IP Library Granted Patent US 12,598,181
Granted Patent B1
US 12,598,181 · App. 18/905,563 · Granted Apr 7, 2026

Adaptive authentication based on real-time risk evaluation

Inventors: Kasiperumal Achappan (Karnatakaq, IN); Ramya Balasubramanian (Telangana, IN); Poornimadevi Pandurangan (Karnataka, IN); Ajay Kumar Panikkar (Sunnyvale, CA); Ravi Kanth Thota (San Francisco, CA)
Assignee: Wells Fargo Bank, N.A.
H04L63/0884
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,181
App. No.
18/905,563
Granted
Apr 7, 2026
Kind
B1
Abstract

A computer system and method for managing device trust during digital interactions. The method comprises capturing device data, including static and dynamic parameters, from a device upon user login to a digital platform. Static parameters are analyzed during the initial login to establish a static trust score, while dynamic parameters are analyzed across sessions to establish a dynamic trust score, which is incrementally updated based on subsequent data. The static and dynamic trust scores are combined to generate a combined trust score, and the device is assigned to one of multiple risk clusters. Based on the assigned cluster, adaptive security protocols are triggered. Assignment to a moderate-risk cluster initiates a step-up authentication process, and failure of the process results in assignment to a high-risk cluster, restricting access to the platform.

Claims (38)

1 . A computer system for managing device trust during digital interactions, comprising:

one or more processors; and

non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, cause the computer system to:

capture device data from a device upon user login to a digital platform, the device data including static parameter data and dynamic parameter data;

analyze the static parameter data during an initial login session to establish a static trust score component for the device;

analyze the dynamic parameter data in the initial login session and across future sessions to establish a dynamic trust score component for the device, wherein the dynamic trust score component is incrementally updated upon analyzing subsequent dynamic parameter data;

combine the static trust score component and the dynamic trust score component to establish a combined trust score;

assign the device to at least one of a first risk cluster, a second risk cluster, or a third risk cluster based on the combined trust score; and

trigger an adaptive security protocol based on an assigned risk cluster,

wherein an assignment to the second risk cluster initiates a moderate risk level authentication process, whereupon failure of the moderate risk level authentication process results in assigning the device to the third risk cluster; and

wherein an assignment to the third risk cluster results in restricted access to the digital platform.

2 . The computer system of claim 1 , wherein the static parameter data comprises at least one of the following: device identifier, secure tag, hardware characteristics, operating system details, device manufacturer, and authentication credentials.

3 . The computer system of claim 1 , wherein the dynamic parameter data comprises at least one of the following: a geo-location, an Internet Protcol address, a session length, a login frequency, a transaction pattern, and a usage anomaly.

4 . The computer system of claim 1 , wherein the first risk cluster corresponds to a trusted status, the second risk cluster corresponds to a moderate risk status, and the third risk cluster corresponds to a high-risk status.

5 . The computer system of claim 1 , further comprising instructions which, when executed by the one or more processors, cause the computer system to update the combined trust score following each update to the dynamic trust score component.

6 . The computer system of claim 1 , further comprising instructions which, when executed by the one or more processors, cause the computer system to utilize an artificial intelligence model to predict future dynamic parameter data for the device based on historical device data.

7 . The computer system of claim 1 , wherein the moderate risk level authentication process comprises initiating a step-up authentication process, including at least one of requiring entry of a one-time passcode, requesting biometric authentication, or presenting a security question.

8 . The computer system of claim 1 , further comprising instructions which, when executed by the one or more processors, cause the computer system to mark the device for dynamic unlearning of a previous risk status.

9 . The computer system of claim 1 , wherein an assignment to the moderate risk level authentication process results in restricting specific actions on the digital platform until completion of the moderate risk level authentication process.

10 . The computer system of claim 1 , wherein assignment to the third risk cluster triggers a manual verification process, wherein a customer contact center or designated authority must approve an assignment of the device to at least one of the first risk cluster or the second risk cluster.

11 . A method for managing device trust during digital interactions, comprising:

capturing device data from a device upon user login to a digital platform, the device data including static parameter data and dynamic parameter data;

analyzing static parameter data during an initial login session to establish a static trust score component for the device;

analyzing the dynamic parameter data in the initial login session and across future sessions to establish a dynamic trust score component for the device, wherein the dynamic trust score component is incrementally updated upon analyzing subsequent dynamic parameter data;

combining the static trust score component and the dynamic trust score component to establish combined trust score;

assigning the device to at least one of a first risk cluster, a second risk cluster, or a third risk cluster based on the combined trust score;

triggering an adaptive security protocol based on an assigned risk cluster,

wherein an assignment to the second risk cluster initiates a moderate risk level authentication process, whereupon failure of the moderate risk level authentication process results in assigning the device to the third risk cluster; and

wherein an assignment to the third risk cluster results in restricted access to the digital platform.

12 . The method of claim 11 , wherein the static parameter data comprises at least one of the following: device identifier, secure tag, hardware characteristics, operating system details, device manufacturer, and authentication credentials.

13 . The method of claim 11 , wherein the dynamic parameter data comprises at least one of the following: a geo-location, an Internet Protcol address, a session length, a login frequency, a transaction pattern, and a usage anomaly.

14 . The method of claim 11 , wherein the first risk cluster corresponds to a trusted status, the second risk cluster corresponds to a moderate risk status, and the third risk cluster corresponds to a high-risk status.

15 . The method of claim 11 , further comprising updating the combined trust score following each update to the dynamic trust score component.

16 . The method of claim 11 , further comprising utilizing an artificial intelligence model to predict future dynamic parameter data for the device based on historical device data.

17 . The method of claim 11 , wherein the moderate risk level authentication process comprises initiating a step-up authentication process, including at least one of requiring entry of a one-time passcode, requesting biometric authentication, or presenting a security question.

18 . The method of claim 11 , further comprising marking the device for dynamic unlearning of a previous risk status, wherein a trust profile of the device is dynamically updated and reset after successful authentication or risk mitigation actions.

19 . The method of claim 11 , wherein an assignment to the moderate risk level authentication process results in restricting specific actions on the digital platform until completion of the moderate risk level authentication process.

20 . The method of claim 11 , wherein assignment to the third risk cluster triggers a manual verification process, wherein a customer contact center or designated authority must approve an assignment of the device to at least one of the first risk cluster or the second risk cluster.

Assignments (2)
STATEMENT OF CHANGE OF ADDRESS OF ASSIGNEE Recorded Jun 17, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071649/0870 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2025
From: ACHAPPAN, KASIPERUMAL; BALASUBRAMANIAN, RAMYA; PANDURANGAN, POORNIMADEVI; PANIKKAR, AJAY KUMAR; THOTA, RAVI KANTH
To: WELLS FARGO BANK, N.A.
Reel/Frame 070766/0212 →
References Cited (16)
US 9979744B1 · Casillas · 2018 [cited by examiner]
US 20120054826A1 · Asim · 2012 [cited by examiner]
US 20140359722A1 · Schultz · 2014 [cited by examiner]
US 20150067831A1 · Wawda · 2015 [cited by examiner]
US 20150089568A1 · Sprague · 2015 [cited by examiner]
US 20160127900A1 · John Archibald · 2016 [cited by examiner]
US 20160224803A1 · Frank · 2016 [cited by examiner]
US 20180293387A1 · Bar-El · 2018 [cited by examiner]
US 20190132308A1 · Graham · 2019 [cited by examiner]
US 20200274902A1 · Gopal · 2020 [cited by examiner]
US 20200322169A1 · Michaud · 2020 [cited by examiner]
US 20210297455A1 · Keith, Jr. · 2021 [cited by examiner]
US 20220353276A1 · Hegrat · 2022 [cited by examiner]
US 20230237134A1 · Douglas · 2023 [cited by examiner]
US 20240195819A1 · Grajek · 2024 [cited by examiner]
US 20250030739A1 · O'Neill · 2025 [cited by examiner]