IP Library Granted Patent US 11,818,272
Granted Patent B2
US 11,818,272 · App. 17/323,450 · Granted Nov 14, 2023

Methods and systems for device authentication

Inventor: Steven Todd Kirsch (Los Altos Hills, CA)
Assignee: NEUSTAR, INC.
H04L9/3247G06F21/31G06F21/335H04L9/14H04L9/30H04L9/3263H04L63/06H04L63/08H04L63/0823H04L63/0869H04L63/12G06F2221/2103H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,818,272
App. No.
17/323,450
Granted
Nov 14, 2023
Kind
B2
Abstract

A method for disabling a device associated with a virtual identity may include receiving, from the device, a request to use the virtual identity, where the request that may include a passcode guess and a device identifier. The method may also include determining that the passcode guess does not authorize use of the virtual identity and incrementing a number of incorrect passcode guesses received within a time interval. The method may additionally include determining that the number of incorrect passcode guesses received within the time interval is greater than or equal to a threshold. The method may further include storing an indication that subsequent requests associated with the device identifier should not authorize use of the virtual identity.

Claims (64)

1. A method for disabling a device associated with a virtual identity, the method comprising:

receiving, from the device, a request to use the virtual identity, the request comprising:

a passcode guess comprising a hash of a salted password; and

a device identifier;

cryptographically transforming the passcode guess to obscure its value;

comparing the passcode guess to a value previously stored in a repository;

determining whether the passcode guess does not authorize use of the virtual identity based on comparing the passcode guess to the value previously stored in the repository;

incrementing a number of incorrect passcode guesses received within a time interval, wherein the incrementing is based on predetermined values for a type of transaction,

wherein the type of transaction includes using a Level of Assurance (LOA) mode, the LOA mode comprising: a disabled mode, an enabled with no security mode, a password with a timeout mode, or an out-of-band (OOB) authorization required with an optional pin and timeout mode;

determining that the number of incorrect passcode guesses received within the time interval is greater than or equal to a threshold;

storing an indication that subsequent requests associated with the device identifier and transaction type should not authorize the use of the virtual identity; and

resetting the number of incorrect passcode guesses when a valid passcode guess is received.

2. The method of claim 1 , wherein one or more user devices associated with the virtual identity are allowed to provide correct passcode guesses and authorize the use of the virtual identity.

3. The method of claim 1 , wherein the passcode guess is based on a PIN.

4. The method of claim 1 , further comprising sending, to one or more user devices associated with the virtual identity, an indication that the device cannot authorize the use of the virtual identity.

5. The method of claim 4 , wherein the indication that the device cannot authorize the use of the virtual identity comprises a push notification to a smart phone.

6. The method of claim 1 , further comprising:

receiving, from an authorized user device:

a second passcode guess; and

an indication that the device should be reauthorized;

determining that the second passcode guess authorizes the use of the virtual identity; and

determining that the subsequent requests associated with the device identifier can authorize the use of the virtual identity.

7. A method for disabling a device associated with a virtual identity, the method comprising:

receiving, from the device, a request to register an unregistered device, the request comprising:

a passcode guess comprising a hash of a salted password; and

a device identifier;

cryptographically transforming the passcode guess to obscure its value;

comparing the passcode guess to a value previously stored in a repository;

determining whether the passcode guess does not authorize registration of the unregistered device based on comparing the passcode guess to the value previously stored in the repository;

incrementing a number of incorrect passcode guesses received within a time interval, wherein the incrementing is based on predetermined values for a type of transaction,

wherein the type of transaction includes using a Level of Assurance (LOA) mode, the LOA mode comprising: a disabled mode, an enabled with no security mode, a password with a timeout mode, or an out-of-band (OOB) authorization required with an optional pin and timeout mode;

determining that the number of incorrect passcode guesses received within the time interval is greater than or equal to a threshold;

storing an indication that subsequent requests associated with the device identifier and transaction type should not register unregistered devices; and

resetting the number of incorrect passcode guesses when a valid passcode guess is received.

8. The method of claim 7 , further comprising sending the indication that subsequent requests associated with the device identifier should not register unregistered devices to a pairing repository.

9. The method of claim 7 , further comprising:

receiving the request to register a second unregistered device, the request comprising:

a second passcode guess; and

the device identifier;

denying the request to register the second unregistered device based on the stored indication.

10. The method of claim 7 , wherein the passcode guess comprises a digital signature derived from a user-provided passcode.

11. The method of claim 7 , wherein the unregistered device comprises a smart phone.

12. The method of claim 7 , wherein the request to register the unregistered device further comprises an encrypted salt value.

13. The method of claim 7 , wherein the request to register the unregistered device further comprises a pairing code.

14. An identity repository comprising:

one or more interfaces that receive requests from user devices;

one or more processors; and

one or more memories communicatively coupled to the one or more processors, having instructions stored thereon, which, when executed by the one or more processors, cause the one or more processors to:

receive a request from the user devices through the one or more interfaces, the request comprising:

a passcode guess comprising a hash of a salted password; and

a device identifier;

cryptographically transform the passcode guess to obscure its value;

compare the passcode guess to a value previously stored in a repository;

determine whether the passcode guess does not authorize use of a virtual identify based on comparing the passcode guess to the value previously stored in the repository;

increment a number of incorrect passcode guesses received within a time interval, wherein the incrementing is based on predetermined values for a type of transaction,

wherein the type of transaction includes using a Level of Assurance (LOA) mode, the LOA mode comprising: a disabled mode, an enabled with no security mode, a password with a timeout mode, or an out-of-band (OOB) authorization required with an optional pin and timeout mode;

determine that the number of incorrect passcode guesses received within the time interval is greater than or equal to a threshold;

generate an indication in the one or more memories that subsequent requests associated with the device identifier and transaction type should not be granted; and

reset the number of incorrect passcode guesses when a valid passcode guess is received.

15. The identity repository of claim 14 , wherein the one or more memories further store encrypted personal information associated with the virtual identity, wherein the device identifier is associated with the virtual identity.

16. The identity repository of claim 14 , wherein the request from the user devices comprises a request to use the virtual identity.

17. The identity repository of claim 14 , wherein the request from the user devices comprises a request to pair an unregistered device with the virtual identity.

18. The identity repository of claim 14 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

send the indication to a pairing repository that is physically separate from the identity repository.

Assignments (6)
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NO. 16/990,698 PREVIOUSLY RECORDED ON REEL 058294 FRAME 0010. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 21, 2022
From: TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR DATA SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
To: DEUTSCHE BANK AG NEW YORK BRANCH
Reel/Frame 059846/0157 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 058294, FRAME 0161 Recorded Dec 27, 2021
From: JPMORGAN CHASE BANK, N.A.
To: EBUREAU, LLC; IOVATION, INC.; SIGNAL DIGITAL, INC.; TRANS UNION LLC; TRANSUNION INTERACTIVE, INC.; TRANSUNION RENTAL SCREENING SOLUTIONS, INC.; TRANSUNION TELEDATA LLC; AGGREGATE KNOWLEDGE, LLC; TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
Reel/Frame 058593/0852 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Dec 1, 2021
From: TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR DATA SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
To: DEUTSCHE BANK AG NEW YORK BRANCH
Reel/Frame 058294/0010 →
GRANT OF SECURITY INTEREST IN UNITED STATES PATENTS Recorded Dec 1, 2021
From: EBUREAU, LLC; IOVATION, INC.; SIGNAL DIGITAL, INC.; TRANS UNION LLC; TRANSUNION HEALTHCARE, INC.; TRANSUNION INTERACTIVE, INC.; TRANSUNION RENTAL SCREENING SOLUTIONS, INC.; TRANSUNION TELEDATA LLC; AGGREGATE KNOWLEDGE, LLC; TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
To: JPMORGAN CHASE BANK, N.A
Reel/Frame 058294/0161 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: ONEID, INC.
To: NEUSTAR, INC.
Reel/Frame 056277/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: KIRSCH, STEVEN TODD
To: ONEID INC.
Reel/Frame 056281/0224 →
Continuity (8)
Continuation 16002990 · Jun 7, 2018
Continuation 15155264 · May 16, 2016
Continuation 13745354 · Jan 18, 2013
Provisional Application 61609515 · Mar 12, 2012
Provisional Application 61609848 · Mar 12, 2012
Provisional Application 61609854 · Mar 12, 2012
Provisional Application 61588084 · Jan 18, 2012
Related Publication 20220109578A1 · Apr 7, 2022
Cited By (4)
US 12,333,623 US 12,346,984 US 12,353,482 US 12,657,589