network information such as IP address, object classes transferred, screen size, font size, language, user entity habits including speed and style of user keyboard entry, mouse strokes, screen touch, adjacent companion mobile device in proximity, biobehavioral data derived from the user entity such as walking gait, trusted locations of the user, haptic-tactic factors derived from hardware sensors embedded inside the device, various specialized sensor data captured by the hardware such as ambient noise, temperature, discrete movement and location of the mobile device, walking and exercise habits of owner, user entity location and user entity driving, transactions on mobile including services, applications used and their frequency and duration including calls, browsing, use of various applications, and exercise routines.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: ACCEPTTO CORPORATION
Reel/Frame 070086/0470 →
RELEASE OF SECURITY INTEREST Recorded Aug 14, 2024
From: MIDTOWN MADISON MANAGEMENT LLC (AS SUCCESSOR TO ELM PARK CAPITAL MANAGEMENT, LLC)
To: ACCEPTTO CORPORATION
Reel/Frame 068288/0686 →
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2024
From: PNC BANK, NATIONAL ASSOCIATION
To: ACCEPTTO CORPORATION
Reel/Frame 068250/0987 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2022
From: ACCEPTTO CORPORATION
To: SECUREAUTH CORPORATION
Reel/Frame 059152/0521 →
SECURITY INTEREST Recorded Dec 14, 2021
From: ACCEPTTO CORPORATION
To: ELM PARK CAPITAL MANAGEMENT, LLC
Reel/Frame 058386/0330 →
SECURITY INTEREST Recorded Dec 14, 2021
From: ACCEPTTO CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 058384/0501 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2019
From: SHAHIDZADEH, NAHAL; SHAHIDZADEH, SHAHROKH; AKKARY, HAITHAM
To: ACCEPTTO CORPORATION
Reel/Frame 048579/0722 →
Continuity (1)
Provisional Application 62641362 · Mar 11, 2018
Cited By (35)
US 12,206,763 US 12,212,959 US 12,225,032 US 12,238,101 US 12,244,599 US 12,255,906 US 12,267,314 US 12,282,917 US 12,284,512 US 12,289,328 US 12,289,329 US 12,294,482 US 12,301,600 US 12,302,451 US 12,309,152 US 12,330,587 US 12,335,399 US 12,335,410 US 12,341,790 US 12,381,902 US 12,395,353 US 12,399,999 US 12,425,230 US 12,425,384 US 12,438,731 US 12,438,774 US 12,443,700 US 12,445,305 US 12,499,201 US 12,499,437 US 12,519,775 US 12,519,826 US 12,538,123 US 12,659,330 US 12,682,341