IP Library › Granted Patent US 12,316,766
Granted Patent B1
US 12,316,766 · App. 18/358,895 · Granted May 27, 2025

Asynchronous step-up authentication for client applications

Inventors: Huang Trung Vo (Little Elm, TX); Hieu Nguyen (Southlake, TX)
Assignee: United Services Automobile Association (USAA)
H04L9/3213G06F21/33H04L63/0892H04W12/06H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,766
App. No.
18/358,895
Granted
May 27, 2025
Kind
B1
Abstract

Embodiments described herein disclose methods and systems for authorizing transactions received from client applications. The transaction request can include a first access token. After validating the first access token, the system can determine whether additional authentication is needed to authorize the transaction. If additional authentication is needed, the system can determine the authentication requirements. Once the additional authentication is received and verified, the system can generate a second access token and authorize the transaction by releasing the first access token.

Claims (67)

1. A method of authorizing transactions, the method comprising:

receiving, at a step-up authentication service, a transaction request for step-up authentication for a transaction requested by a user,

wherein the transaction request includes a first access token that is active for a first predefined timeframe;

determining authentication information required for the transaction;

sending, via a first channel associated with a client application, an authentication request for the authentication information from the user;

receiving, at the step-up authentication service, the authentication information via a second channel associated with a second application, wherein the second channel associated with the second application is different from the first channel associated with the client application;

generating, by the step-up authentication service, a second access token that is active for at least one of:

a step-up time threshold that is less than the first predefined timeframe, or

a number of step-up transactions; and

sending, to an authentication service, the second access token relating to the transaction, wherein the transaction is authorized by releasing the second access token.

2. The method of claim 1 , further comprising:

verifying the authentication information from the client application.

3. The method of claim 1 , further comprising:

generating a third access token and exchanging the third access token with the second access token.

4. The method of claim 1 , further comprising:

determining the authentication information required for the transaction based on at least one transaction parameter,

wherein the authentication information includes biometric information, user knowledge-based information, or item-based information, and

wherein the authentication request specifies a channel for the user to provide the authentication information.

5. The method of claim 1 , wherein the transaction request is received from the user via a third channel that is different from the first channel.

6. The method of claim 1 , wherein the transaction request for the step-up authentication is sent to the step-up authentication service in response to a risk for the transaction exceeding a threshold.

7. The method of claim 1 , wherein the step-up authentication for the transaction is required based on at least one of: an amount of funds involved with the transaction, an identity of the user, or a device used to request the transaction.

8. A system comprising:

one or more processors; and

one or more memories storing instructions that, when executed by the one or more processors, cause the system to perform a process of authorizing transactions, the process comprising:

receiving, at a step-up authentication service, a transaction request for step-up authentication for a transaction requested by a user,

wherein the transaction request includes a first access token that is active for a first predefined timeframe;

determining authentication information required for the transaction;

sending, via a first channel associated with a client application, an authentication request for the authentication information from the user;

receiving, at the step-up authentication service, the authentication information via a second channel associated with a second application, wherein the second channel associated with the second application is different from the first channel associated with the client application;

generating, by the step-up authentication service, a second access token that is active for at least one of:

a step-up time threshold that is less than the first predefined timeframe, or

a number of step-up transactions; and

sending, to an authentication service, the second access token relating to the transaction,

wherein the transaction is authorized by releasing the second access token.

9. The system according to claim 8 , wherein the process further comprises:

verifying the authentication information from the client application.

10. The system according to claim 8 , wherein the process further comprises:

generating a third access token and exchanging the third access token with the second access token.

11. The system according to claim 8 , wherein the process further comprises:

determining the authentication information required for the transaction based on at least one transaction parameter,

wherein the authentication information includes biometric information, user knowledge-based information, or item-based information, and

wherein the authentication request specifies a channel for the user to provide the authentication information.

12. The system according to claim 8 , wherein the transaction request is received from the user via a third channel that is different from the first channel.

13. The system according to claim 8 , wherein the transaction request for the step-up authentication is sent to the step-up authentication service in response to a risk for the transaction exceeding a threshold.

14. The system according to claim 8 , wherein the step-up authentication for the transaction is required based on at least one of: an amount of funds involved with the transaction, an identity of the user, or a device used to request the transaction.

15. A non-transitory computer-readable medium storing instructions that, when executed by a computing system, cause the computing system to perform operations of authorizing transactions, the operations comprising:

receiving, at a step-up authentication service, a transaction request for step-up authentication for a transaction requested by a user,

wherein the transaction request includes a first access token that is active for a first predefined timeframe;

determining authentication information required for the transaction;

sending, via a first channel associated with a client application, an authentication request for the authentication information from the user;

receiving, at the step-up authentication service, the authentication information via a second channel associated with a second application, wherein the second channel associated with the second application is different from the first channel associated with the client application;

generating, by the step-up authentication service, a second access token that is active for at least one of:

a step-up time threshold that is less than the first predefined timeframe, or

a number of step-up transactions; and

sending, to an authentication service, the second access token relating to the transaction, wherein the transaction is authorized by releasing the second access token.

16. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

verifying the authentication information from the client application.

17. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

generating a third access token and exchanging the third access token with the second access token.

18. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

determining the authentication information required for the transaction based on at least one transaction parameter,

wherein the authentication information includes biometric information, user knowledge-based information, or item-based information, and

wherein the authentication request specifies a channel for the user to provide the authentication information.

19. The non-transitory computer-readable medium of claim 15 , wherein the transaction request is received from the user via a third channel that is different from the first channel.

20. The non-transitory computer-readable medium of claim 15 ,

wherein the transaction request for the step-up authentication is sent to the step-up authentication service in response to a risk for the transaction exceeding a threshold, and

wherein the step-up authentication for the transaction is required based on at least one of: an amount of funds involved with the transaction, an identity of the user, or a device used to request the transaction.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2023
From: VO, HOANG TRUNG; NGUYEN, HIEU
To: UIPCO, LLC
Reel/Frame 064500/0746 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2023
From: UIPCO, LLC
To: UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
Reel/Frame 064500/0792 →
Continuity (3)
Continuation 17237019 · Apr 21, 2021
Continuation 16898360 · Jun 10, 2020
Continuation 15796042 · Oct 27, 2017
References Cited (34)
US 9578015B2 · Xu et al. · 2017 [cited by applicant]
US 10250594B2 · Chathoth et al. · 2019 [cited by applicant]
US 10432605B1 · Lester · 2019 [cited by examiner]
US 10673862B1 · Threlkeld · 2020 [cited by applicant]
US 10686600B1 · Vo · 2020 [cited by examiner]
US 10846389B2 · Jain · 2020 [cited by examiner]
US 11018867B1 · Vo · 2021 [cited by examiner]
US 11750386B1 · Vo · 2023 [cited by examiner]
US 20110004933A1 · Dickinson et al. · 2011 [cited by applicant]
US 20150254672A1 · Huesch · 2015 [cited by examiner]
US 20150334099A1 · Zhang et al. · 2015 [cited by applicant]
US 20160127352A1 · Xu et al. · 2016 [cited by applicant]
US 20160285871A1 · Chathoth et al. · 2016 [cited by applicant]
US 20160337346A1 · Momchilov et al. · 2016 [cited by applicant]
US 20170063932A1 · Hubbard et al. · 2017 [cited by applicant]
US 20170230363A1 · Deutschmann · 2017 [cited by examiner]
US 20170255932A1 · Aabye · 2017 [cited by examiner]
US 20180018660A1 · Gomes et al. · 2018 [cited by applicant]
US 20180082284A1 · Gomes et al. · 2018 [cited by applicant]
US 20180176222A1 · Bhaskar et al. · 2018 [cited by applicant]
US 20180211030A1 · Kim et al. · 2018 [cited by applicant]
US 20180211248A1 · Sims et al. · 2018 [cited by applicant]
US 20180211249A1 · Sims et al. · 2018 [cited by applicant]
US 20180234411A1 · Masiero · 2018 [cited by examiner]
US 20180260550A1 · Shin et al. · 2018 [cited by applicant]
US 20180268405A1 · Lopez · 2018 [cited by applicant]
US 20180309752A1 · Villavicencio et al. · 2018 [cited by applicant]
US 20190034924A1 · Prabhu et al. · 2019 [cited by applicant]
US 20190122209A1 · Shah · 2019 [cited by examiner]
US 20190205045A1 · Hugot · 2019 [cited by examiner]
US 20200097960A1 · Wong · 2020 [cited by examiner]
U.S. Appl. No. 17/237,019, filed Apr. 21, 2021, Asynchronous Step-Up Authentication for Client Applications. [cited by applicant]
U.S. Appl. No. 16/898,360, now U.S. Pat. No. 11,018,867, filed Jun. 10, 2020, May 25, 2021, Asynchronous Step-Up Authentication for Client Applications. [cited by applicant]
U.S. Appl. No. 15/796,042, now U.S. Pat. No. 10,686,600, filed Oct. 27, 2017, Jun. 16, 2020, Asynchronous Step-Up Authentication for Client Applications. [cited by applicant]