IP Library › Granted Patent US 11,811,757
Granted Patent B1
US 11,811,757 · App. 17/685,880 · Granted Nov 7, 2023

Authentication as a service

Inventors: Mariam Alexanian (San Francisco, CA); Andrew G. Foote (San Francisco, CA); Ilya Ozerets (San Francisco, CA); Shanti Tandukar (San Francisco, CA)
Assignee: Wells Fargo Bank, N.A.
H04L63/0861G06F18/22G06F21/32G06F21/45G06V40/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,811,757
App. No.
17/685,880
Granted
Nov 7, 2023
Kind
B1
Abstract

In accordance with at least some aspects of the present disclosure, an illustrative method for authenticating a user is disclosed. A plurality of biometric modalities are displayed for authenticating the user. A selection of one or more of the biometric authentication modalities may be received. User authentication data may be received for each of the one or more selected authentication modalities. The user authentication data may be compared with previously-determined biometric data. An authentication score may be determined based on the comparison of the user authentication data with the previously-determined biometric data. A determination may be made whether to authenticate the user based on the authentication score.

Claims (56)

1. A method for authenticating a user comprising:

receiving a first request to authenticate the user for access to a third-party application;

receiving a first security threshold from a third party associated with the third-party application, the first security threshold comprising a minimum authentication score required to access the third-party application;

receiving first user authentication data for a first biometric authentication modality;

determining a first authentication score based on a comparison of the first user authentication data with previously-determined biometric data;

providing to the user, access to the third-party application based on a comparison of the first authentication score with the first security threshold;

receiving a second request to authenticate the user for an operation within the third-party application;

receiving a second security threshold from the third party, the second security threshold comprising a minimum authentication score required to perform the operation within the third-party application and a second biometric authentication modality, the second biometric authentication modality selected from a subset of biometric authentication modalities based on a location or surroundings of the user, the subset of biometric authentication modalities prescribed by the third party for the operation within the third-party application, wherein the second security threshold is greater than the first security threshold and the first authentication score;

receiving second user authentication data for the second biometric authentication modality, wherein the second biometric authentication modality is different than the first biometric authentication modality;

determining a second authentication score based on a comparison of the second user authentication data with the previously-determined biometric data; and

allowing the user to perform the operation within the third-party application based on determining that the second authentication score satisfies the second security threshold.

2. The method of claim 1 , wherein the first biometric authentication modality is specified by the third party.

3. The method of claim 2 , wherein the first biometric authentication modality is specified by the third party based on the first security threshold.

4. The method of claim 1 , wherein the second biometric authentication modality is selected by the user.

5. The method of claim 1 , wherein the first security threshold and second security threshold are correlated with a level of security that is achievable using the first biometric authentication modality and second biometric authentication modality, respectively.

6. The method of claim 5 , wherein the second biometric authentication modality is capable of achieving a higher level of security than the first biometric authentication modality.

7. The method of claim 1 , wherein the operation within the third-party application comprises transferring funds from an account of the user to a third-party recipient.

8. The method of claim 1 , wherein the operation within the third-party application comprises transferring funds from a first account of the user to a second account of the user.

9. A device comprising:

a user interface configured to receive user authentication data, wherein the user authentication data comprises user biometric data from a user;

a memory configured to store pre-registered biometric data; and

a processor communicatively coupled to the user interface and the memory, wherein the processor is configured to:

receive a first request to authenticate the user for access to a third-party application;

receive a first security threshold from a third party associated with the third-party application, the first security threshold comprising a minimum authentication score required to access the third-party application;

receive, via the user interface, first user authentication data for a first biometric authentication modality;

determine a first authentication score based on a comparison of the first user authentication data with previously-determined biometric data;

provide, to the user, access to the third-party application based on a comparison of the first authentication score with the first security threshold;

receive a second request to authenticate the user for an operation within the third-party application;

receive a second security threshold from the third party and a second biometric authentication modality, the second security threshold comprising a minimum authentication score required to perform the operation within the third-party application, the second biometric authentication modality selected from a subset of biometric authentication modalities based on a location or surroundings of the user, the subset of biometric authentication modalities prescribed by the third party for the operation within the third-party application, wherein the second security threshold is greater than the first security threshold and the first authentication score;

receive second user authentication data for the second biometric authentication modality, wherein the second biometric authentication modality is different than the first biometric authentication modality;

determine a second authentication score based on a comparison of the second user authentication data with the previously-determined biometric data; and

allow the user to perform the operation within the third-party application based on determining that the second authentication score satisfies the second security threshold.

10. The device of claim 9 , wherein the first biometric authentication modality is specified by the third party.

11. The device of claim 9 , wherein the processor is configured to select the second biometric authentication modality from the subset of biometric authentication modalities, further based at least in part on a selection received from another user device associated with another user.

12. The device of claim 9 , wherein the second biometric authentication modality is selected by the user from the subset of biometric authentication modalities.

13. The device of claim 9 , wherein the first security threshold and second security threshold are correlated with a level of security that is achievable using the first biometric authentication modality and second biometric authentication modality, respectively.

14. A method for authenticating a user comprising:

receiving a first request to authenticate the user to perform a first operation within a third-party application;

receiving a first security threshold from a third party associated with the third-party application, the first security threshold comprising a minimum authentication score required to perform the first operation within the third-party application;

displaying, via a user interface, a first suitable set of biometric authentication modalities, the first suitable set of biometric authentication modalities specified by the third party based on at least one of the first operation and the first security threshold;

receiving, from the user via the user interface, a selection of a biometric authentication modality from the first suitable set of biometric authentication modalities;

receiving user authentication data for the selected biometric authentication modality;

determining an authentication score based on a comparison of the user authentication data with previously-determined biometric data;

allowing the user to perform the first operation within the third-party application based on a comparison of the authentication score with the first security threshold;

receiving a second request to authenticate the user to perform a second operation within the third-party application;

receiving a second security threshold from the third party and a second biometric authentication modality, the second security threshold comprising a minimum authentication score required to perform the second operation within the third-party application wherein the second security threshold is greater than the first security threshold, the second biometric authentication modality selected from a second suitable set of biometric authentication modalities based on a location or surroundings of the user, the second suitable set of biometric authentication modalities prescribed by the third party for the second operation within the third-party application;

receiving second user authentication data for the selected second biometric authentication modality;

determining a second authentication score based on a comparison of the second user authentication data with the previously-determined biometric data; and

allowing the user to perform the second operation within the third-party application based on determining that the second authentication score satisfies the second security threshold.

15. The method of claim 14 , wherein the first security threshold is based on a characteristic of the first operation within the third-party application.

16. The method of claim 15 , wherein the allowing the user to perform the first operation within the third-party application comprises determining that the authentication score meets or exceeds the first security threshold.

17. The method of claim 14 , further comprising:

displaying, via the user interface, an unsuitable set of biometric authentication modalities, wherein the unsuitable set of biometric authentication modalities are not selectable by the user.

18. The method of claim 14 , the method further comprising:

displaying, via the user interface, the second suitable set of biometric authentication modalities, the second suitable set of biometric authentication modalities specified by the third party based on at least one of the second operation and second security threshold, wherein the second suitable set of biometric authentication modalities differs from the first suitable set of biometric authentication modalities.

19. The method of claim 18 , wherein each biometric authentication modality of the first suitable set of biometric authentication modalities and the second suitable set of biometric authentication modalities is one of a fingerprint, a palm print, an eye scan, a face scan, or voice recognition.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2023
From: ALEXANIAN, MARIAM; FOOTE, ANDREW G.; OZERETS, ILYA; TANDUKAR, SHANTI
To: WELLS FARGO BANK, N.A.
Reel/Frame 064738/0082 →
Continuity (2)
Continuation 16022427 · Jun 28, 2018
Provisional Application 62527877 · Jun 30, 2017