IP Library Granted Patent US 11,991,166
Granted Patent B2
US 11,991,166 · App. 17/472,355 · Granted May 21, 2024

Method and apparatus for an identity assurance score with ties to an ID-less and password-less authentication system

Inventor: Nelson A. Cicchitto (San Ramon, CA)
H04L63/083H04L63/0815H04W12/068H04L2463/082H04W12/68
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,991,166
App. No.
17/472,355
Granted
May 21, 2024
Kind
B2
Abstract

A technique is provided by which a user goes to a site and instead of the authentication system of the site going to their own databases to match an ID and password given by the user, because doing so is not secure, the site companies makes a call to an identity assurance score server (with ties to the ID-less and password-less system) and send a parameter such as a number. Then, based on that parameter (e.g., number or score), the identity assurance score server (with ties to the ID-less and password-less system, such as described hereinabove) sends a corresponding login protocol or factors to be satisfied to authenticate the user.

Claims (80)

1. A computer-implemented method, comprising:

receiving, at an identity assurance server, a first request initiated from a company server for an identity assurance score corresponding to an entity requesting the company server for access to an asset of the company;

generating, in response to the request, the identity assurance score and determining a collection of requirements that the entity must satisfy to access the asset, the collection of requirements based on the generated identity assurance score;

transmitting by the identity assurance server for delivery to the company server, the identity assurance score and the collection of requirements for the entity to satisfy;

receiving, at the identity assurance server and originating from the company server, informational data corresponding to the collection of requirements completed by the entity;

confirming, at the identity assurance server, that the received informational data matches data previously saved on a database at the identity assurance server; and

notifying the company that the received information data has been confirmed;

wherein the identity assurance score is based on a predetermined hierarchy of levels of requirements to be satisfied for the request to be approved; and

wherein the hierarchy of levels comprises the following levels of requirements for granting access to the asset:

first level—ID of user and No Password;

second level—ID and Password;

third level—Description of something the entity knows;

fourth level—Description of something the entity has;

fifth level—Number of social network connections the entity has;

sixth level—Location of the entity;

seventh level—One biometric identifier;

eighth level—Two biometric identifiers;

ninth level—Three biometric identifiers;

tenth level—Financial information corresponding to the entity;

eleventh level—One health identifier;

twelfth level—Second health identifier; and

thirteenth level—DNA (Deoxyribonucleic acid) of the entity;

wherein one or more steps are performed on at least a processor coupled to at least a memory.

2. The method of claim 1 , wherein the asset of the company is any of a computer-related account or service or a room or building under control of the company.

3. The method of claim 1 , wherein the requirements of the level are cumulative, meaning that the identity assurance score causes the requirements for the current level and the previous levels to be checked for satisfaction before approving the request.

4. The method of claim 1 , wherein the identity assurance score for the current level does not have to incorporate requirements of any other level of any other identity assurance score before approving the request.

5. The method of claim 1 , wherein a biometric identifier is fingerprint or voice of the entity.

6. The method of claim 5 , wherein financial information comprises any of: current bank balances; the number of bank accounts; whether the entity is a homeowner; or whether the entity has any personal loans.

7. The method of claim 6 , wherein a health identifier is 1 Blood Type; dental information; or type of surgeries.

8. An apparatus, comprising:

a first receiving processor configured to receive, at an identity assurance server, a first request initiated from a company server for an identity assurance score corresponding to an entity requesting the company server for access to an asset of the company;

a generating processor configured to generate, in response to the request, the identity assurance score and determine a collection of requirements that the entity must satisfy to access the asset, the collection of requirements based on the generated identity assurance score;

a transmitting processor configured to transmit by the identity assurance server for delivery to the company server, the identity assurance score and the collection of requirements for the entity to satisfy;

a second receiving processor configured to receive, at the identity assurance server and originating from the company server, informational data corresponding to the collection of requirements completed by the entity;

a confirming processor configured to confirm, at the identity assurance server, that the received informational data matches data previously saved on a database at the identity assurance server;

a notifying processor configured to notify the company that the received information data has been confirmed; and

at least one memory operable to store computer program instructions executable by at least one of said processors;

wherein the identity assurance score is based on a predetermined hierarchy of levels of requirements to be satisfied for the request to be approved; and

wherein the hierarchy of levels comprises the following levels of requirements for granting access to the asset:

first level—ID of user and No Password;

second level—ID and Password;

third level—Description of something the entity knows;

fourth level—Description of something the entity has;

fifth level—Number of social network connections the entity has;

sixth level—Location of the entity;

seventh level—One biometric identifier;

eighth level—Two biometric identifiers;

ninth level—Three biometric identifiers;

tenth level—Financial information corresponding to the entity;

eleventh level—One health identifier;

twelfth level—Second health identifier; and

thirteenth level—DNA (Deoxyribonucleic acid) of the entity.

9. The apparatus of claim 8 , wherein the asset of the company is any of a computer-related account or service or a room or building under control of the company.

10. The apparatus of claim 8 , wherein the requirements of the level are cumulative, meaning that the identity assurance score causes the requirements for the current level and the previous levels to be checked for satisfaction before approving the request.

11. The apparatus of claim 8 , wherein the identity assurance score for the current level does not have to incorporate requirements of any other level of any other identity assurance score before approving the request.

12. The apparatus of claim 8 , wherein a biometric identifier is fingerprint or voice of the entity.

13. The apparatus of claim 12 , wherein financial information comprises any of: current bank balances; the number of bank accounts; whether the entity is a homeowner; or whether the entity has any personal loans.

14. The apparatus of claim 13 , wherein a health identifier is 1 Blood Type; dental information; or type of surgeries.

15. A non-transitory computer readable medium having stored thereon a computer program, said computer program comprising a program code which, when executed by a processor, performs the steps of:

receiving, at an identity assurance server, a first request initiated from a company server for an identity assurance score corresponding to an entity requesting the company server for access to an asset of the company;

generating, in response to the request, the identity assurance score and determining a collection of requirements that the entity must satisfy to access the asset, the collection of requirements based on the generated identity assurance score;

transmitting by the identity assurance server for delivery to the company server, the identity assurance score and the collection of requirements for the entity to satisfy;

receiving, at the identity assurance server and originating from the company server, informational data corresponding to the collection of requirements completed by the entity;

confirming, at the identity assurance server, that the received informational data matches data previously saved on a database at the identity assurance server; and

notifying the company that the received information data has been confirmed;

wherein the identity assurance score is based on a predetermined hierarchy of levels of requirements to be satisfied for the request to be approved; and

wherein the hierarchy of levels comprises the following levels of requirements for granting access to the asset:

first level—ID of user and No Password;

second level—ID and Password;

third level—Description of something the entity knows;

fourth level—Description of something the entity has;

fifth level—Number of social network connections the entity has;

sixth level—Location of the entity;

seventh level—One biometric identifier;

eighth level—Two biometric identifiers;

ninth level—Three biometric identifiers;

tenth level—Financial information corresponding to the entity;

eleventh level—One health identifier;

twelfth level—Second health identifier; and

thirteenth level—DNA (Deoxyribonucleic acid) of the entity.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Mar 25, 2025
From: AVATIER IP, LLC
To: PICCADILLY PATENT FUNDING LLC, AS SECURITY HOLDER
Reel/Frame 070613/0769 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2025
From: AVATIER CORPORATION
To: AVATIER IP, LLC
Reel/Frame 070184/0820 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2025
From: CICCHITTO, NELSON A.
To: AVATIER CORPORATION
Reel/Frame 069972/0161 →
Continuity (6)
Continuation 15970796 · May 3, 2018
Continuation In Part 15626997 · Jun 19, 2017
Division 15052747 · Feb 24, 2016
Provisional Application 62501027 · May 3, 2017
Provisional Application 62120153 · Feb 24, 2015
Related Publication 20210409391A1 · Dec 30, 2021
Cited By (1)
US 12,621,291