IP Library Granted Patent US 12,373,521
Granted Patent B2
US 12,373,521 · App. 17/873,275 · Granted Jul 29, 2025

Secure user authentication using machine learning and geo-location data

Inventors: Richard S. Scot (Huntersville, NC); Graham Wyllie (Charlotte, NC); Kelly Renee-Drop Keiter (Waxhaw, NC); Robert Nyeland Huggins (Charlotte, NC)
Assignee: Bank of America Corporation
G06F21/31
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,521
App. No.
17/873,275
Granted
Jul 29, 2025
Kind
B2
Abstract

Arrangements for providing frictionless unauthorized activity detection and user authentication are provided. In some aspects, user data, such as transaction data may be received and used to train a machine learning model. In some examples, the machine learning model may be executed to generate one or more expected user patterns. In some arrangements, a request for transaction may be received. The request for transaction may include transaction details. In response, the system may request current geo-location data of a user. In some examples, the transaction details and geo-location data may be analyzed (e.g., compared to the expected user patterns) to generate an authentication output. The authentication output may then be transmitted to one or more systems to process the requested transaction, prevent transaction processing, or the like.

Claims (57)

1. A computing platform, comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

a memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive historical user data for a user;

train a machine learning model using the received historical user data;

in response to a triggering event associated with transaction activity of the user, execute the machine learning model to generate one or more expected user patterns for the user, wherein the one or more expected user patterns for the user predict patterns of user behavior that are different from historical behavior of the user, wherein the triggering event corresponds to a schedule for generating the one or more expected user patterns that is based on a number of changes of location of the user;

after generating the one or more expected user patterns for the user, receive a request to process a transaction, the request to process the transaction including transaction details;

receive, from a user computing device of the user, geo-location data of the user computing device, wherein the geo-location data includes data captured over a range of time;

analyze the request to process the transaction including the transaction details and the geo-location data of the user computing device including comparing the transaction details and geo-location data to determine whether the transaction details and geo-location data fall within at least one of the one or more expected user patterns;

generate, based on the analyzing, an authentication output, the authentication output indicating an output of the comparing; and

transmit the authentication output, wherein transmitting the authentication output causes the authentication output to be displayed.

2. The computing platform of claim 1 , wherein the historical user data includes historical transaction data.

3. The computing platform of claim 1 , wherein the authentication output includes an indication of whether unauthorized activity is occurring.

4. The computing platform of claim 1 , wherein the geo-location data is captured by a global positioning system of the user computing device.

5. The computing platform of claim 1 , further including instructions that, when executed, cause the computing platform to:

identify a type of authentication output; and

generate a notification based on the identified type of authentication output.

6. The computing platform of claim 5 , further including instructions that, when executed, cause the computing platform to:

transmit the notification to the user computing device, wherein transmitting the notification causes the notification to display on the user computing device.

7. The computing platform of claim 1 , wherein training the machine learning model using the received historical user data includes training the machine learning model using labeled datasets.

8. A method, comprising:

receiving, by a computing platform, the computing platform having at least one processor and memory, historical user data for a user;

training, by the at least one processor, a machine learning model using the received historical user data;

in response to a triggering event associated with transaction activity of the user, executing, by the at least one processor, the machine learning model to generate one or more expected user patterns for the user, wherein the one or more expected user patterns for the user predict patterns of user behavior that are different from historical behavior of the user, wherein the triggering event corresponds to a schedule for generating the one or more expected user patterns that is based on a number of changes of location of the user;

after generating the one or more expected user patterns for the user, receiving, by the at least one processor, a request to process a transaction, the request to process the transaction including transaction details;

receiving, by the at least one processor and from a user computing device of the user, geo-location data of the user computing device, wherein the geo-location data includes data captured over a range of time;

analyzing, by the at least one processor, the request to process the transaction including the transaction details and the geo-location data of the user computing device including comparing the transaction details and geo-location data to determine whether the transaction details and geo-location data fall within at least one of the one or more expected user patterns;

generating, by the at least one processor and based on the analyzing, an authentication output, the authentication output indicating an output of the comparing; and

transmitting, by the at least one processor, the authentication output, wherein transmitting the authentication output causes the authentication output to be displayed.

9. The method of claim 8 wherein the historical user data includes historical transaction data.

10. The method of claim 8 , wherein the authentication output includes an indication of whether unauthorized activity is occurring.

11. The method of claim 8 , wherein the geo-location data is captured by a global positioning system of the user computing device.

12. The method of claim 8 , further including:

identifying, by the at least one processor, a type of authentication output; and

generating, by the at least one processor, a notification based on the identified type of authentication output.

13. The method of claim 12 , further including:

transmitting, by the at least one processor, the notification to the user computing device, wherein transmitting the notification causes the notification to display on the user computing device.

14. The method of claim 8 , wherein training the machine learning model using the received historical user data includes training the machine learning model using labeled datasets.

15. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, memory, and a communication interface, cause the computing platform to:

receive historical user data for a user;

train a machine learning model using the received historical user data;

in response to a triggering event associated with transaction activity of the user, execute the machine learning model to generate one or more expected user patterns for the user, wherein the one or more expected user patterns for the user predict patterns of user behavior that are different from historical behavior of the user, wherein the triggering event corresponds to a schedule for generating the one or more expected user patterns that is based on a number of changes of location of the user;

after generating the one or more expected user patterns for the user, receive a request to process a transaction, the request to process the transaction including transaction details;

receive, from a user computing device of the user, geo-location data of the user computing device, wherein the geo-location data includes data captured over a range of time;

analyze the request to process the transaction including the transaction details and the geo-location data of the user computing device including comparing the transaction details and geo-location data to determine whether the transaction details and geo-location data fall within at least one of the one or more expected user patterns;

generate, based on the analyzing, an authentication output, the authentication output indicating an output of the comparing; and

transmit the authentication output, wherein transmitting the authentication output causes the authentication output to be displayed.

16. The one or more non-transitory computer-readable of claim 15 , wherein the historical user data includes historical transaction data.

17. The one or more non-transitory computer-readable of claim 15 , wherein the authentication output includes an indication of whether unauthorized activity is occurring.

18. The one or more non-transitory computer-readable of claim 15 , wherein the geo-location data is captured by a global positioning system of the user computing device.

19. The one or more non-transitory computer-readable of claim 15 , further including instructions that, when executed, cause the computing platform to:

identify a type of authentication output; and

generate a notification based on the identified type of authentication output.

20. The one or more non-transitory computer-readable of claim 19 , further including instructions that, when executed, cause the computing platform to:

transmit the notification to the user computing device, wherein transmitting the notification causes the notification to display on the user computing device.

21. The one or more non-transitory computer-readable of claim 15 , wherein training the machine learning model using the received historical user data includes training the machine learning model using labeled datasets.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2022
From: SCOT, RICHARD S.; WYLLIE, GRAHAM; KEITER, KELLY RENEE-DROP; HUGGINS, ROBERT NYELAND
To: BANK OF AMERICA CORPORATION
Reel/Frame 060620/0739 →
Continuity (1)
Related Publication 20240037195A1 · Feb 1, 2024
References Cited (38)
US 8843108B1 · Lish · 2014 [cited by examiner]
US 9391985B2 · Hefetz · 2016 [cited by examiner]
US 9801058B2 · Tali · 2017 [cited by examiner]
US 9961088B2 · Hughes, Jr. · 2018 [cited by examiner]
US 10212587B2 · Bentley · 2019 [cited by examiner]
US 10664896B2 · Or · 2020 [cited by examiner]
US 10990971B2 · Lloyd · 2021 [cited by examiner]
US 11257080B2 · John · 2022 [cited by examiner]
US 11403131B2 · Mohapatra · 2022 [cited by examiner]
US 11544716B2 · Martinez-Guarneros · 2023 [cited by examiner]
US 11593823B2 · Buesser · 2023 [cited by examiner]
US 11875335B2 · Benkreira · 2024 [cited by examiner]
US 11995175B2 · Maiman · 2024 [cited by examiner]
US 20100274691A1 · Hammad · 2010 [cited by examiner]
US 20130030994A1 · Calman · 2013 [cited by examiner]
US 20130102283A1 · Lau · 2013 [cited by examiner]
US 20140279503A1 · Bertanzetti · 2014 [cited by examiner]
US 20140358661A1 · Or · 2014 [cited by examiner]
US 20160162896A1 · Grigg · 2016 [cited by examiner]
US 20170091765A1 · Lloyd · 2017 [cited by examiner]
US 20180150903A1 · Waldron · 2018 [cited by examiner]
US 20190108572A1 · Or · 2019 [cited by examiner]
US 20190197514A1 · Tineo · 2019 [cited by examiner]
US 20190295088A1 · Jia · 2019 [cited by examiner]
US 20190378135A1 · Lloyd · 2019 [cited by examiner]
US 20200005295A1 · Murphy · 2020 [cited by examiner]
US 20210090084A1 · Fisher · 2021 [cited by examiner]
US 20210383391A1 · Barry · 2021 [cited by examiner]
US 20220101192A1 · Patel · 2022 [cited by examiner]
US 20220215465A1 · Mitchko · 2022 [cited by examiner]
US 20230030389A1 · Chaudhary · 2023 [cited by examiner]
US 20230035570A1 · Edwards · 2023 [cited by examiner]
US 20230106289A1 · Maiman · 2023 [cited by examiner]
US 20230107703A1 · Zhang · 2023 [cited by examiner]
US 20230162056A1 · Poole · 2023 [cited by examiner]
US 20230273981A1 · Rapowitz · 2023 [cited by examiner]
US 20240029051A1 · Sethia · 2024 [cited by examiner]
US 20240037195A1 · Scot · 2024 [cited by examiner]