IP Library › Granted Patent US 11,882,103
Granted Patent B1
US 11,882,103 · App. 17/161,428 · Granted Jan 23, 2024

Mobile application authentication infrastructure

Inventors: Andrew P. Jamison (San Antonio, TX); Jared Anthony Bluntzer (San Antonio, TX); Dallin Clarence Wilcox (San Antonio, TX)
Assignee: United Services Automobile Association (USAA)
H04L63/08H04L63/102H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,882,103
App. No.
17/161,428
Granted
Jan 23, 2024
Kind
B1
Abstract

Various embodiments of the present technology generally relate to authentication. More specifically, some embodiments relate to systems and methods for mobile application infrastructure and framework for application authentication. Currently, methods and systems for authentication are not flexible or dynamic and over-authentication has become a solution because it is cheap and easy. In contrast, in accordance with some embodiments of this application, the methods and systems can analyze authentication challenges and non-authentication challenges received from a server over a network in a client side infrastructure. The client side infrastructure can determine a customized, flexible, and dynamic plan for responding to authentication challenges in manner that avoids over-authentication on the client side.

Claims (54)

1. A computer-implemented method comprising:

receiving information regarding a user requested activity;

determining, by an authentication coordinator, whether the user requested activity requires an authentication based on where the information regarding the user requested activity is stored;

in response to a determination that the user requested activity requires the authentication, determining multiple authentication challenges for a user based on the user requested activity;

requesting the user to provide authentication information in a single response to the authentication challenges, wherein the authentication information associated with the single response satisfies a level of authentication;

selecting one or more of the authentication challenges having at most the level of authentication; and

authenticating the user based on the single response for actions associated with the selected one or more of the authentication challenges.

2. The computer-implemented method of claim 1 , further comprising:

receiving a request from the user, wherein the request indicates a type of information to be accessed by the user; and

prioritizing the multiple authentication challenges for the user based on the type of the information.

3. The computer-implemented method of claim 2 , further comprising enabling access, for the user, to the information, wherein the enabling is based on a result of the authenticating the user.

4. The computer-implemented method of claim 1 , further comprising prioritizing the multiple authentication challenges for the user based on a protocol, wherein the protocol includes a device preference, a user preference, and/or a desired response time.

5. The computer-implemented method of claim 1 , further comprising:

determining that available authentication information, for the selected one or more of the authentication challenges, is insufficient; and

prompting the user for additional authentication information;

wherein the authenticating the user is further based on the additional authentication information.

6. The computer-implemented method of claim 1 , further comprising:

receiving a request from the user, wherein the request indicates a type of information to be accessed by the user; and

determining the level of authentication based on the type of the information.

7. The computer-implemented method of claim 6 , wherein the information to be accessed by the user includes information regarding a number of shares owned by the user.

8. The computer-implemented method of claim 6 , wherein the information to be accessed by the user includes personal information of the user.

9. The computer-implemented method of claim 6 , wherein the information to be accessed by the user includes an account balance of the user.

10. The computer-implemented method of claim 1 , wherein the single response to the authentication challenges includes a voiceprint.

11. The computer-implemented method of claim 1 , wherein the single response to the authentication challenges includes a fingerprint.

12. A non-transitory machine-readable memory having stored thereon machine-executable instructions that, when executed by one or more processors, cause the one or more processors to perform a process comprising:

receive information regarding a user requested activity;

determine, by an authentication coordinator, whether the user requested activity requires an authentication based on where the information regarding the user requested activity is stored;

in response to a determination that the user requested activity requires the authentication, determine multiple authentication challenges for a user based on the user requested activity;

request the user to provide authentication information in a single response to the authentication challenges, wherein the authentication information associated with the single response satisfies a level of authentication;

select one or more of the authentication challenges having at most the level of authentication; and

authenticate the user based on the single response for actions associated with the selected one or more of the authentication challenges.

13. The non-transitory machine-readable memory of claim 12 , wherein the process further comprises:

receiving a request from the user, wherein the request indicates a type of information to be accessed by the user; and

determining the level of authentication based on the type of the information.

14. The non-transitory machine-readable memory of claim 12 , wherein the single response to the authentication challenges includes a voiceprint.

15. The non-transitory machine-readable memory of claim 12 , wherein the single response to the authentication challenges includes a fingerprint.

16. The non-transitory machine-readable memory of claim 12 , wherein the process further comprises:

receiving a request from the user, wherein the request indicates a type of information to be accessed by the user; and

prioritizing the multiple authentication challenges for the user based on the type of the information.

17. The non-transitory machine-readable memory of claim 16 , wherein the process further comprises:

enabling access, for the user, to the information, wherein the enabling is based on a result of the authenticating the user.

18. A computing system comprising:

one or more processors; and

one or more memories, storing instructions that, when executed by the one or more processors, cause the computing system to perform a process comprising:

receiving information regarding a user requested activity;

determining, by an authentication coordinator, whether the user requested activity requires an authentication based on where the information regarding the user requested activity is stored;

in response to a determination that the user requested activity requires the authentication, determining multiple authentication challenges for a user based on the user requested activity;

requesting the user to provide authentication information in a single response to the authentication challenges, wherein the authentication information associated with the single response satisfies a level of authentication;

selecting one or more of the authentication challenges having at most the level of authentication; and

authenticating the user based on the single response for actions associated with the selected one or more of the authentication challenges.

19. The computing system of claim 18 , wherein the process further comprises:

receiving a request from the user, wherein the request indicates a type of information to be accessed by the user; and

determining the level of authentication based on the information.

20. The computing system of claim 19 , wherein the process further comprises prioritizing the multiple authentication challenges for the user based on the type of the information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2021
From: JAMISON, ANDREW P.; BLUNTZER, JARED ANTHONY; WILCOX, DALLIN CLARENCE
To: UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
Reel/Frame 055070/0023 →
Continuity (3)
Continuation 16557236 · Aug 30, 2019
Continuation 14586442 · Dec 30, 2014
Provisional Application 61953560 · Mar 14, 2014
Cited By (1)
US 12,432,192