IP Library Granted Patent US 11,889,024
Granted Patent B2
US 11,889,024 · App. 17/948,991 · Granted Jan 30, 2024

Caller verification via carrier metadata

Inventors: John Cornwell (Atlanta, GA); Terry Nelms, II (Atlanta, GA)
Assignee: Pindrop Security, Inc.
H04M3/5175G06F18/214H04M3/2218H04M3/2281H04M3/42059G06V2201/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,889,024
App. No.
17/948,991
Granted
Jan 30, 2024
Kind
B2
Abstract

Embodiments described herein provide for passive caller verification and/or passive fraud risk assessments for calls to customer call centers. Systems and methods may be used in real time as a call is coming into a call center. An analytics server of an analytics service looks at the purported Caller ID of the call, as well as the unaltered carrier metadata, which the analytics server then uses to generate or retrieve one or more probability scores using one or more lookup tables and/or a machine-learning model. A probability score indicates the likelihood that information derived using the Caller ID information has occurred or should occur given the carrier metadata received with the inbound call. The one or more probability scores be used to generate a risk score for the current call that indicates the probability of the call being valid (e.g., originated from a verified caller or calling device, non-fraudulent).

Claims (49)

1. A computer-implemented method for caller verification, the method comprising:

obtaining, by the computer, a call-data pair of call data received for a current call, the call-data pair including a carrier metadata value of a type of carrier metadata value correlated to a derived metadata value of a type of derived metadata value;

obtaining, by the computer, probability data according to the call data of the current call, the probability data comprising a machine-learning architecture trained to determine a risk score for the call data and a probability value indicating a probability of occurrence of the call-data pair;

generating, by the computer, a feature vector for the current call based upon the probability value, the derived metadata value, and the carrier metadata value of the call-data pair;

generating, by the computer, the risk score for the current call by applying the machine-learning architecture on the feature vector of the current call; and

identifying, by the computer, the current call as a fraudulent call in response to the computer determining that the risk score satisfies a fraud threshold score.

2. The method according to claim 1 , wherein obtaining the call-data pair of the current call includes:

receiving, by the computer, the call data for the current call that originated from a calling device via one or more telephony networks including a carrier network; and

determining, by the computer, the derived metadata value of the type of derived metadata value based upon at least the carrier metadata value of the type of carrier metadata value.

3. The method according to claim 1 , wherein the computer obtains a plurality of call-data pairs based on the call data of the current call, wherein the computer obtains the probability data for each call-data pair of the plurality of call-data pairs, and wherein the computer generates the feature vector for the current call based upon each probability value, each derived metadata value, and each carrier metadata value of the plurality of call-data pairs.

4. The method according to claim 1 , wherein obtaining the probability data includes querying, by the computer, one or more databases for the probability value and the machine-learning architecture according to the type of carrier metadata value or the type of derived metadata value.

5. The method according to claim 4 , wherein the computer transmits queries the one or more databases for the derived metadata value according to a purported caller identifier as the carrier metadata value.

6. The method according to claim 1 , wherein obtaining the probability value of the probability data includes:

receiving, by the computer, the call data of a plurality of prior calls from one or more databases, the call data of each prior call including a prior carrier metadata value of the type of carrier metadata value and a prior derived metadata value of the type of derived metadata value; and

generating, by the computer, one or more prior call-data pairs by correlating each prior carrier metadata value of the type of carrier metadata value against each prior derived metadata value of the type of derived metadata value for the plurality of prior calls;

calculating, by the computer, one or more probability values indicating each probability of occurrence of each prior carrier metadata value of the type of carrier metadata value correlated to each prior derived metadata value of the type of derived metadata value for the plurality of prior calls.

7. The method according to claim 1 , further comprising:

obtaining, by the computer, training call data for a plurality training calls and a plurality of training labels corresponding to the training call data of the plurality of training calls;

obtaining, by the computer, the probability value indicating a probability of occurrence of a training carrier metadata value of the type of carrier metadata value correlated to a training derived metadata value of the type of derived metadata value for the plurality of training calls;

for each training call, generating, by the computer, a training feature vector for the training call based upon the probability value, the training derived metadata value, and the training carrier metadata value; and

training, by the computer, the machine-learning architecture to determine the risk score by applying the machine-learning architecture on each training feature vector of each training call and each training label corresponding to the training call.

8. The method according to claim 7 , wherein the training call data includes production call data of a plurality of prior calls including a prior spoofed call, and wherein the plurality of training labels include a negative training label corresponding to the training call data of the prior spoofed call.

9. The method according to claim 7 , wherein the training call data includes production call data for a plurality of prior calls and synthetic call data for a synthetic call, and wherein the plurality of training labels include a negative training label corresponding to the synthetic call data of the synthetic call.

10. The method according to claim 9 , the method further comprising generating, by the computer, the synthetic call data for the synthetic training call of the plurality of training calls using the training carrier metadata value of the production call data of a first prior call and the training derived metadata value of the production call data of a second prior call.

11. A system comprising:

a server comprising a processor configured to:

obtain a call-data pair of call data received for a current call, the call-data pair including a carrier metadata value of a type of carrier metadata value correlated to a derived metadata value of a type of derived metadata value;

obtain probability data according to the call data of the current call, the probability data comprising a machine-learning architecture trained to determine a risk score for the call data and a probability value indicating a probability of occurrence of the call-data pair;

generate a feature vector for the current call based upon the probability value, the derived metadata value, and the carrier metadata value of the call-data pair;

generate the risk score for the current call by applying the machine-learning architecture on the feature vector of the current call; and

identify the current call as a fraudulent call in response to the server determining that the risk score satisfies a fraud threshold score.

12. The system according to claim 11 , wherein, when obtaining the call-data pair of the current call, the server is further configured to:

receive the call data for the current call that originated from a calling device via one or more telephony networks including a carrier network; and

determine the derived metadata value of the type of derived metadata value based upon at least the carrier metadata value of the type of carrier metadata value.

13. The system according to claim 11 , wherein the server obtains a plurality of call-data pairs based on the call data of the current call, wherein the server obtains the probability data for each call-data pair of the plurality of call-data pairs, and wherein the server generates the feature vector for the current call based upon each probability value, each derived metadata value, and each carrier metadata value of the plurality of call-data pairs.

14. The system according to claim 11 , wherein, when obtaining the probability data, the server is further configured to query one or more databases for the probability value and the machine-learning architecture according to the type of carrier metadata value or the type of derived metadata value.

15. The system according to claim 14 , wherein the computer transmits queries the one or more databases for the derived metadata value according to a purported caller identifier as the carrier metadata value.

16. The system according to claim 11 , wherein, when obtaining the probability value of the probability data, the server is further configured to:

receive the call data of a plurality of prior calls from one or more databases, the call data of each prior call including a prior carrier metadata value of the type of carrier metadata value and a prior derived metadata value of the type of derived metadata value; and

generate one or more prior call-data pairs by correlating each prior carrier metadata value of the type of carrier metadata value against each prior derived metadata value of the type of derived metadata value for the plurality of prior calls;

calculate one or more probability values indicating each probability of occurrence of each prior carrier metadata value of the type of carrier metadata value correlated to each prior derived metadata value of the type of derived metadata value for the plurality of prior calls.

17. The system according to claim 11 , wherein the server is further configured to:

obtain training call data for a plurality training calls and a plurality of training labels corresponding to the training call data of the plurality of training calls;

obtain the probability value indicating a probability of occurrence of a training carrier metadata value of the type of carrier metadata value correlated to a training derived metadata value of the type of derived metadata value for the plurality of training calls;

for each training call, generate a training feature vector for the training call based upon the probability value, the training derived metadata value, and the training carrier metadata value; and

train the machine-learning architecture to determine the risk score by applying the machine-learning architecture on each training feature vector of each training call and each training label corresponding to the training call.

18. The system according to claim 17 , wherein the training call data includes production call data of a plurality of prior calls including a prior spoofed call, and wherein the plurality of training labels include a negative training label corresponding to the training call data of the prior spoofed call.

19. The system according to claim 17 , wherein the training call data includes production call data for a plurality of prior calls and synthetic call data for a synthetic call, and wherein the plurality of training labels include a negative training label corresponding to the synthetic call data of the synthetic call.

20. The system according to claim 19 , wherein the server is further configured to generate the synthetic call data for the synthetic training call of the plurality of training calls using the training carrier metadata value of the production call data of a first prior call and the training derived metadata value of the production call data of a second prior call.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2024
From: PINDROP SECURITY, INC.
To: HERCULES CAPITAL, INC., AS AGENT
Reel/Frame 067867/0860 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2024
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: PINDROP SECURITY, INC.
Reel/Frame 069477/0962 →
SECURITY INTEREST Recorded Jul 31, 2023
From: PINDROP SECURITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064443/0584 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 20, 2022
From: CORNWELL, JOHN; NELMS, TERRY, II
To: PINDROP SECURITY, INC.
Reel/Frame 061156/0946 →
Continuity (3)
Continuation 16992789 · Aug 13, 2020
Provisional Application 62888978 · Aug 19, 2019
Related Publication 20230014180A1 · Jan 19, 2023
Cited By (1)
US 12,701,184