IP Library › Granted Patent US 12,499,501
Granted Patent B2
US 12,499,501 · App. 17/578,733 · Granted Dec 16, 2025

System and method for caller verification

Inventors: Tracey Nyholt (Calgary, CA); Mike Bond (Calgary, CA); Gabrielle Comeau (Calgary, CA); Chelsea Finnigan (Calgary, CA)
Assignee: TECHJUTSU PROPERTIES INC.
G06Q50/265H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,501
App. No.
17/578,733
Granted
Dec 16, 2025
Kind
B2
Abstract

A caller is verified by receiving a unique identifier from the caller, identifying an account based at least in part on the unique identifier, sending a soft token verification request to an identity provider to send a soft token push notification to a device associated with an owner of the account, and receiving a result of the soft token push notification from the identity provider. Upon the result of the soft token push notification being successful, the caller is classified as verified for the account.

Claims (79)

1 . A computer-implemented method for verifying a caller attempting to access a resource, the method comprising:

registering, with a third party identity-providing entity, a device associated with an owner of an account, said registering including registering a soft token as a factor of authentication for said account;

receiving, at a call receiver device, a call from the caller;

receiving, at the call receiver device, a request for access to said account from the caller, said request for access comprising a unique identifier;

accessing, by a user of the call receiver device, said user of the call receiver device being distinct from said caller, a caller verification entity via a web interface on said call receiver device, wherein hosting for said web interface is provided by a cloud provider in one or more geographically localized containers, said cloud provider providing access restrictions to said web interface, said accessing comprising:

providing said user of said call receiver device with an access token;

transmitting, by said call receiver device, a Hypertext Transfer Protocol Secure (HTTPS) request for access to said caller verification entity via a representational state transfer (REST) application programming interface (API);

confirming, by said cloud provider, that said user of said call receiver device complies with said access restrictions for said web interface;

confirming, by said cloud provider, that said call receiver device complies with said access restrictions for said web interface;

authenticating, by the caller verification entity, said user of said call receiver device based on said access token provided to said user of said call receiver device;

receiving, at the caller verification entity, said unique identifier from said call receiver device;

identifying, by said caller verification entity, an account based on the unique identifier, said identifying comprising:

transmitting, by said caller verification entity, said unique identifier to said third party identity-providing entity via said REST API;

identifying, by said third party identity-providing entity, said account based on the unique identifier;

displaying, on a graphical user interface of said caller verification entity, a plurality of authentication options for said account, said plurality of authentication options including at least a push, a time-based one-time password (TOTP), and an authenticator application;

selecting, by said user of said call receiver device, one of said plurality of authentication options;

sending, by said caller verification entity via said REST API, a soft token transmission request to said third party identity-providing entity;

responsive to receiving said soft token transmission request, transmitting, by said third party identity-providing entity via said REST API, a soft token push notification to said registered device associated with said owner of said account based on said registered soft token for said account, wherein said soft token push notification includes said selected authentication option;

receiving, at said caller verification entity, a result of said soft token push notification from said third party identity-providing entity; and

upon the result of the soft token push notification being successful, classifying the caller as verified at said caller verification entity;

granting access to said resource upon classifying the caller as verified at said caller verification entity; and

logging, by said caller verification entity, all verification events associated with said request for access to said account from said caller.

2 . The computer-implemented method of claim 1 , wherein serving the web interface is over Hypertext Transfer Protocol Secure (HTTPS).

3 . The computer-implemented method of claim 1 , further comprising displaying the result on the web interface at said caller verification entity.

4 . The computer-implemented method of claim 1 , wherein the unique identifier includes one or more of an email address, a phone number, or an account number.

5 . The computer-implemented method of claim 1 , further comprising upon the result being unsuccessful, sending a notification of the response to a fraud department.

6 . A computer system comprising:

a processor; and

a non-transitory computer-readable storage medium having stored thereon computer-executable instructions that, when executed by the processor, cause the processor to:

register, with a third party identity-providing entity, a device associated with an owner of an account, said registering including registering a soft token as a factor of authentication for said account;

receive, at a call receiver device, a call from a caller;

receive, at the call receiver device, a request for access to said account from the caller, said request for access comprising a unique identifier;

access, by a user of the call receiver device, said user of said call receiver device being distinct from said caller, a caller verification entity via a web interface on said call receiver device, wherein hosting for said web interface is provided by a cloud provider in one or more geographically localized containers, said cloud provider providing access restrictions to said web interface, said accessing comprising:

providing said user of said call receiver device with an access token;

transmitting, by said call receiver device, a hypertext transfer protocol secure (HTTPS) request for access to said caller verification entity via a representational state transfer (REST) application programming interface (API);

confirming, by said cloud provider, that said user of said call receiver device complies with said access restrictions for said web interface;

confirming, by said cloud provider, that said call receiver device complies with said access restrictions for said web interface;

authenticating, by the caller verification entity, said user of said call receiver device based on said access token provided to said user of said call receiver device;

receive, at the caller verification entity, said unique identifier from said call receiver device;

identify, by said caller verification entity, an account based on the unique identifier, said identifying comprising:

transmitting, by said caller verification entity, said unique identifier to said third party identity-providing entity via said REST API;

identifying, by said third party identity-providing entity, said account based on the unique identifier;

display, on a graphical user interface of said caller verification entity, a plurality of authentication options for said account, said plurality of authentication options including at least a push, a time-based one-time password (TOTP), and an authenticator application;

select, by said user of said call receiver device, one of said plurality of authentication options;

send, by said caller verification entity via said REST API, a soft token transmission request to said third party identity-providing entity;

responsive to receiving said soft token transmission request, transmitting, by said third party identity-providing entity via said REST API, a soft token push notification to said registered device associated with said owner of said account based on said registered soft token for said account, wherein said soft token push notification includes said selected authentication option;

receive, at said caller verification entity, a result of said soft token push notification from said third party identity-providing entity;

upon the result of the soft token push notification being successful, classify the caller as verified at said caller verification entity;

grant access to said resource upon classifying the caller as verified at said caller verification entity; and

log, by said caller verification entity, all verification events associated with said request for access to said account from said caller.

7 . A non-transitory computer-readable storage medium having stored thereon computer-executable instructions that, when executed by one or more processors, cause the one or more processors to:

register, with a third party identity-providing entity, a device associated with an owner of an account, said registering including registering a soft token as a factor of authentication for said account;

receive, at a call receiver device, a call from a caller;

receive, at the call receiver device, a request for access to said account from the caller, said request for access comprising a unique identifier;

access, by a user of the call receiver device, said user of said call receiver device being distinct from said caller, a caller verification entity via a web interface on said call receiver device, wherein hosting for said web interface is provided by a cloud provider in one or more geographically localized containers, said cloud provider providing access restrictions to said web interface, said accessing comprising:

providing said user of said call receiver device with an access token;

transmitting, by said call receiver device, a hypertext transfer protocol secure (HTTPS) request for access to said caller verification entity via a representational state transfer (REST) application programming interface (API);

confirming, by said cloud provider, that said user of said call receiver device complies with said access restrictions for said web interface;

confirming, by said cloud provider, that said call receiver device complies with said access restrictions for said web interface;

authenticating, by the caller verification entity, said user of said call receiver device based on said access token provided to said user of said call receiver device;

receive, at the caller verification entity, said unique identifier from said call receiver device;

identify, by said caller verification entity, an account based on the unique identifier, said identifying comprising:

transmitting, by said caller verification entity, said unique identifier to said third party identity-providing entity via said REST API;

identifying, by said third party identity-providing entity, said account based on the unique identifier;

display, on a graphical user interface of said caller verification entity, a plurality of authentication options for said account, said plurality of authentication options including at least a push, a time-based one-time password (TOTP), and an authenticator application;

select, by said user of said call receiver device, one of said plurality of authentication options;

send, by said caller verification entity via said REST API, a soft token transmission request to said third party identity-providing entity;

responsive to receiving said soft token transmission request, transmit, by said third party identity-providing entity via said REST API, a soft token push notification to said registered device associated with said owner of said account based on said registered soft token for said account, wherein said soft token push notification includes said selected authentication option;

receive, at said caller verification entity, a result of said soft token push notification from said third party identity-providing entity; and

upon the result of the soft token push notification being successful, classify the caller as verified at said caller verification entity;

grant access to said resource upon classifying the caller as verified at said caller verification entity; and

log, by said caller verification entity, all verification events associated with said request for access to said account from said caller.

8 . The computer-implemented method of claim 1 , wherein said soft token push notification is customized to depict a brand associated with said resource while displayed on said device associated with said owner of said account.

9 . The computer-implemented method of claim 1 , further comprising, after sending said soft token transmission request, starting a timer.

10 . The computer-implemented method of claim 9 , wherein when said timer reaches a predetermined time limit without receiving said result of said soft token push notification, classifying said caller as unauthorized at said caller verification entity.

11 . The computer-implemented method of claim 1 , wherein said soft token push notification includes a geographical location of said caller verification entity.

12 . The method of claim 1 , further comprising automatically scaling up one of said geographically localized containers in response to a traffic spike.

13 . The method of claim 1 , wherein said access restrictions for said web interface comprise web application firewall rules targeting specific access to network segments.

14 . The method of claim 1 , wherein said access restrictions comprise restricting access to said web interface to only designated users from within an authorized network.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2025
From: TECHJUTSU INC.
To: TECHJUTSU PROPERTIES INC.
Reel/Frame 072863/0262 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2022
From: NYHOLT, TRACEY; BOND, MIKE; COMEAU, GABRIELLE; FINNIGAN, CHELSEA
To: TECHJUTSU INC.
Reel/Frame 058692/0885 →
Continuity (3)
Provisional Application 63154115 · Feb 26, 2021
Provisional Application 63143318 · Jan 29, 2021
Related Publication 20220245747A1 · Aug 4, 2022
References Cited (30)
US 8745718B1 · Dufel · 2014 [cited by examiner]
US 8832788B1 · Gibson · 2014 [cited by examiner]
US 10681207B1 · Johnson · 2020 [cited by examiner]
US 10750008B1 · Cairns et al. · 2020 [cited by applicant]
US 11228677B1 · Cairns · 2022 [cited by examiner]
US 11770706B1 · Lilley · 2023 [cited by examiner]
US 20060059569A1 · Dasgupta · 2006 [cited by examiner]
US 20060294387A1 · McCracken · 2006 [cited by examiner]
US 20080198991A1 · Saito · 2008 [cited by examiner]
US 20130294513A1 · Seregin · 2013 [cited by examiner]
US 20140115341A1 · Robertson · 2014 [cited by examiner]
US 20140137199A1 · Hefetz · 2014 [cited by examiner]
US 20150059003A1 · Bouse · 2015 [cited by examiner]
US 20160019543A1 · Taylor, III · 2016 [cited by examiner]
US 20160078430A1 · Douglas · 2016 [cited by examiner]
US 20170104870A1 · Mandanapu · 2017 [cited by examiner]
US 20180013851A1 · Pollack · 2018 [cited by examiner]
US 20180062858A1 · Xu · 2018 [cited by examiner]
US 20180089693A1 · Martin · 2018 [cited by examiner]
US 20180278746A1 · Yacov · 2018 [cited by examiner]
US 20200084204A1 · Craswell · 2020 [cited by examiner]
US 20200259830A1 · Shaffer · 2020 [cited by examiner]
US 20200279255A1 · Douglas et al. · 2020 [cited by applicant]
US 20200389552A1 · Trim · 2020 [cited by examiner]
US 20210014062A1 · Bhattacharjee · 2021 [cited by examiner]
US 20210160231A1 · Kumar · 2021 [cited by examiner]
Peterson, Jon, Henning Schulzrinne, and Hannes Tschofenig. Secure telephone identity problem statement and requirements. No. rfc7340. 2014. (Year: 2014). [cited by examiner]
Chokngamwong, Roongroj. “Increasing the efficiency of one-time key issuing for the first verification caller ID spoofing attacks.” 2018 15th International Joint Conference on Computer Science and Software Engineering (J… [cited by examiner]
CIPO, Office Action dated Mar. 16, 2023 received in Canadian Patent Application No. 3110613. [cited by applicant]
Office Action received from Canadian Patent Office in respect of Canadian Patent Application No. 3,110,613 dated Dec. 6, 2023. [cited by applicant]