IP Library Granted Patent US 10,951,606
Granted Patent B1
US 10,951,606 · App. 17/112,913 · Granted Mar 16, 2021

Continuous authentication through orchestration and risk calculation post-authorization system and method

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,951,606
App. No.
17/112,913
Granted
Mar 16, 2021
Kind
B1
Abstract

A system and method for secure authentication of user entity and user entity device identity. The system and method described herein allows an identity to be continuously proven because of user entity's behavior and their biometrics. With all the fraud and risk that exists today, if someone has a user entity's driver's license they can do a lot of harm. A primary identity provider receives user contextual and behavioral information from third party secondary identity providers to allow risk based continuous authentication and step up post-authorization authentication or termination of session as required upon detection of an anomaly by third party identity provider.

Claims (15)

1. A method for secure authentication of a user entity identity comprising:

a primary identity provider allows a user entity through a client device to enable a single sign on to a plurality of services;

the primary identity provider collects the contextual and behavioral information of the user entity and the client device for access to at least one service of the plurality of services;

the primary identity provider delegates login and authentication process including a risk based multi-factor authentication to a third party identity provider;

the third party identity provider sends the contextual and behavioral information including at least one service identifier, a user identification, the client device, client device browser health, location, time, network, client device and client device browser fingerprint, and other attributes to a discrete risk engine of the third party identity provider; and

conducts policy orchestration upon detection of anomaly of the at least one service and takes a predetermined action per policy and risk including terminating the specific service and session or step up authentication using a new discrete multi-factor authentication.

2. The method of claim 1 , wherein the third party identity provider requests for step up or termination of more than a session of the at least one service associated with the user entity.

3. The method of claim 1 , wherein the third party identity provider requests for step up or termination of more than the specific session of services associated with the user entity and terminates or steps up additional services such as another service.

4. The method of claim 1 , wherein additional contextual data about a service provider state is streamed or batched via a smart data hub of the third party identity provider and make a primary identity provider aware of the context of the service provider by requesting step up authentication.

5. The method of claim 1 wherein smart multifactor authentication is provided via security assertion markup language version 2 (SAML 2.0) or open identification connection authentication (OIDC).

6. The method of claim 1 , further comprising:

monitoring the client device by the risk engine during an active session to provide updates to the primary identity provider if an anomaly occurs during the active session.

7. The method of claim 1 , wherein the risk engine is operated by artificial intelligence.

8. The method of claim 1 , wherein the client device contextual factors and network contextual factors further include at least one of the group of egocentric or allocentric factors consisting of:

mobile device model, mobile device hardware configuration, mobile device operating system, mobile device applications, mobile device web browser version, service set identifier (SSID) of the network WiFi, network information such as IP address, object classes transferred, screen size, font size, language, user entity habits including speed and style of user keyboard entry, mouse strokes, screen touch, adjacent companion mobile device in proximity, bio-behavioral data derived from the user entity such as walking gait, trusted locations of the user, haptic-tactic factors derived from hardware sensors embedded inside the device, various specialized sensor data captured by the hardware such as ambient noise, temperature, discrete movement and location of the mobile device, walking and exercise habits of owner, user entity location and user entity driving, transactions on mobile including services, applications used and their frequency and duration including calls, browsing, use of various applications, exercise routines, payments, user behavior analytics (UBA) services, identification authorization and proofing, secure data access, crowd control, safety, check-in and check-out services, short message service (SMS) concierge services, promotions, and location based service (LBS) functions.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: ACCEPTTO CORPORATION
Reel/Frame 070086/0470 →
RELEASE OF SECURITY INTEREST Recorded Aug 14, 2024
From: MIDTOWN MADISON MANAGEMENT LLC (AS SUCCESSOR TO ELM PARK CAPITAL MANAGEMENT, LLC)
To: ACCEPTTO CORPORATION
Reel/Frame 068288/0686 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2024
From: PNC BANK, NATIONAL ASSOCIATION
To: ACCEPTTO CORPORATION
Reel/Frame 068250/0987 →
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2022
From: ACCEPTTO CORPORATION
To: SECUREAUTH CORPORATION
Reel/Frame 059152/0521 →
SECURITY INTEREST Recorded Dec 14, 2021
From: ACCEPTTO CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 058384/0501 →
SECURITY INTEREST Recorded Dec 14, 2021
From: ACCEPTTO CORPORATION
To: ELM PARK CAPITAL MANAGEMENT, LLC
Reel/Frame 058386/0330 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2020
From: SHAHIDZADEH, NAHAL; SHAHIDZADEH, SHAHROKH; AKKARY, HAITHAM; CLIFFORD, CHRISTOPHER; KARIMIKHO, SEYEDAMIR
To: ACCEPTTO CORPORATION
Reel/Frame 054599/0343 →