IP Library Granted Patent US 11,367,323
Granted Patent B1
US 11,367,323 · App. 17/486,662 · Granted Jun 21, 2022

System and method for secure pair and unpair processing using a dynamic level of assurance (LOA) score

Inventors: Shahrokh Shahidzadeh (Portland, OR); Nahal Shahidzadeh (Portland, OR); Haitham Akkary (Portland, OR); Frank Stefan Ulbrich (Karlsruhe, DE); Mani Malekmohammadi (North Vancouver, CA)
Assignee: SecureAuth Corporation
G07C9/37G06F21/32G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,367,323
App. No.
17/486,662
Granted
Jun 21, 2022
Kind
B1
Abstract

A system and method for biobehavioral identification may include a user device, a secure system/client device, and a server. The elements of the system work together to monitor the biologic features (e.g., fingerprints, pupils, or the like) and behavior (e.g., wake time, exercise time, location) to verify the authenticity of a user requesting access to a database and/or secure facility.

Claims (24)

1. A method of preventing a pairing of an unauthorized user entity device with a secure website comprising:

orchestrating a first policy engine in a risk engine with a second policy engine in a first mobile device to enable the first policy engine and second policy to function as a single policy engine in authenticating and authorizing a user entity;

monitoring behavior of the user entity of the first mobile device and comparing the behavior against an identity confidence threshold;

determining that a second mobile device is attempting to access the secure website while the first mobile device is still paired with the secure website and has not been unpaired and determining that a subscriber identification module (SIM) card swap has potentially happened;

raising the level of assurance required for access to the secure website by the second mobile device according to a predetermined policy;

requiring authentication by the second mobile device using a push to the first mobile device or a time-based one time password (TOTP);

receiving an attempted pairing from the second mobile device and blocking access to the secure website; and

contacting the first mobile device to notify the user entity of a security event.

2. The method of claim 1 , further comprising:

graphing behavior of the user entity of the first mobile device to create the identity confidence threshold.

3. The method of claim 2 , wherein the behavior graphed by the first mobile device includes at least one from the group consisting of: location where the user entity wakes up, where the user entity drives to, and if the user entity is deemed normal against the derived collection of the user entity habits.

4. A system comprising:

a plurality of processors forming a risk engine, wherein the risk engine is coupled to a network interface, and the plurality of processors are coupled to a first mobile device, wherein the risk engine and first mobile device are configured to:

orchestrate a first policy engine in the risk engine with a second policy engine in the first mobile device to enable the first policy engine and second policy to function as a single policy engine in authenticating and authorizing a user entity;

monitor behavior of a user entity of a first mobile device and compare the behavior against an identity confidence threshold;

determine that a second mobile device is attempting to access the secure website while the first mobile is still paired with the secure website and has not been unpaired and determine that a subscriber identification module (SIM) card swap has potentially happened;

raise the level of assurance required for access to the secure website by the second mobile device according to a predetermined policy;

require authentication by the second mobile device using a push to the first mobile device or a time-based one time password (TOTP);

receive an attempted pairing from the second mobile device and blocking access to the secure website; and

contact the first mobile device to notify the user entity of a security event.

5. The system of claim 4 , the plurality of processors further configured to:

graph behavior of the user entity of the first mobile device to create the identity confidence threshold.

6. The system of claim 5 , further comprising:

wherein the behavior graphed by the first mobile device includes at least one from the group consisting of: location where the user entity wakes up, where the user entity drives to, and if the user entity is deemed normal against the derived collection of the user entity habits.

Assignments (3)
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2022
From: ACCEPTTO CORPORATION
To: SECUREAUTH CORPORATION
Reel/Frame 059152/0521 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2021
From: SHAHIDZADEH, SHAHROKH; SHAHIDZADEH, NAHAL; AKKARY, HAITHAM; ULBRICH, FRANK STEFAN; MALEKMOHAMMADI, MANI
To: ACCEPTTO CORPORATION
Reel/Frame 057614/0515 →
Cited By (1)
US 12,581,302