IP Library Granted Patent US 11,096,059
Granted Patent B1
US 11,096,059 · App. 17/140,018 · Granted Aug 17, 2021

System and method for secure touchless authentication of user paired device, behavior and identity

Inventor: Shahrokh Shahidzadeh (Portland, OR)
Assignee: Acceptto Corporation
H04W12/69G06Q50/10H04W4/029H04W12/06H04W12/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,096,059
App. No.
17/140,018
Granted
Aug 17, 2021
Kind
B1
Abstract

A system and method for secure authentication of user entity and user entity device identity. The system and method described herein allows an identity to be continuously proven because of user entity's behavior and their biometrics. With all the fraud and risk that exists today, if someone has a user entity's driver's license they can do a lot of harm. By tying a user entity's identity to their user entity device (e.g., a mobile smartphone), then when a user entity enters a location (e.g., airport, hotel, bank), the user entity device announces through a wireless “I Am Here” signal which starts a process of continuous authentication while the user entity device interacts with the services offered by the location.

Claims (57)

1. A method for secure authentication of a user entity identity comprising:

monitoring a user entity device by an identity provider for a first time period to collect contextual, biometric and behavioral factors of the user entity operating the user entity device;

receiving from a first mobile application programming interface located on the user entity device through a first secure communication link an announcement of the arrival of a user entity device at a second application programming interface of a first relying party and checking for a reservation for the user entity associated with the user entity device;

if the reservation is found, sending a user entity identity match request from the first relying party to the identity provider to start an active session;

collecting the contextual, biometric and behavioral factors of the user entity interacting with the user entity device over a second time period at the identity provider to determine a trust score for the user entity based on the contextual, biometric and behavioral factors collected during both the first and second time periods;

comparing the trust score to a level of assurance required by the first relying party;

sending a notification to the user entity device from the identity provider through a second secure communication link for authentication;

receiving a confirmation from the user entity device using a third secure communication link of the identity of the user entity at the identity provider;

sending a first authentication signal from the identity provider to the first relying party and a second relying party;

sending a user identity match request to the identity provider from the second relying party; and

updating the contextual, biometric and behavioral factors of the user entity interacting with the user entity device during the active session at the identity provider to determine an updated trust score for the user entity and comparing the updated trust score to a level of assurance required by the second relying party.

2. The method of claim 1 further comprising:

sending a notification to the user entity device from the identity provider for authentication based on both biometric and behavioral factors;

receiving a confirmation from the user entity device of the identity of the user entity at the identity provider; and

sending a second authentication signal to the second relying party.

3. The method of claim 1 , further comprising:

monitoring the user entity device by the identity provider during the active session to provide updates to the first relying party and a second relying party of the location and estimated time of arrival of the user entity device.

4. The method of claim 3 , further comprising:

notifying the first and second relying parties if an anomaly occurs during the active session in the schedule of the user entity device.

5. The method of claim 1 , further comprising:

receiving at the first relying party concierge services information on the user entity from at least one of the group consisting of: predictive services, social data analytics, analytics, air travel experience partners, location based services (LBS) and travel applications, corporate travel products, airlines, hospitality and loyalty programs, and points exchange; and

determining at the first relying party which concierge services to offer to send to the user entity device.

6. The method of claim 5 , wherein the concierge services are received from a third party database.

7. The method of claim 1 , wherein the check-in site is a virtual check-in.

8. The method of claim 7 , wherein the virtual check-in is operated by artificial intelligence.

9. The method of claim 1 , wherein the check-in is contactless.

10. The method of claim 1 , wherein the user entity contextual factors and network contextual factors may further include at least one of the group of egocentric or allocentric factors consisting of:

a user entity device model, a user entity device hardware configuration, a user entity device operating system, user entity device applications, user entity device web browser version, service set identifier (SSID) of the network WiFi, information of the network including an internet protocol (IP) address, object classes transferred, information of the user entity device including screen size, font size, language, user entity habits including speed and style of user keyboard entry, mouse strokes, screen touch, adjacent companion user entity device in proximity, biobehavioral data derived from the user entity including walking gait, trusted locations of the user entity device, haptic-tactic factors derived from hardware sensors embedded inside the user entity device, various specialized sensor data captured by the user entity hardware including ambient noise, temperature, discrete movement and location of the user entity device, walking and exercise habits of the user entity, user entity location and user entity driving, transactions on the user entity device including services, applications used and their frequency and duration including calls, browsing, use of various applications, exercise routines, payments, user entity behavior analytics services, identification authorization and proofing, secure data access, crowd control, safety, check-in and check out services, short message service (SMS) concierge services, promotions, and location based service (LBS) functions.

11. A system for secure authentication of a user entity identity comprising:

a processor coupled to a network interface, the processor configured to:

monitor a user entity device by an identity provider for a first time period to collect contextual, biometric and behavioral factors of the user entity operating the user entity device;

receive from a first mobile application programming interface located on the user entity device through a first secure communication link an announcement of the arrival of a user entity device at a second application programming interface of a first relying party and checking for a reservation for the user entity associated with the user entity device;

if the reservation is found, send a user entity identity match request from the first relying party to the identity provider to start an active session;

collect the contextual, biometric and behavioral factors of the user entity interacting with the user entity device over a second predetermined time period at the identity provider to determine a trust score for the user entity based on the contextual, biometric and behavioral factors collected during both the first and second predetermined time periods;

compare the trust score to a level of assurance required by the first relying party;

send a notification to the user entity device from the identity provider using a second secure communication link for authentication based on behavioral factors;

receive a confirmation from the user entity device using a third secure communication link of the identity of the user entity at the identity provider;

send a first authentication signal from the identity provider to the first relying party and a second relying party;

send a user identity match request to the identity provider from the second relying party;

update the contextual, biometric and behavioral factors of the user entity interacting with the user entity device during the active session at the identity provider to determine an updated trust score for the user entity and compare the updated trust score to a level of assurance required by the second relying party.

12. The system of claim 11 wherein the processor is further configured to:

send a notification to the user entity device from the identity provider for authentication based on both biometric and behavioral factors;

receive a confirmation from the user entity device of the identity of the user entity at the identity provider; and

send a second authentication signal to the second relying party.

13. The system of claim 11 wherein the processor is further configured to:

monitor the user entity device by the identity provider during the active session to provide updates to the first relying part and a second relying party of the location and estimated time of arrival of the user entity device.

14. The system of claim 13 wherein the processor is further configured to:

notify the first and second relying parties if an anomaly occurs during the active session in the schedule of the user entity device.

15. The system of claim 11 wherein the processor is further configured to:

receive at the first relying party concierge services information on the user entity from at least one of the group consisting of: predictive services, social data analytics, analytics, air travel experience partners, location based services (LBS) and travel applications, corporate travel products, airlines, hospitality and loyalty programs, and points exchange; and

determine at the first relying party which concierge services to offer to send to the user entity device.

16. The system of claim 15 , wherein the concierge services are received from a third party database.

17. The system of claim 11 , wherein the check-in site is a virtual check-in.

18. The system of claim 17 , wherein the virtual check-in is operated by artificial intelligence.

19. The system of claim 11 , wherein the check-in is contactless.

20. The system of claim 11 wherein the user entity contextual factors and network contextual factors may further include at least one of the group of egocentric or allocentric factors consisting of:

a user entity device model, a user entity device hardware configuration, a user entity device operating system, user entity device applications, user entity device web browser version, service set identifier (SSID) of the network WiFi, information of the network including an internet protocol (IP) address, object classes transferred, information of the user entity device including screen size, font size, language, user entity habits including speed and style of user keyboard entry, mouse strokes, screen touch, adjacent companion user entity device in proximity, biobehavioral data derived from the user entity including walking gait, trusted locations of the user entity device, haptic-tactic factors derived from hardware sensors embedded inside the user entity device, various specialized sensor data captured by the user entity hardware including ambient noise, temperature, discrete movement and location of the user entity device, walking and exercise habits of the user entity, user entity location and user entity driving, transactions on the user entity device including services, applications used and their frequency and duration including calls, browsing, use of various applications, exercise routines, payments, user entity behavior analytics services, identification authorization and proofing, secure data access, crowd control, safety, check-in and check out services, short message service (SMS) concierge services, promotions, and location based service (LBS) functions.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: ACCEPTTO CORPORATION
Reel/Frame 070086/0470 →
RELEASE OF SECURITY INTEREST Recorded Aug 14, 2024
From: MIDTOWN MADISON MANAGEMENT LLC (AS SUCCESSOR TO ELM PARK CAPITAL MANAGEMENT, LLC)
To: ACCEPTTO CORPORATION
Reel/Frame 068288/0686 →
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2024
From: PNC BANK, NATIONAL ASSOCIATION
To: ACCEPTTO CORPORATION
Reel/Frame 068250/0987 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2022
From: ACCEPTTO CORPORATION
To: SECUREAUTH CORPORATION
Reel/Frame 059152/0521 →
SECURITY INTEREST Recorded Dec 14, 2021
From: ACCEPTTO CORPORATION
To: ELM PARK CAPITAL MANAGEMENT, LLC
Reel/Frame 058386/0330 →
SECURITY INTEREST Recorded Dec 14, 2021
From: ACCEPTTO CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 058384/0501 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2021
From: SHAHIDZADEH, SHAHROKH
To: ACCEPTTO CORPORATION
Reel/Frame 055010/0149 →
Continuity (2)
Continuation In Part 16984570 · Aug 4, 2020
Provisional Application 62882605 · Aug 4, 2019
Cited By (10)
US 12,210,496 US 12,212,567 US 12,218,940 US 12,238,101 US 12,242,440 US 12,299,094 US 12,356,184 US 12,368,756 US 12,519,826 US 12,526,315