IP Library Granted Patent US 11,101,993
Granted Patent B1
US 11,101,993 · App. 17/140,016 · Granted Aug 24, 2021

Authentication and authorization through derived behavioral credentials using secured paired communication devices

Inventors: Nahal Shahidzadeh (Portland, OR); Shahrokh Shahidzadeh (Portland, OR); Haitham Akkary (Portland, OR); Frank Stefan Ulbrich (Karlsruhe, DE); Mani Malekmohammadi (North Vancouver, CA)
Assignee: Acceptto Corporation
H04L9/0866G06F21/32G06F21/35G06F21/45H04L9/0891H04L9/0897
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,101,993
App. No.
17/140,016
Granted
Aug 24, 2021
Kind
B1
Abstract

A system and method for biobehavorial identification may include a user device, a secure system/client device, and a server. The elements of the system work together to monitor the biologic features (e.g., fingerprints, pupils, or the like) and behavior (e.g., wake time, exercise time, location) to verify the authenticity of a user requesting access to a database and/or secure facility.

Claims (44)

1. A system comprising:

a first mobile device having a first network interface configured to be communicatively coupled to a network utilizing a secure communication protocol and at least one first hardware processor of a plurality of hardware processors coupled to a first memory and configured to:

receive a first security code key and embed the first security code key in the first memory;

monitor behavior of a user entity of the first mobile device and compare the behavior against an identity confidence threshold and generate a second security code key based on meeting the identity confidence threshold;

a client device cryptographically paired with the first mobile device and wherein the client device has a network interface configured to be communicatively coupled to the network utilizing the secure communication protocol and at least one second hardware processor of a plurality of hardware processors coupled to a second memory and configured to: generate a third security code key from authentication software based on the first security code key and second security code key being valid and meeting a threshold and the authentication of the user entity of interest identity, send the third security code key to a risk engine for approval, and receive approval from the risk engine; and

synchronize behavioral data collected by the client device with the first mobile device.

2. The system of claim 1 , wherein the first mobile device is further configured to: graph behavior of the user entity of the first mobile device to create the identity confidence threshold.

3. The system of claim 2 , wherein the behavior graphed by the first mobile device includes at least one from the group consisting of: location where a user wakes up, where the user drives to, and if user is deemed normal against a derived collection of the user habits.

4. The system of claim 1 , wherein the third security code key is temporal.

5. The system of claim 1 , wherein the client device is capable of monitoring behavior of the user entity and transferring information of the behavioral to the first mobile device along with the third security code key as a biobehavioral derived credential.

6. The system of claim 1 , wherein that at least one second hardware processor of a plurality of hardware processors is further configured to: continuously update the third security code key and remains valid as long as time validity of the third security code key has not expired, the user entity of a second mobile device has not misbehaved and anomaly from measured normal behavior has not occurred.

7. The system of claim 1 wherein that at least one second hardware processor of a plurality of hardware processors is further configured to: continuously authenticate during a post authorization period to measure security posture consistency beyond the authentication.

8. The system of claim 1 wherein that at least one second hardware processor of a plurality of hardware processors is further configured to: continuously authenticate during a post authorization period to measure security posture consistency beyond the authentication and use predictive analytics to predict next most likely action and detect anomalies when predictions are not met.

9. A system comprising:

a client device having a network interface configured to be communicatively coupled to a network utilizing a secure communication protocol and at least one first hardware processor of a plurality of first hardware processors configured to:

request a transaction from a relying party;

request authentication from a user entity using authentication software and receive a first security code key;

notify a risk engine of an authentication request;

create a second security code key based on user entity behavior meeting an identity confidence threshold in a trusted execution environment;

send an out of band signal to a user entity device for multifactor authentication;

receive the out of band signal to create a third security code;

authorize access to the client device based on a first security code, a second security code and a third security code;

measure risk score continuously;

update the second key and the third key to provide continuous authentication; and

synchronize behavioral data collected by the client device with the risk engine.

10. A system comprising:

a first mobile device having a first network interface configured to be communicatively coupled to a network utilizing a secure communication protocol and at least one first hardware processor of a plurality of hardware processors coupled to a first memory and configured to:

receive a first security code key and embed the first security code key in the first memory;

monitor a behavior of the user of the first mobile device and compare the behavior against an identity confidence threshold and generate a second security code key based meeting the identity confidence threshold;

a client device cryptographically paired with the first mobile device and wherein the client device has a network interface configured to be communicatively coupled to the network utilizing the secure communication protocol and at least one second hardware processor of a plurality of hardware processors coupled to a second memory and configured to:

generate a third security code key from authentication software based on the first security code key and second security code key being valid and meeting a threshold and the authentication of a user of interest identity;

send the third security code key to a risk engine for multifactor authentication with the first mobile device;

receive a multifactor authentication signal and unlock access to the client device; and

synchronize behavioral data collected by the client device with the first mobile device.

11. A system comprising:

a client device having a network interface configured to be communicatively coupled to a network utilizing a secure communication protocol and at least one first hardware processor of a plurality of first hardware processors configured to:

request a transaction from a relying party;

request authentication from a user entity using authentication software and receive a first security code key;

create a second security code key based on user entity behavior meeting an identity confidence threshold in a trusted execution environment;

create a third security code key based on the first and second security code keys;

send an authorization request including the third security code key to a risk engine for out of band multifactor authentication with a user entity device;

receive a multifactor authentication signal from the risk engine to create a third security code; and

authorize access to the client device based on the first security code, second security code and third security code; and

continually monitor the user entity behavior with the client device by the risk engine.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: ACCEPTTO CORPORATION
Reel/Frame 070086/0470 →
RELEASE OF SECURITY INTEREST Recorded Aug 14, 2024
From: MIDTOWN MADISON MANAGEMENT LLC (AS SUCCESSOR TO ELM PARK CAPITAL MANAGEMENT, LLC)
To: ACCEPTTO CORPORATION
Reel/Frame 068288/0686 →
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2024
From: PNC BANK, NATIONAL ASSOCIATION
To: ACCEPTTO CORPORATION
Reel/Frame 068250/0987 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2022
From: ACCEPTTO CORPORATION
To: SECUREAUTH CORPORATION
Reel/Frame 059152/0521 →
SECURITY INTEREST Recorded Dec 14, 2021
From: ACCEPTTO CORPORATION
To: ELM PARK CAPITAL MANAGEMENT, LLC
Reel/Frame 058386/0330 →
SECURITY INTEREST Recorded Dec 14, 2021
From: ACCEPTTO CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 058384/0501 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2021
From: SHAHIDZADEH, NAHAL; SHAHIDZADEH, SHAHROKH; AKKARY, HAITHAM; ULBRICH, FRANK STEFAN; MALEKMOHAMMADI, MANI
To: ACCEPTTO CORPORATION
Reel/Frame 055003/0556 →
Continuity (2)
Continuation 16249772 · Jan 16, 2019
Provisional Application 62618066 · Jan 16, 2018
Cited By (8)
US 12,198,138 US 12,393,669 US 12,438,731 US 12,499,201 US 12,513,128 US 12,526,315 US 12,537,688 US 12,538,123