IP Library › Granted Patent US 12,363,089
Granted Patent B1
US 12,363,089 · App. 18/401,314 · Granted Jul 15, 2025

Mobile application authentication infrastructure

Inventors: Andrew P. Jamison (San Antonio, TX); Jared Anthony Bluntzer (San Antonio, TX); Dallin Clarence Wilcox (San Antonio, TX)
Assignee: United Services Automobile Association (USAA)
H04L63/08H04L63/102H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,363,089
App. No.
18/401,314
Granted
Jul 15, 2025
Kind
B1
Abstract

Various embodiments of the present technology generally relate to authentication. More specifically, some embodiments relate to systems and methods for mobile application infrastructure and framework for application authentication. Currently, methods and systems for authentication are not flexible or dynamic and over-authentication has become a solution because it is cheap and easy. In contrast, in accordance with some embodiments of this application, the methods and systems can analyze authentication challenges and non-authentication challenges received from a server over a network in a client side infrastructure. The client side infrastructure can determine a customized, flexible, and dynamic plan for responding to authentication challenges in manner that avoids over-authentication on the client side.

Claims (54)

1. A computer-implemented method comprising:

determining, by an authentication coordinator, whether a user requested activity requires an authentication based on where information regarding the user requested activity is stored, wherein the information regarding the user requested activity indicates multiple levels of authentication and types of user activities;

in response to a determination that the user requested activity requires the authentication, determining multiple authentication challenges, by an authentication plan mapper, for a user based on the user requested activity, wherein the multiple authentication challenges is determined based on a customized authentication plan, wherein the customized authentication plan is based on

a protocol incorporating one or more factors corresponding to the user requested activity, and

implementation of only a portion of the multiple authentication challenges to limit user input so as to increase efficiency;

requesting the user to provide authentication information in a single response satisfying a level of authentication; and

authenticating the user based on the multiple authentication challenges and the single response.

2. The computer-implemented method of claim 1 , further comprising:

receiving a request from the user, wherein the request indicates a type of information to be accessed by the user; and

prioritizing the multiple authentication challenges for the user based on the type of the information.

3. The computer-implemented method of claim 2 , further comprising enabling access, for the user, to the information, wherein the enabling is based on a result of the authenticating the user.

4. The computer-implemented method of claim 1 , further comprising prioritizing the multiple authentication challenges for the user based on a protocol, wherein the protocol includes a device preference, a user preference, and/or a desired response time.

5. The computer-implemented method of claim 1 , further comprising:

determining that available authentication information, for the selected one or more of the authentication challenges, is insufficient; and

prompting the user for additional authentication information;

wherein the authenticating the user is further based on the additional authentication information.

6. The computer-implemented method of claim 1 , further comprising:

receiving a request from the user, wherein the request indicates a type of information to be accessed by the user; and

determining the level of authentication based on the type of the information.

7. The computer-implemented method of claim 6 , wherein the information to be accessed by the user includes information regarding a number of shares owned by the user.

8. The computer-implemented method of claim 6 , wherein the information to be accessed by the user includes personal information of the user.

9. The computer-implemented method of claim 6 , wherein the information to be accessed by the user includes an account balance of the user.

10. The computer-implemented method of claim 1 , wherein the single response to the authentication challenges includes a voiceprint.

11. The computer-implemented method of claim 1 , wherein the single response to the authentication challenges includes a fingerprint.

12. A non-transitory machine-readable memory having stored thereon machine-executable instructions that, when executed by one or more processors, cause the one or more processors to perform a process comprising:

determine, by an authentication coordinator, whether a user requested activity requires an authentication based on where information regarding the user requested activity is stored, wherein the information regarding the user requested activity indicates multiple levels of authentication and types of user activities;

in response to a determination that the user requested activity requires the authentication, determine multiple authentication challenges, by an authentication plan mapper, for a user based on the user requested activity, wherein the multiple authentication challenges is determined based on a customized authentication plan, wherein the customized authentication plan is based on

a protocol incorporating one or more factors corresponding to the user requested activity, and

implementation of only a portion of the multiple authentication challenges to limit user input so as to increase efficiency;

request the user to provide authentication information in a single satisfying a level of authentication; and

authenticate the user based on the multiple authentication challenges and the single response.

13. The non-transitory machine-readable memory of claim 12 , wherein the process further comprises:

receiving a request from the user, wherein the request indicates a type of information to be accessed by the user; and

determining the level of authentication based on the type of the information.

14. The non-transitory machine-readable memory of claim 12 , wherein the single response to the authentication challenges includes a voiceprint.

15. The non-transitory machine-readable memory of claim 12 , wherein the single response to the authentication challenges includes a fingerprint.

16. The non-transitory machine-readable memory of claim 12 , wherein the process further comprises:

receiving a request from the user, wherein the request indicates a type of information to be accessed by the user; and

prioritizing the multiple authentication challenges for the user based on the type of the information.

17. The non-transitory machine-readable memory of claim 16 , wherein the process further comprises:

enabling access, for the user, to the information, wherein the enabling is based on a result of the authenticating the user.

18. A computing system comprising:

one or more processors; and

one or more memories, storing instructions that, when executed by the one or more processors, cause the computing system to perform a process comprising:

determining, by an authentication coordinator, whether a user requested activity requires an authentication based on where information regarding the user requested activity is stored, wherein the information regarding the user requested activity indicates multiple levels of authentication and types of user activities;

in response to a determination that the user requested activity requires the authentication, determining multiple authentication challenges, by an authentication plan mapper, for a user based on the user requested activity, wherein the multiple authentication challenges is determined based on a customized authentication plan, wherein the customized authentication plan is based on

a protocol incorporating one or more factors corresponding to the user requested activity, and

implementation of only a portion of the multiple authentication challenges to limit user input so as to increase efficiency;

requesting the user to provide authentication information in a single response satisfying a level of authentication; and

authenticating the user based on the multiple authentication challenges and the single response for actions associated with the selected one or more of the authentication challenges.

19. The computing system of claim 18 , wherein the process further comprises:

receiving a request from the user, wherein the request indicates a type of information to be accessed by the user; and

determining the level of authentication based on the information.

20. The computing system of claim 19 , wherein the process further comprises prioritizing the multiple authentication challenges for the user based on the type of the information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2024
From: JAMISON, ANDREW P.; BLUNTZER, JARED ANTHONY; WILCOX, DALLIN CLARENCE
To: UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
Reel/Frame 067598/0019 →
Continuity (4)
Continuation 17161428 · Jan 28, 2021
Continuation 16557236 · Aug 30, 2019
Continuation 14586442 · Dec 30, 2014
Provisional Application 61953560 · Mar 14, 2014
References Cited (20)
US 6023762A · Dean · 2000 [cited by examiner]
US 9430624B1 · Mortensen et al. · 2016 [cited by applicant]
US 10447677B1 · Jamison et al. · 2019 [cited by applicant]
US 10938799B1 · Jamison et al. · 2021 [cited by applicant]
US 20030051147A1 · Maeda et al. · 2003 [cited by applicant]
US 20030084289A1 · Watanabe · 2003 [cited by applicant]
US 20030163739A1 · Armington · 2003 [cited by applicant]
US 20030225703A1 · Angel · 2003 [cited by applicant]
US 20050240428A1 · Gabrick et al. · 2005 [cited by applicant]
US 20080066165A1 · Rosenoer · 2008 [cited by applicant]
US 20090292927A1 · Wenzel et al. · 2009 [cited by applicant]
US 20100158233A1 · Caceres et al. · 2010 [cited by applicant]
US 20100251338A1 · James · 2010 [cited by applicant]
US 20120214442A1 · Crawford et al. · 2012 [cited by applicant]
US 20140068730A1 · Hamilton, II et al. · 2014 [cited by applicant]
US 20140082713A1 · Markel · 2014 [cited by examiner]
US 20140280740A1 · Alley · 2014 [cited by examiner]
US 20140289833A1 · Briceno et al. · 2014 [cited by applicant]
US 20150244701A1 · Hamilton, II et al. · 2015 [cited by applicant]
US 20160087952A1 · Tartz · 2016 [cited by applicant]