IP Library Granted Patent US 12,212,709
Granted Patent B2
US 12,212,709 · App. 17/004,921 · Granted Jan 28, 2025

Call authentication at the call center using a mobile device

Inventors: Payas Gupta (Atlanta, GA); Terry Nelms, II (Atlanta, GA)
Assignee: Pindrop Security, Inc.
H04M3/42042H04M3/42059H04W12/068H04M2203/6045
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,212,709
App. No.
17/004,921
Granted
Jan 28, 2025
Kind
B2
Abstract

Embodiments described herein provide for automatically authenticating telephone calls to an enterprise call center. The system disclosed herein builds on the trust of a data channel for the telephony channel. Certain types of authentication information can be received through the telephony channel, as well. But the mobile application associated with the call center system may provide additional or alternative forms of data through the data channel. The system may send requests to a mobile application of a device to provide information that can reliably be assumed to be coming from that particular device, such as a state of the device and/or a user's response to push notifications. In some cases, the authentication processes may be based on quantity and quality of matches between certain metadata or attributes expected to be received from a given device as compared to the metadata or attributes received.

Claims (41)

1. A computer-implemented method comprising:

receiving, by a computer via a first communication channel, an indication of an inbound call from an inbound device, the inbound call purportedly originating from a registered caller;

transmitting, by the computer during the inbound call via a second communication channel using a registered phone number associated with a registered device associated with the registered caller, one or more requests to the registered device associated with the registered caller, a first request of the one or more requests comprising a message notification configured to display a confirmation element at a graphical user interface of the registered device, the first request comprising at least one of: a short message service (SMS) message, a multimedia message service (MMS) message, or a rich communication service (RCS) message;

receiving, by the computer via the second communication channel, one or more responses to the one or more requests from the registered device, the one or more responses including a first response to the first request received according to an input to the confirmation element and one or more attributes of the registered device received with the input to the confirmation element; and

executing, by the computer, an authentication routine to authenticate the inbound call using the one or more responses for the one or more requests, the authentication routine includes applying, by the computer, a machine-learning architecture on one or more attributes of the inbound device of the inbound call purporting to be associated with the registered caller and the one or more attributes of the registered attributes received in the one or more responses and generating, by the computer, an authentication score indicating a degree of similarity between the one or more attributes of the inbound device and the one or more attributes of the registered device received in the one or more responses with the input to the confirmation element; and

authenticating, by the computer, the inbound call based upon whether the authentication score satisfies a threshold.

2. The method according to claim 1 , wherein the computer receives from the registered device a second response to a second request for a first state of the registered device, and wherein the method further comprises:

identifying, by the computer, a second state of the inbound call; and

comparing, by the computer, the second state of the inbound call against the first state of the registered device.

3. The method according to claim 2 , wherein the method further comprises:

comparing, by the computer, the one or more attributes of the registered device received with the confirmation element against the one or more attributes of the inbound device.

4. The method according to claim 1 , wherein the computer transmits the first request via the second communication channel, and wherein the first request comprises a push notification to a mobile application of the registered device.

5. The method according to claim 1 , wherein the computer receives a caller identifier (caller ID) for the registered caller with the indication of the inbound call, and wherein the method further comprises:

identifying, by the computer, in a database a device identifier (device ID) for the registered device associated with the caller ID, wherein the computer transmits the one or more requests to the registered device using the device ID.

6. The method according to claim 1 , further comprising:

in response to receiving the inbound call, authenticating, by the computer, the inbound call according to an initial authentication routine using a set of user credentials received via the first communication channel.

7. The method according to claim 1 , further comprising generating, by the computer, a risk score based upon the one or more responses including device identification data from the registered device and corresponding device identification data from a device that originated the inbound call, wherein the computer authenticates the inbound call in response to determining that the risk score satisfies a threshold score.

8. The method according to claim 1 , further comprising determining, by the computer, whether a device that originated the inbound call has a mobile application associated with a call center system installed.

9. The method according to claim 1 , wherein the first request comprises the confirmation element configured to transmit a negative authentication response from the registered device, and wherein the method further comprises:

determining, by the computer, that the first response to the first request received according to the input to the confirmation element is an affirmative response after a predetermined threshold period of time from transmitting the first request.

10. A system comprising:

a database configured to store a plurality of data records associated with a plurality of registered callers; and

a computer comprising a processor configured to:

receive, via a first communication channel, an indication of an inbound call from an inbound device, the inbound call purportedly originating from a registered caller;

transmit, during the inbound call via a second communication channel using a registered phone number associated with a registered device associated with the registered caller, one or more requests to the registered device associated with the registered caller, a first request of the one or more requests comprising a message notification configured to display a confirmation element at a graphical user interface of the registered device, the first request comprising at least one of: a short message service (SMS) message, a multimedia message service (MMS) message, or a rich communication service (RCS) message;

receive, via the second communication channel, one or more responses to the one or more requests from the registered device, the one or more responses including a first response to the first request received according to an input to the confirmation element and one or more attributes of the registered device received with the input to the confirmation element; and

execute an authentication routine to authenticate the inbound call using the one or more responses for the one or more requests, the authentication routine includes applying a machine-learning architecture on one or more attributes of the inbound device of the inbound call purporting to be associated with the registered device caller and the one or more attributes of the registered attributes received in the one or more responses and generating an authentication score indicating a degree of similarity between the one or more attributes of the inbound device and the one or more attributes of the registered device received in the one or more responses with the input to the confirmation element; and

authenticating, by the computer, the inbound call based upon whether the authentication score satisfies a threshold.

11. The system according to claim 10 , wherein the computer receives from the registered device a second response to a second request for a first state of the registered device, and wherein the computer is further configured to:

identify a second state of the inbound call; and

compare the second state of the inbound call against the first state of the registered device.

12. The system according to claim 11 , wherein the computer is configured to:

compare the one or more attributes of the registered device received with the input to the confirmation element against the one or more attributes of the inbound device.

13. The system according to claim 10 , wherein the computer transmits the first request via the second communication channel, and wherein the first request comprises a push notification to a mobile application of the registered device.

14. The system according to claim 10 , wherein the computer is configured to:

receive a caller identifier (caller ID) for the registered caller with the indication of the inbound call; and

identify in the database a device identifier (device ID) for the registered device associated with the caller ID, wherein the computer transmits the one or more requests to the registered device using the device ID.

15. The system according to claim 10 , wherein in response to receiving the inbound call the computer is further configured to authenticate the inbound call according to an initial authentication routine using a set of user credentials received via the first communication channel.

16. The system according to claim 10 , further comprising generating, by the computer, a risk score based upon the one or more responses including device identification data from the registered device and corresponding device identification data from a device that originated the inbound call, wherein the computer authenticates the inbound call in response to determining that the risk score satisfies a threshold score.

17. The system according to claim 10 , wherein the computer is further configured to determine whether a device that originated the inbound call includes a mobile application associated with a call center system.

18. The system according to claim 10 , wherein the first request comprises the confirmation element configured to transmit a negative authentication response from the registered device, and wherein the computer is configured to determine that the first response is an affirmative response after a predetermined threshold period of time from transmitting the first request.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2024
From: PINDROP SECURITY, INC.
To: HERCULES CAPITAL, INC., AS AGENT
Reel/Frame 067867/0860 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2024
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: PINDROP SECURITY, INC.
Reel/Frame 069477/0962 →
SECURITY INTEREST Recorded Jul 31, 2023
From: PINDROP SECURITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064443/0584 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2020
From: GUPTA, PAYAS; NELMS, TERRY, II
To: PINDROP SECURITY, INC.
Reel/Frame 053619/0545 →
Continuity (4)
Continuation In Part 16287879 · Feb 27, 2019
Provisional Application 62893033 · Aug 28, 2019
Provisional Application 62640826 · Mar 9, 2018
Related Publication 20200396331A1 · Dec 17, 2020
References Cited (77)
US 5949874A · Mark · 1999 [cited by applicant]
US 6021119A · Derks et al. · 2000 [cited by applicant]
US 8046230B1 · Mcintosh · 2011 [cited by applicant]
US 8135119B1 · Zhao et al. · 2012 [cited by applicant]
US 8254541B2 · Cai · 2012 [cited by applicant]
US 8660255B2 · Theivendran et al. · 2014 [cited by applicant]
US 8738442B1 · Liu et al. · 2014 [cited by applicant]
US 8856895B2 · Perrot · 2014 [cited by applicant]
US 9001985B2 · Cox et al. · 2015 [cited by applicant]
US 9060057B1 · Danis · 2015 [cited by applicant]
US 9094519B1 · Shuman · 2015 [cited by examiner]
US 9277049B1 · Danis · 2016 [cited by applicant]
US 9332119B1 · Danis · 2016 [cited by applicant]
US 9338619B2 · Kang · 2016 [cited by applicant]
US 9344892B1 · Rodrigues et al. · 2016 [cited by applicant]
US 9531695B2 · Koppolu et al. · 2016 [cited by applicant]
US 9544440B2 · Deng et al. · 2017 [cited by applicant]
US 9549062B1 · Yaung et al. · 2017 [cited by applicant]
US 9762728B1 · Cox et al. · 2017 [cited by applicant]
US 9781255B1 · Gailloux et al. · 2017 [cited by applicant]
US 9800612B2 · Harvey et al. · 2017 [cited by applicant]
US 9860367B1 · Jiang et al. · 2018 [cited by applicant]
US 9942766B1 · Bonn et al. · 2018 [cited by applicant]
US 10044647B1 · Karp · 2018 [cited by examiner]
US 10142464B1 · Cairns et al. · 2018 [cited by applicant]
US 10149156B1 · Tiku · 2018 [cited by examiner]
US 10389874B1 · Farnsworth et al. · 2019 [cited by applicant]
US 11019203B2 · Gupta · 2021 [cited by examiner]
US 11258896B1 · Cox · 2022 [cited by examiner]
US 20040023644A1 · Montemer · 2004 [cited by examiner]
US 20060142012A1 · Kirchhoff et al. · 2006 [cited by applicant]
US 20070116227A1 · Vitenson et al. · 2007 [cited by applicant]
US 20080219177A1 · Flynn et al. · 2008 [cited by applicant]
US 20080253376A1 · Charzinski · 2008 [cited by examiner]
US 20090080624A1 · Small et al. · 2009 [cited by applicant]
US 20090097630A1 · Fotta · 2009 [cited by applicant]
US 20090138712A1 · Driscoll · 2009 [cited by applicant]
US 20090274143A1 · Garg et al. · 2009 [cited by applicant]
US 20100040216A1 · Chida · 2010 [cited by examiner]
US 20110183652A1 · Eng et al. · 2011 [cited by applicant]
US 20110211572A1 · Campion et al. · 2011 [cited by applicant]
US 20110250874A1 · Shah et al. · 2011 [cited by applicant]
US 20120166185A1 · Zirngibl et al. · 2012 [cited by applicant]
US 20130016819A1 · Cheethirala · 2013 [cited by applicant]
US 20130156170A1 · Springer · 2013 [cited by applicant]
US 20140241513A1 · Springer · 2014 [cited by applicant]
US 20140250512A1 · Goldstone et al. · 2014 [cited by applicant]
US 20140335822A1 · Jain · 2014 [cited by applicant]
US 20150024712A1 · Kang · 2015 [cited by applicant]
US 20150036813A1 · Ananthakrishnan et al. · 2015 [cited by applicant]
US 20150057044A1 · Altman · 2015 [cited by applicant]
US 20150347725A1 · Ben Ari · 2015 [cited by examiner]
US 20150373193A1 · Cook · 2015 [cited by applicant]
US 20160050203A1 · Hefetz · 2016 [cited by examiner]
US 20170060779A1 · Falk · 2017 [cited by applicant]
US 20170163803A1 · Russell · 2017 [cited by applicant]
US 20180365400A1 · Lopez-Hinojosa · 2018 [cited by examiner]
US 20200008021A1 · Polychronidis · 2020 [cited by examiner]
US 20200267224A1 · Doane · 2020 [cited by examiner]
US 20210136200A1 · Li · 2021 [cited by examiner]
US 20220046126A1 · Grabowski · 2022 [cited by examiner]
US 20230362298A1 · Kwok · 2023 [cited by examiner]
US 20240098177A1 · Edwards · 2024 [cited by examiner]
WO WO2018236625A1 · 2018 [cited by applicant]
U.S. Appl. No. 62/928,222, filed Oct. 30, 2019) (Year: 2019). [cited by examiner]
International Search Report corresponding to International Application No. PCT/US2020/048175 dated Dec. 31, 2020. [cited by applicant]
Jiang et al., “Integrating Internet Telephony Services”, Jun. 2002, retrieved on [Oct. 29, 2020]. Retrieved from the Internet <URL: http://cs.uccs.edu/˜cs525/sip/IEEEInternetComputing02_IPTelephony.pdf> entire document. [cited by applicant]
Written Opinion of the International Searching Authority issued in International Application No. PCT/US2020/048175 with Date of Mailing Dec. 31, 2020. [cited by applicant]
Android Phone Application to Detect Malicious Cell Phone Spoofing, https://cse.sc.edu/files/Laurie%20Dening.pdf, Apr. 3, 2018, 8 pages. [cited by applicant]
Mustafa et al., You Can Call But You Can't Hide: Detecting Caller ID Spoofing Attacks, http://ieeexplore.ieee.org/document/6903577/, Jun. 26, 2014, 20 pages. [cited by applicant]
Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, dated May 15, 2019, issued in corresponding International Application No. PCT/US2019/02106… [cited by applicant]
Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, mailed Jul. 10, 2019, in corresponding International Application No. PCT/US19/21062, 12 pa… [cited by applicant]
International Search Report and Written Opinion issued in International Application No. PCT/US2018/013965 with dated May 14, 2018. [cited by applicant]
International Preliminary Report on Patentability for PCT/US2020/048175 dated Mar. 10, 2022 (7 pages). [cited by applicant]
Examination Report No. 1 for Australian app. 2020340368 dated Jan. 31, 2023 (4 pages). [cited by applicant]
Extended European Search Report on EPO App. 20859570.2 dated Aug. 8, 2023 (8 pages). [cited by applicant]
Examiner's Requisition dated Mar. 28, 2024 on CA App. 3, 150,456 (4 pages). [cited by applicant]
Cited By (1)
US 12,457,291