IP Library › Granted Patent US 11,108,774
Granted Patent B2
US 11,108,774 · App. 16/449,704 · Granted Aug 31, 2021

Method and system for verifying user identity

Inventors: Ryan Fox (Lebanon, OH); Matthew Thompson (Alexandria, VA)
Assignee: Capital One Services, LLC
H04L63/0884H04L63/0876H04L63/12H04L67/02H04L67/306H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,774
App. No.
16/449,704
Filed
Jun 24, 2019
Granted
Aug 31, 2021
Kind
B2
Art Unit
2436
USPC
726/7
Abstract

Embodiments disclosed herein generally relate to a system and method of verifying an identity of user. A computing system receives a HTTP request. The HTTP request includes at least a user name and an IP address associated with a router accessed by the remote client device. The computing system parses the HTTP request to extract the user name and the IP address contained therein. The computing system identifies a user account associated with the extracted user name. The computing system identifies an internet service provider associated with the IP address. The computing system transmits a verification message to the third party service provider. The computing system receives a confirmation message from the third party service provider. The computing system increases a level of confidence in an identification verification process based on the confirmation.

Claims (69)

1. A method of verifying an identity of a user, comprising:

receiving, by a computing system from a remote client device, an authentication attempt via a website associated with the computing system, data of the authentication attempt including at least a user name and a first internet protocol (IP) address associated with a router accessed by the remote client device;

determining, by the computing system, that data in the authentication attempt matches a user account registered with the computing system;

identifying, by the computing system, a previous authentication attempt from the remote client device, data of the previous authentication attempt including the user name and a second IP address associated with a second router accessed by the remote client device;

determining, by the computing system, that the first IP address is different from the second IP address;

in response to determining that the first IP address is different from the second IP address, performing, by the computing system, a further authentication process comprising:

identifying, by the computing system, a third party internet service provider associated with the first IP address;

transmitting, by the computing system, a verification message to the third party internet service provider associated with the first IP address, wherein the verification message includes identification information associated with the user account; and

receiving, by the computing system, a confirmation message from the third party internet service provider indicative of a confirmation that the identification information associated with the user account at least partially matches identification information associated with an account with the third party internet service provider; and

authenticating, by the computing system, the remote client device.

2. The method of claim 1 , further comprising:

receiving, by the computing system from the remote client device, a third authentication attempt, data of the third authentication attempt including at least the user name and a third IP address associated with a third router accessed by the remote client device;

determining that the third IP address is equal to the first IP Address; and

authenticating the remote client device.

3. The method of claim 2 , wherein there are no intermediary authentication attempts between the authentication attempt and the third authentication attempt.

4. The method of claim 1 , wherein transmitting, by the computing system, the verification message to the third party internet service provider associated with the first IP address comprises:

querying a database to retrieve identification information associated with the user account; and

generating a message that includes one or more items of identification.

5. The method of claim 1 , wherein the identification information comprises at least a name, address, social security number, telephone number, email address, date of birth, and credit card information.

6. The method of claim 1 , wherein the identification information associated with the account with the third party internet service provider includes a name of an authorized user to a primary user of the account with the third party internet service provider.

7. The method of claim 1 , wherein transmitting, by the computing system, the verification message to the third party internet service provider associated with the first IP address further comprises:

transmitting a current location of the remote client device.

8. The method of claim 1 , further comprising:

pre-populating, by the computing system, one or more fields of a form based on information in the confirmation message; and

prompting, by the computing system, the remote client device to display the form.

9. The method of claim 1 , wherein transmitting, by the computing system, the verification message to the third party internet service provider associated with the first IP address comprises:

transmitting an API call comprising the verification to the internet service provider.

10. A system, comprising:

a processor; and

a memory having programming instructions stored thereon, which, when executed by the processor, performs operations comprising:

receiving, from a remote client device, an authentication attempt, the authentication attempt via a website associated with the system, the authentication attempt including at least a user name and a first internet protocol (IP) address associated with a router accessed by the remote client device;

determining that data in the authentication attempt matches a user account registered with the system;

identifying a previous authentication attempt from the remote client device, the previous authentication attempt including the user name and a second IP address associated with a second router accessed by the remote client device;

determining that the first IP address is different from the second IP address;

in response to determining that the first IP address is different from the second IP address, performing a further authentication process comprising:

identifying a third party internet service provider associated with the first IP address;

transmitting a verification message to the third party internet service provider associated with the first IP address, wherein the verification message includes identification information associated with the user account; and

receiving a confirmation message from the third party internet service provider indicative of a confirmation that the identification information associated with the user account at least partially matches identification information associated with an account with the third party internet service provider; and

authenticating the remote client device.

11. The system of claim 10 , wherein the operations further comprise:

receiving, from the remote client device, a third authentication attempt, the third authentication attempt including at least the user name and a third IP address associated with a third router accessed by the remote client device;

determining that the third IP address is equal to the first IP Address; and

authenticating the remote client device.

12. The system of claim 11 , wherein there are no intermediary authentication attempts between the authentication attempt and the third authentication attempt.

13. The system of claim 10 , wherein transmitting the verification message to the third party internet service provider associated with the first IP address comprises:

querying a database to retrieve identification information associated with the user account; and

generating a message that includes one or more items of identification.

14. The system of claim 10 , wherein the identification information comprises at least a name, address, social security number, telephone number, email address, date of birth, and credit card information.

15. The system of claim 10 , wherein the identification information associated with the account with the third party internet service provider includes a name of an authorized user to a primary user of the account with the third party internet service provider.

16. The system of claim 10 , wherein transmitting the verification message to the third party internet service provider associated with the first IP address further comprises:

transmitting a current location of the remote client device.

17. The system of claim 10 , wherein the operations further comprise:

pre-populating one or more fields of a form based on information in the confirmation message; and

prompting the remote client device to display the form.

18. A non-transitory computer readable medium including one or more sequences of instructions, which, when executed by one or more processors, cause the one or more processors to perform operations, comprising:

receiving, by a computing system from a remote client device, an authentication attempt via a website associated with the computing system, data of the authentication attempt including at least a user name and a first internet protocol (IP) address associated with a router accessed by the remote client device;

determining, by the computing system, that data in the authentication attempt matches a user account registered with the computing system;

identifying, by the computing system, a previous authentication attempt from the remote client device, data of the previous authentication attempt including the user name and a second IP address associated with a second router accessed by the remote client device;

determining, by the computing system, that the first IP address is different from the second IP address;

in response to determining that the first IP address is different from the second IP address, performing, by the computing system, a further authentication process comprising:

identifying, by the computing system, a third party internet service provider associated with the first IP address;

transmitting, by the computing system, a verification message to the third party internet service provider associated with the first IP address, wherein the verification message includes identification information associated with the user account; and

receiving, by the computing system, a confirmation message from the third party internet service provider indicative of a confirmation that the identification information associated with the user account at least partially matches identification information associated with an account with the third party internet service provider; and

authenticating, by the computing system, the remote client device.

19. The non-transitory computer readable medium of claim 18 , wherein the operations further comprise:

receiving, by the computing system from the remote client device, a third authentication attempt, data of the third authentication attempt including at least the user name and a third IP address associated with a third router accessed by the remote client device;

determining that the third IP address is equal to the first IP Address; and

authenticating the remote client device.

20. The non-transitory computer readable medium of claim 19 , wherein there are no intermediary authentication attempts between the authentication attempt and the third authentication attempt.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2019
From: FOX, RYAN; THOMPSON, MATTHEW
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 049564/0470 →
Continuity (2)
Division 15978389 · May 14, 2018
Related Publication 20190349373A1 · Nov 14, 2019