IP Library › Granted Patent US 11,949,716
Granted Patent B2
US 11,949,716 · App. 17/588,421 · Granted Apr 2, 2024

System for secure channel selection for multi-factor authentication using non-fungible electronic resources

Inventor: Anirudh Kumar Sharma (Haryana, IN)
Assignee: BANK OF AMERICA CORPORATION
H04L63/18H04L63/0838H04L63/102H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,949,716
App. No.
17/588,421
Filed
Jan 31, 2022
Granted
Apr 2, 2024
Kind
B2
Art Unit
2491
USPC
726/7
Abstract

Systems, computer program products, and methods are described herein for secure channel selection for multi-factor authentication using non-fungible electronic resources. The present invention is configured to receive, from a user input device, a request from a user to access resources; determine a first authentication channel for verification of user identity; trigger an authentication channel validation engine to validate the first authentication channel; retrieve authentication channel information associated with the first authentication channel; determine that the user has a non-fungible token (NFT) for the first authentication channel; retrieve, from one or more metadata layers of the NFT, authentication channel descriptors associated with the first authentication channel; compare the authentication channel information with the authentication channel descriptors to determine a match; determine that the first authentication channel is valid based on at least the match; and initialize verification of the user identity via the first authentication channel.

Claims (86)

1. A system for secure channel selection for multi-factor authentication using non-fungible electronic resources, the system comprising:

at least one non-transitory storage device; and

at least one processor coupled to the at least one non-transitory storage device, wherein the at least one processor is configured to:

electronically receive, from a user input device, a request from a user to access resources, wherein the request comprises a first access type;

determine, using an identity verification engine, a first authentication channel for verification of user identity based on at least the first access type;

trigger an authentication channel validation engine to validate the first authentication channel;

retrieve, from an identity repository, authentication channel information associated with the first authentication channel;

determine, using the authentication channel validation engine, that the user has a non-fungible token (NFT) for the first authentication channel;

retrieve, from one or more metadata layers of the NFT, authentication channel descriptors associated with the first authentication channel;

compare the authentication channel information with the authentication channel descriptors to determine a match;

determine, using the authentication channel validation engine, that the first authentication channel is valid based on at least the match; and

initialize, using the identity verification engine, verification of the user identity via the first authentication channel.

2. The system of claim 1 , wherein the at least one processor is further configured to:

electronically receive, from the user input device, a pre-registration request for access to resources within a distributed network, wherein the access comprises one or more access types;

determine one or more authentication channels for the user based on at least the one or more access types;

retrieve, from the user input device, authentication channel information for each of the one or more authentication channels; and

store the authentication channel information for each of the one or more authentication channels in the identity repository.

3. The system of claim 2 , wherein the at least one processing device is further configured to:

electronically receive, from the user input device, a request to generate one or more non-fungible tokens (NFTs) for the one or more authentication channels;

retrieve the authentication channel information for the one or more authentication channels;

initiate an NFT engine to generate the one or more NFTs for the one or more authentication channels, wherein the one or more NFTs comprises at least the authentication channel information for the one or more authentication channels; and

record the one or more NFTs in a distributed ledger.

4. The system of claim 3 , wherein the at least one processor is further configured to:

transmit control signals configured to cause the user input device to display a notification indicating that the one or more NFTs have been generated and recorded in the distributed ledger.

5. The system of claim 3 , wherein recording the one or more NFTs on the distributed ledger further comprises:

generating one or more transaction objects for the one or more NFTs; and

deploying the one or more transaction objects on the distributed ledger.

6. The system of claim 1 , wherein the verification of the user identity comprises at least a primary verification protocol and a secondary verification protocol.

7. The system of claim 6 , wherein the at least one processor is further configured to:

initiate, using the identity verification engine, the primary verification protocol in response to receiving the request, wherein initiating further comprises prompting the user to present one or more authentication credentials;

electronically receive, from the user input device, the one or more authentication credentials in response to the prompt;

determine that the one or more authentication credentials meets one or more requirements associated with the primary verification protocol; and

in response, determine that the user has satisfied the primary verification protocol.

8. The system of claim 7 , wherein the at least one processor is further configured to:

determine that the one or more authentication credentials does not meet the one or more requirements associated with the primary verification protocol; and

deny the request from the user to access the resources based on at least determining that the user has not satisfied the primary verification protocol.

9. The system of claim 6 , wherein the at least one processor is further configured to:

initiate, using the identity verification engine, a secondary verification protocol via the first authentication channel in response determining that the user has satisfied the primary verification protocol.

10. The system of claim 9 , wherein initiating further comprises transmitting a one-time code to the user via the first authentication channel using authentication channel information associated with the first authentication channel.

11. The system of claim 10 , wherein the at least one processor is further configured to:

electronically receive, from the user input device, a user input reproducing the one-time code;

determine that the user input reproducing the one-time code matches the one-time code initially transmitted to the user using the authentication information associated with the first authentication channel; and

in response, determine that the user has satisfied the secondary verification protocol.

12. The system of claim 11 , wherein the at least one processor is further configured to:

authorize the request from the user to access the resources based on at least determining that the user has satisfied the primary verification protocol and the secondary verification protocol.

13. A computer program product for secure channel selection for multi-factor authentication using non-fungible electronic resources, the computer program product comprising a non-transitory computer-readable medium comprising code causing a first apparatus to:

electronically receive, from a user input device, a request from a user to access resources, wherein the request comprises a first access type;

determine, using an identity verification engine, a first authentication channel for verification of user identity based on at least the first access type;

trigger an authentication channel validation engine to validate the first authentication channel;

retrieve, from an identity repository, authentication channel information associated with the first authentication channel;

determine, using the authentication channel validation engine, that the user has a non-fungible token (NFT) for the first authentication channel;

retrieve, from one or more metadata layers of the NFT, authentication channel descriptors associated with the first authentication channel;

compare the authentication channel information with the authentication channel descriptors to determine a match;

determine, using the authentication channel validation engine, that the first authentication channel is valid based on at least the match; and

initialize, using the identity verification engine, verification of the user identity via the first authentication channel.

14. The computer program product of claim 13 , wherein the first apparatus is further configured to:

electronically receive, from the user input device, a pre-registration request for access to resources within a distributed network, wherein the access comprises one or more access types;

determine one or more authentication channels for the user based on at least the one or more access types;

retrieve, from the user input device, authentication channel information for each of the one or more authentication channels; and

store the authentication channel information for each of the one or more authentication channels in the identity repository.

15. The computer program product of claim 14 , wherein the first apparatus is further configured to:

electronically receive, from the user input device, a request to generate one or more non-fungible tokens (NFTs) for the one or more authentication channels;

retrieve the authentication channel information for the one or more authentication channels;

initiate an NFT engine to generate the one or more NFTs for the one or more authentication channels, wherein the one or more NFTs comprises at least the authentication channel information for the one or more authentication channels; and

record the one or more NFTs in a distributed ledger.

16. The computer program product of claim 15 , wherein the first apparatus is further configured to:

transmit control signals configured to cause the user input device to display a notification indicating that the one or more NFTs have been generated and recorded in the distributed ledger.

17. The computer program product of claim 15 , wherein recording the one or more NFTs on the distributed ledger further comprises:

generating one or more transaction objects for the one or more NFTs; and

deploying the one or more transaction objects on the distributed ledger.

18. The computer program product of claim 13 , wherein the verification of the user identity comprises at least a primary verification protocol and a secondary verification protocol.

19. The computer program product of claim 18 , wherein the first apparatus is further configured to:

initiate, using the identity verification engine, the primary verification protocol in response to receiving the request, wherein initiating further comprises prompting the user to present one or more authentication credentials;

electronically receive, from the user input device, the one or more authentication credentials in response to the prompt;

determine that the one or more authentication credentials meets one or more requirements associated with the primary verification protocol; and

in response, determine that the user has satisfied the primary verification protocol.

20. A method for secure channel selection for multi-factor authentication using non-fungible electronic resources, the method comprising:

electronically receiving, from a user input device, a request from a user to access resources, wherein the request comprises a first access type;

determining, using an identity verification engine, a first authentication channel for verification of user identity based on at least the first access type;

triggering an authentication channel validation engine to validate the first authentication channel;

retrieving, from an identity repository, authentication channel information associated with the first authentication channel;

determining, using the authentication channel validation engine, that the user has a non-fungible token (NFT) for the first authentication channel;

retrieving, from one or more metadata layers of the NFT, authentication channel descriptors associated with the first authentication channel;

comparing the authentication channel information with the authentication channel descriptors to determine a match;

determining, using the authentication channel validation engine, that the first authentication channel is valid based on at least the match; and

initializing, using the identity verification engine, verification of the user identity via the first authentication channel.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2022
From: SHARMA, ANIRUDH KUMAR
To: BANK OF AMERICA CORPORATION
Reel/Frame 058825/0555 →
Continuity (1)
Related Publication 20230247053A1 · Aug 3, 2023
Cited By (1)
US 12,238,139