IP Library › Granted Patent US 12,261,846
Granted Patent B2
US 12,261,846 · App. 18/631,333 · Granted Mar 25, 2025

Confirming authenticity of a user to a third-party system

Inventors: Helcio Cano (Peachtree Corners, GA); Rich Huffman (Roswell, GA); Ravindra Bijlani (Alpharetta, GA); Richard Michaelson (Shoreview, MN); Rob Harris (Minneapolis, MN); Vivian Van Zyl (Atlanta, GA); Esther Pigg (Duluth, GA); Marty Romain (Oakdale, MN)
Assignees: Equifax, Inc.; Fidelity Information Services, Inc.
H04L63/0884H04L63/083H04L67/53H04L9/3271H04L67/306H04L2463/102H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,846
App. No.
18/631,333
Granted
Mar 25, 2025
Kind
B2
Abstract

A telecommunications network server system provides a digital identifier to a user device. The digital identifier may include identification data corresponding to a user of the user device. In addition, the telecommunications network server system receives, from one or more third-party systems, requests to authenticate the user for an electronic transaction with the respective third-party system. The telecommunications network server system provides a unique electronic transaction code to each third-party system. Responsive to receiving from the user device one of the unique electronic transaction codes, the telecommunications network server system provides, to the respective third-party system, authentication of the user.

Claims (62)

1. A server device comprising:

at least one processor; and

a non-transitory computer-readable storage device comprising instructions that are executable by the at least one processor to:

receive an electronic transaction code and a digital identifier of a user device associated with a user to authenticate the user to perform transactions through the user device at a third-party electronic device;

confirm the electronic transaction code and the digital identifier, wherein confirming comprises:

validating the electronic transaction code by matching the electronic transaction code with a stored electronic transaction code from a plurality of electronic transaction codes stored in a network storage; and

verifying authenticity of the user associated with the digital identifier as involved in a transaction with the third-party electronic device; and

in response to confirming the electronic transaction code and the digital identifier, provide a confirmation of the authenticity of the user to the third-party electronic device for use in authenticating a requested transaction by the user device at the third-party electronic device.

2. The server device of claim 1 , wherein the non-transitory computer-readable storage device includes instructions that are executable by the processor to:

transmit via a network communications port the digital identifier to the user device associated with the user authenticated by the server device, the digital identifier being electronically tethered or bound to the user device.

3. The server device of claim 1 , wherein confirming the electronic transaction code and the digital identifier comprises:

in response to receiving the electronic transaction code and the digital identifier, transmit a demand to the user device for the user to provide confirmatory input to the user device for receipt by the server device; and

receive the confirmatory input from the user device,

wherein the confirmation of authenticity of the user is provided to the third-party electronic device only subsequent to receiving the confirmatory input from the user device.

4. The server device of claim 1 , wherein the electronic transaction code is a Quick Response (QR) code that is scanable by the user device.

5. The server device of claim 1 , wherein the non-transitory computer-readable storage device includes instructions that are executable by the processor to:

monitor an amount of time between transmitting the electronic transaction code to the third-party electronic device and receiving the electronic transaction code and the digital identifier from the user device; and

in response to determining the amount of time is greater than a pre-selected threshold amount of time, transmit via a network communications port an indication of unsuccessful confirmation of authenticity of the user to the third-party electronic device.

6. The server device of claim 1 , wherein the non-transitory computer-readable storage device includes instructions that are executable by the processor to:

transmit via a network communications port an obfuscated version of the digital identifier to the third-party electronic device, the obfuscated version of the digital identifier being usable by the third-party electronic device to authenticate the user based on the digital identifier stored in the user device and being not usable to confirm authenticity of the user with the electronic transaction code.

7. The server device of claim 1 , wherein the non-transitory computer-readable storage device includes instructions that are executable by the processor to:

receive from the user device a command to share personal identification information about the user to the third-party electronic device and one or more types of personal identification information to share to the third-party electronic device; and

transmit via a network communications port the personal identification information about the user as selected from the user device to the third-party electronic device.

8. The server device of claim 1 , wherein the non-transitory computer-readable storage device includes instructions that are executable by the processor to:

receive requests from the third-party electronic devices that are separate from each other, the requests indicating that the user is requesting to be authenticated for transactions with the third-party electronic devices;

transmit a plurality of electronic transaction codes to the third-party electronic devices, the plurality of electronic transaction codes including unique codes such that each unique code corresponds to one transaction;

receive the plurality of electronic transaction codes and the digital identifier from the user device; and

in response to confirming the plurality of electronic transaction codes and the digital identifier, transmit confirmations of authenticity of the user to the third-party electronic devices.

9. A method comprising:

receiving an electronic transaction code and a digital identifier of a user device associated with a user to authenticate the user to perform transactions through the user device at a third-party electronic device;

confirming the electronic transaction code and the digital identifier, wherein confirming comprises:

validating the electronic transaction code by matching the electronic transaction code with a stored electronic transaction code from a plurality of electronic transaction codes stored in a network storage; and

verifying authenticity of the user associated with the digital identifier as involved in a transaction with the third-party electronic device; and

in response to confirming the electronic transaction code and the digital identifier, providing a confirmation of the authenticity of the user to the third-party electronic device for use in authenticating a requested transaction by the user device at the third-party electronic device.

10. The method of claim 9 , comprising:

transmitting via a network communications port the digital identifier to the user device associated with the user, the digital identifier being electronically tethered or bound to the user device.

11. The method of claim 9 , wherein confirming the electronic transaction code and the digital identifier comprises:

in response to receiving the electronic transaction code and the digital identifier, transmitting a demand to the user device for the user to provide confirmatory input to the user device; and

receiving the confirmatory input from the user device,

wherein the confirmation of authenticity of the user is provided to the third-party electronic device only subsequent to receiving the confirmatory input from the user device.

12. The method of claim 9 , wherein the electronic transaction code is a Quick Response (QR) code that is scanable by the user device.

13. The method of claim 9 , comprising:

monitoring an amount of time between transmitting the electronic transaction code to the third-party electronic device and receiving the electronic transaction code and the digital identifier from the user device; and

in response to determining the amount of time is greater than a pre-selected threshold amount of time, transmitting via a network communications port an indication of unsuccessful confirmation of authenticity of the user to the third-party electronic device.

14. A non-transitory computer-readable medium embodying program code for authenticating a user to a third-party electronic device, the program code comprising instructions which, when executed by a processor, cause the processor to perform operations including:

receiving an electronic transaction code and a digital identifier of a user device associated with a user to authenticate the user to perform transactions through the user device at a third-party electronic device;

confirming the electronic transaction code and the digital identifier, wherein confirming comprises:

validating the electronic transaction code by matching the electronic transaction code with a stored electronic transaction code from a plurality of electronic transaction codes stored in a network storage; and

verifying authenticity of the user associated with the digital identifier as involved in a transaction with the third-party electronic device; and

in response to confirming the electronic transaction code and the digital identifier, providing a confirmation of the authenticity of the user to the third-party electronic device for use in authenticating a requested transaction by the user device at the third-party electronic device.

15. The non-transitory computer-readable medium of claim 14 , comprising instructions that are executable by the processor to perform operations comprising:

transmitting via a network communications port the digital identifier to the user device associated with the user, the digital identifier being electronically tethered or bound to the user device.

16. The non-transitory computer-readable medium of claim 14 , wherein confirming the electronic transaction code and the digital identifier comprises:

in response to receiving the electronic transaction code and the digital identifier, transmitting a demand to the user device for the user to provide confirmatory input to the user device; and

receiving the confirmatory input from the user device,

wherein the confirmation of authenticity of the user is provided to the third-party electronic device only subsequent to receiving the confirmatory input from the user device.

17. The non-transitory computer-readable medium of claim 14 , wherein the electronic transaction code is a Quick Response (QR) code that is scanable by the user device.

18. The non-transitory computer-readable medium of claim 14 , comprising instructions that are executable by the processor to perform operations comprising:

monitoring an amount of time between transmitting the electronic transaction code to the third-party electronic device and receiving the electronic transaction code and the digital identifier from the user device; and

in response to determining the amount of time is greater than a pre-selected threshold amount of time, transmitting via a network communications port an indication of unsuccessful confirmation of authenticity of the user to the third-party electronic device.

19. The non-transitory computer-readable medium of claim 14 , comprising instructions that are executable by the processor to perform operations comprising:

transmitting via a network communications port an obfuscated version of the digital identifier to the third-party electronic device, the obfuscated version of the digital identifier being usable by the third-party electronic device to authenticate the user based on the digital identifier stored in the user device and being not usable to confirm authenticity of the user with the electronic transaction code.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: HARRIS, ROB; VAN ZYL, VIVIAN; PIGG, ESTHER; ROMAIN, MARTY
To: FIDELITY INFORMATION SERVICES, LLC
Reel/Frame 068475/0800 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: CANO, HELCIO; HUFFMAN, RICH; BIJLANI, RAVINDRA; MICHAELSON, RICHARD
To: EQUIFAX, INC.
Reel/Frame 068475/0877 →
Continuity (5)
Continuation 18128628 · Mar 30, 2023
Continuation 17523674 · Nov 10, 2021
Continuation 16473182
Provisional Application 62443236 · Jan 6, 2017
Related Publication 20240259372A1 · Aug 1, 2024
References Cited (18)
US 11962590B2 · Cano et al. · 2024 [cited by applicant]
US 20120017266A1 · Dichiara et al. · 2012 [cited by applicant]
US 20130132234A1 · Grossi et al. · 2013 [cited by applicant]
US 20130219479A1 · DeSoto · 2013 [cited by examiner]
US 20130334323A1 · Chiviendacz et al. · 2013 [cited by applicant]
US 20150235211A1 · Hurry et al. · 2015 [cited by applicant]
US 20150334108A1 · Khalil · 2015 [cited by examiner]
US 20160019539A1 · Hoyos et al. · 2016 [cited by applicant]
US 20160294821A1 · Neuman et al. · 2016 [cited by applicant]
US 20200092287A1 · Cano et al. · 2020 [cited by applicant]
US 20220070169A1 · Cano et al. · 2022 [cited by applicant]
US 20230239295A1 · Cano et al. · 2023 [cited by applicant]
WO WO2015170118 · 2015 [cited by applicant]
WO WO2018129373 · 2018 [cited by applicant]
Extended European Search Report in EP 22172670.6, dated Jul. 12, 2022, 8 pages. [cited by applicant]
Office Action in Australian Application No. 2018206414, dated Nov. 23, 2021, 6 pages. [cited by applicant]
Office Action in Australian Application No. 2022203766, dated Apr. 26, 2023, 4 pages. [cited by applicant]
PCT International Search Report and Written Opinion in International Application No. PCT/US2018/012658, dated Apr. 23, 2018, 16 pages. [cited by applicant]