IP Library Granted Patent US 11,232,428
Granted Patent B2
US 11,232,428 · App. 16/426,064 · Granted Jan 25, 2022

System for securing user information by employing phone number and personal identification number

Inventor: Karim Anwar Rammal (New York, NY)
Assignee: BOLORO GLOBAL LIMITED
G06Q20/32G06Q20/12G06Q20/16G06Q20/20G06Q20/322G06Q20/325G06Q20/3255G06Q20/382G06Q20/3821G06Q20/38215G06Q20/40G06Q20/425H04L12/14H04L12/1467H04L63/0428H04L63/0892H04L63/126G06Q20/00G06Q20/30G06Q20/4012
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,232,428
App. No.
16/426,064
Granted
Jan 25, 2022
Kind
B2
Abstract

A system, method and computer program product for securing user information, including processing circuitry that receives an encrypted first request from a first party and that includes a unique identifier associated with an account of a user, sends, based on the encrypted first request, an encrypted authorization request to an operator servicing the account of the user, and receives, in response to the encrypted authorization request, an authorization from the operator based on a result of an authorization message exchange for authorizing or not authorizing the request sent by the operator to a device associated with the user over a network controlled by the operator. No pecuniary information of the user nor the personal identification number of the user is received by the processing circuitry thereby shielding the pecuniary information of the user from the first party.

Claims (51)

1. A system for securing user information, the system comprising:

a mobile phone operator that services an account of a user associated with a phone number of the user; and

processing circuitry configured to:

receive an encrypted first request from a first party that creates a requirement for the user, the encrypted first request received from the first party including the phone number of the user and the encrypted first request from the first party including data identifying the mobile phone operator, and

send, based on the encrypted first request, an encrypted authorization request to the mobile phone operator,

wherein the mobile phone operator is configured to:

receive the encrypted authorization request from the processing circuitry,

initiate, in response to the encrypted authorization request, an authorization message exchange for authorizing or not authorizing the first request with a device associated with the user using a text messaging service over a network controlled by the mobile phone operator, the authorization message exchange including transmission of a personal identification number of the user directly to the mobile phone operator in response to a request for authorization of the first request from the mobile phone operator to the user, and

send a response to the encrypted authorization request to the processing circuitry based upon a result of the authorization message exchange,

wherein the processing circuitry is further configured to:

if the response to the encrypted authorization request from the mobile phone operator authorizes the request, satisfy the requirement of the first party from resources of the mobile phone operator,

if the response to the encrypted authorization request from the mobile phone operator does not authorize the request or if an authorization message is not received by the mobile phone operator over the network within a predetermined period of time, decline to satisfy the requirement of the first party,

wherein the first party is configured to send a message directly to the user including information regarding processing of the encrypted authorization request, and

wherein the personal identification number of the user, transmitted to the mobile phone operator in response to the request for authorization of the first request, is not received by the processing circuitry and is not received by the first party thereby shielding the personal identification number of the user from the first party.

2. The system of claim 1 , wherein the mobile phone operator is configured to check protocols of the account of the user for processing the encrypted authorization request.

3. The system of claim 1 , wherein the encrypted authorization request includes details of the first party.

4. The system of claim 1 , wherein the text messaging service is a Short Messaging Service (SMS).

5. A computer implemented method for securing user information, the method comprising:

via a mobile phone operator:

servicing an account of a user associated with a phone number of the user, via processing circuitry:

receiving an encrypted first request from a first party that creates a requirement for the user, the encrypted first request received from the first party including the phone number of the user and the encrypted first request from the first party including data identifying the mobile phone operator; and

sending, based on the encrypted first request, an encrypted authorization request to the mobile phone operator,

via the mobile phone operator:

receiving the encrypted authorization request from the processing circuitry;

initiating, in response to the encrypted authorization request, an authorization message exchange for authorizing or not authorizing the first request with a device associated with the user using a text messaging service over a network controlled by the mobile phone operator, the authorization message exchange including transmission of a personal identification number of the user directly to the mobile phone operator in response to a request for authorization of the first request from the mobile phone operator to the user; and

sending a response to the encrypted authorization request to the processing circuitry based upon a result of the authorization message exchange,

via the processing circuitry:

if the response to the encrypted authorization request from the mobile phone operator authorizes the request, satisfying the requirement of the first party from resources of the mobile phone operator;

if the response to the encrypted authorization request from the mobile phone operator does not authorize the request or if an authorization message is not received by the mobile phone operator over the network within a predetermined period of time, declining to satisfy the requirement of the first party, and

sending, from the first party, a message directly to the user including information regarding processing of the encrypted authorization request,

wherein the personal identification number of the user, transmitted to the mobile phone operator in response to the request for authorization of the first request, is not received via the processing circuitry and is not received by the first party thereby shielding the personal identification number of the user from the first party.

6. The method of claim 5 , further comprising checking, via the mobile phone operator, protocols of the account of the user for processing the encrypted authorization request.

7. The method of claim 5 , wherein the encrypted authorization request includes details of the first party.

8. The method of claim 5 , wherein the text messaging service is a Short Messaging Service (SMS).

9. A computer program product for securing user information and including one or more computer readable instructions embedded on a tangible, non-transitory computer readable medium and configured to cause one or more computer processors to implement a method comprising:

via a mobile phone operator:

servicing an account of a user associated with a phone number of the user, via processing circuitry:

receiving an encrypted first request from a first party that creates a requirement for the user, the encrypted first request received from the first party including the phone number of the user and the encrypted first request from the first party including data identifying the mobile phone operator; and

sending, based on the encrypted first request, an encrypted authorization request to the mobile phone operator,

via the mobile phone operator:

receiving the encrypted authorization request from the processing circuitry;

initiating, in response to the encrypted authorization request, an authorization message exchange for authorizing or not authorizing the first request with a device associated with the user using a text messaging service over a network controlled by the mobile phone operator, the authorization message exchange including transmission of a personal identification number of the user directly to the mobile phone operator in response to a request for authorization of the first request from the mobile phone operator to the user; and

sending a response to the encrypted authorization request to the processing circuitry based upon a result of the authorization message exchange,

via the processing circuitry:

if the response to the encrypted authorization request from the mobile phone operator authorizes the request, satisfying the requirement of the first party from resources of the mobile phone operator;

if the response to the encrypted authorization request from the mobile phone operator does not authorize the request or if an authorization message is not received by the mobile phone operator over the network within a predetermined period of time, declining to satisfy the requirement of the first party, and

sending, from the first party, a message directly to the user including information regarding processing of the encrypted authorization request,

wherein the personal identification number of the user, transmitted to the mobile phone operator in response to the request for authorization of the first request, is not received via the processing circuitry and is not received by the first party thereby shielding the personal identification number of the user from the first party.

10. The computer program product of claim 9 , wherein the method further comprises checking, via the mobile phone, protocols of the account of the user for processing the encrypted authorization request.

11. The computer program product of claim 9 , wherein the encrypted authorization request includes details of the first party.

12. The computer program product of claim 9 , wherein the text messaging service is a Short Messaging Service (SMS).

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2021
From: RAMMAL, KARIM ANWAR
To: NET2TEXT LTD
Reel/Frame 058385/0228 →
CHANGE OF NAME Recorded Aug 26, 2019
From: NET2TEXT LIMITED
To: BOLORO GLOBAL LIMITED
Reel/Frame 050163/0813 →
Continuity (4)
Division 14222613 · Mar 22, 2014
Continuation 13148043
Provisional Application 61152696 · Feb 14, 2009
Related Publication 20200175513A1 · Jun 4, 2020