IP Library › Granted Patent US 11,632,371
Granted Patent B2
US 11,632,371 · App. 17/523,674 · Granted Apr 18, 2023

Confirming authenticity of a user to a third-party system

Inventors: Helcio Cano (Peachtree Corners, GA); Rich Huffman (Roswell, GA); Ravindra Bijlani (Alpharetta, GA); Richard Michaelson (Shoreview, MN); Rob Harris (Minneapolis, MN); Vivian Van Zyl (Atlanta, GA); Esther Pigg (Duluth, GA); Marty Romain (Oakdale, MN)
Assignees: Equifax, Inc.; Fidelity Information Services LLC
H04L63/0884H04L63/083H04L67/53H04L9/3271H04L67/306H04L2463/102H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,632,371
App. No.
17/523,674
Granted
Apr 18, 2023
Kind
B2
Abstract

A telecommunications network server system provides a digital identifier to a user device. The digital identifier may include identification data corresponding to a user of the user device. In addition, the telecommunications network server system receives, from one or more third-party systems, requests to authenticate the user for an electronic transaction with the respective third-party system. The telecommunications network server system provides a unique electronic transaction code to each third-party system. Responsive to receiving from the user device one of the unique electronic transaction codes, the telecommunications network server system provides, to the respective third-party system, authentication of the user.

Claims (68)

1. A telecommunications network server device comprising:

at least one processor;

a network communications port configured for being controlled by the at least one processor; and

a non-transitory computer-readable storage device comprising instructions that are executable by the at least one processor to:

receive via the network communications port a request from a third-party electronic device that a user is requesting to be authenticated for a particular transaction with the third-party electronic device;

in response to the request, transmit via the network communications port an electronic transaction code to the third-party electronic device;

receive the electronic transaction code and a digital identifier from a user device associated with the user, the digital identifier being storable in encrypted form in the user device and usable to authenticate the user for transactions with third-party electronic devices that are communicatively separate from each other, the digital identifier being electronically tethered or bound to the user device;

confirm the electronic transaction code and the digital identifier; and

in response to confirming the electronic transaction code and the digital identifier, transmit via the network communications port a confirmation of authenticity of the user to the third-party electronic device.

2. The telecommunications network server device of claim 1 , wherein the electronic transaction code is a Quick Response (QR) code that is scannable by the user device.

3. The telecommunications network server device of claim 1 , wherein confirming the electronic transaction code and the digital identifier comprises:

monitoring an amount of time between transmitting the electronic transaction code to the third-party electronic device and receiving the electronic transaction code and the digital identifier from the user device; and

in response to determining the amount of time is greater than a pre-selected threshold amount of time, transmitting via the network communications port an indication of unsuccessful confirmation of authenticity of the user to the third-party electronic device.

4. The telecommunications network server device of claim 1 , wherein the non-transitory computer-readable storage device includes instructions that are executable by the at least one processor to:

transmit via the network communications port an obfuscated version of the digital identifier to the third-party electronic device, the obfuscated version of the digital identifier being usable by the third-party electronic device to authenticate the user based on the digital identifier stored in the user device and being not usable to confirm authenticity of the user with the electronic transaction code.

5. The telecommunications network server device of claim 1 , wherein the non-transitory computer-readable storage device includes instructions that are executable by the at least one processor to:

receive from the user device a command to share personal identification information about the user to the third-party electronic device and one or more types of personal identification information to share to the third-party electronic device; and

transmit via the network communications port the personal identification information about the user as selected from the user device to the third-party electronic device.

6. The telecommunications network server device of claim 1 , wherein the non-transitory computer-readable storage device includes instructions that are executable by the at least one processor to:

receive requests from the third-party electronic devices that are separate from each other, the requests indicating that the user is requesting to be authenticated for transactions with the third-party electronic devices;

transmit a plurality of electronic transaction codes to the third-party electronic devices, the plurality of electronic transaction codes including unique codes such that each unique code corresponds to one transaction;

receive the plurality of electronic transaction codes and the digital identifier from the user device; and

in response to confirming the plurality of electronic transaction codes and the digital identifier, transmit confirmations of authenticity of the user to the third-party electronic devices.

7. The telecommunications network server device of claim 1 , wherein the electronic transaction code uniquely identifies the particular transaction between the user and the third-party electronic device.

8. The telecommunications network server device of claim 1 , wherein the request from the third-party electronic device that the user is requesting to be authenticated for the particular transaction with the third-party electronic device is received after an online session is established between the user device associated with the user and the third-party electronic device via the Internet.

9. A method of authenticating a user to a third-party electronic device, the method comprising operations executable by one or more processors, the operations including:

receiving via a network communications port a request from a third-party electronic device that a user is requesting to be authenticated for a particular transaction with the third-party electronic device;

in response to the request, transmitting via the network communications port an electronic transaction code to the third-party electronic device;

receiving the electronic transaction code and a digital identifier from a user device associated with the user, the digital identifier being storable in encrypted form in the user device and usable to authenticate the user for transactions with third-party electronic devices that are communicatively separate from each other, the digital identifier being electronically tethered or bound to the user device;

confirming the electronic transaction code and the digital identifier; and

in response to confirming the electronic transaction code and the digital identifier, transmitting via the network communications port a confirmation of authenticity of the user to the third-party electronic device.

10. The method of claim 9 , wherein confirming the electronic transaction code and the digital identifier comprises:

monitoring an amount of time between transmitting the electronic transaction code to the third-party electronic device and receiving the electronic transaction code and the digital identifier from the user device; and

in response to determining the amount of time is greater than a pre-selected threshold amount of time, transmitting via the network communications port an indication of unsuccessful confirmation of authenticity of the user to the third-party electronic device.

11. The method of claim 9 , the operations further including:

transmitting via the network communications port an obfuscated version of the digital identifier to the third-party electronic device, the obfuscated version of the digital identifier being usable by the third-party electronic device to authenticate the user based on the digital identifier stored in the user device and being not usable to confirm authenticity of the user with the electronic transaction code.

12. The method of claim 9 , the operations further including:

receiving from the user device a command to share personal identification information about the user to the third-party electronic device and one or more types of personal identification information to share to the third-party electronic device; and

transmitting via the network communications port the personal identification information about the user as selected from the user device to the third-party electronic device.

13. The method of claim 9 , the operations further including:

receiving requests from the third-party electronic devices that are separate from each other, the requests indicating that the user is requesting to be authenticated for transactions with the third-party electronic devices;

transmitting a plurality of electronic transaction codes to the third-party electronic devices, the plurality of electronic transaction codes including unique codes such that each unique code corresponds to one transaction;

receiving the plurality of electronic transaction codes and the digital identifier from the user device; and

in response to confirming the plurality of electronic transaction codes and the digital identifier, transmitting, confirmations of authenticity of the user to the third-party electronic devices.

14. The method of claim 9 , wherein the electronic transaction code uniquely identifies the particular transaction between the user and the third-party electronic device.

15. The method of claim 9 , wherein the request from the third-party electronic device that the user is requesting to be authenticated for the particular transaction with the third-party electronic device is received after an online session is established between the user device associated with the user and the third-party electronic device via the Internet.

16. A non-transitory computer-readable medium embodying program code for authenticating a user to a third-party electronic device, the program code comprising instructions which, when executed by at least one processor, cause the at least one processor to perform operations including:

receiving via a network communications port a request from a third-party electronic device that a user is requesting to be authenticated for a particular transaction with the third-party electronic device;

in response to the request, transmitting via the network communication port an electronic transaction code to the third-party electronic device;

receiving the electronic transaction code and a digital identifier from a user device associated with the user, the digital identifier being storable in encrypted form in the user device and usable to authenticate the user for transactions with third-party electronic devices that are communicatively separate from each other, the digital identifier being electronically tethered or bound to the user device;

confirming the electronic transaction code and the digital identifier; and

in response to confirming the electronic transaction code and the digital identifier, transmitting via the network communication port a confirmation of authenticity of the user to the third-party electronic device.

17. The non-transitory computer-readable medium of claim 16 , wherein the electronic transaction code is a Quick Response (QR) code scannable by the user device.

18. The non-transitory computer-readable medium of claim 16 , the operations further including:

monitoring an amount of time between transmitting the electronic transaction code to the third-party electronic device and receiving the electronic transaction code and the digital identifier from the user device; and

in response to determining the amount of time is greater than a pre-selected threshold amount of time, transmitting via the network communications port an indication of unsuccessful confirmation of authenticity of the user to the third-party electronic device.

19. The non-transitory computer-readable medium of claim 16 , the operations further including:

transmitting via the network communications port an obfuscated version of the digital identifier to the third-party electronic device, the obfuscated version of the digital identifier being usable by the third-party electronic device to authenticate the user based on the digital identifier stored in the user device and being not usable to confirm authenticity of the user with the electronic transaction code.

20. The non-transitory computer-readable medium of claim 16 , the operations further including:

receiving from the user device a command to share personal identification information about the user with the third-party electronic device and one or more types of the personal identification information to share with the third-party electronic device; and

transmitting via the network communications port the personal identification information about the user as selected from the user device to the third-party electronic device.

21. The non-transitory computer-readable medium of claim 16 , the operations further including:

receiving requests from the third-party electronic devices that are separate from each other, the requests indicating that the user is requesting to be authenticated for transactions with the third-party electronic devices;

transmitting a plurality of electronic transaction codes to the third-party electronic devices, the plurality of electronic transaction codes including unique codes such that each unique code corresponds to one transaction;

receiving the plurality of electronic transaction codes and the digital identifier from the user device; and

in response to confirming the plurality of electronic transaction codes and the digital identifier, transmitting confirmations of authenticity of the user to the third-party electronic devices.

22. The non-transitory computer-readable medium of claim 16 , wherein the electronic transaction code uniquely identifies the particular transaction between the user and the third-party electronic device.

23. The non-transitory computer-readable medium of claim 16 , wherein the request from the third-party electronic device that the user is requesting to be authenticated for the particular transaction with the third-party electronic device is received after an online session is established between the user device associated with the user and the third-party electronic device via the Internet.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2021
From: CANO, HELCIO; HUFFMAN, RICH; BIJLANI, RAVINDRA; MICHAELSON, RICHARD
To: EQUIFAX, INC.
Reel/Frame 058104/0893 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2021
From: HARRIS, ROB; ZYL, VIVIAN VAN; PIGG, ESTHER; ROMAIN, MARTY
To: FIDELITY INFORMATION SERVICES, LLC
Reel/Frame 058104/0930 →
Continuity (3)
Continuation 16473182
Provisional Application 62443236 · Jan 6, 2017
Related Publication 20220070169A1 · Mar 3, 2022
Cited By (1)
US 12,720,560