IP Library › Granted Patent US 12,204,618
Granted Patent B1
US 12,204,618 · App. 17/379,720 · Granted Jan 21, 2025

Authentication using third-party data

Inventor: David Hatch (Daly City, CA)
Assignee: Wells Fargo Bank, N.A.
G06F21/316G06F21/36H04L63/0428H04L63/0884H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,204,618
App. No.
17/379,720
Granted
Jan 21, 2025
Kind
B1
Abstract

In an example, techniques of this disclosure include establishing, by a computing device, authentication data for authenticating a user of a service provided by a service provider, where the authentication data comprises one or more first data entries and one or more second data entries that correspond to the one or more first data entries. The techniques also include retrieving, from at least one third-party service provider, one or more second data entries maintained by the at least one third-party service provider that correspond to the one or more first data entries, and authenticating the user based on the authentication data, where authenticating the user comprises comparing the one or more first data entries to the one or more second data entries retrieved from the at least one third-party service provider.

Claims (53)

1. A method comprising:

receiving, by a computing device of a service provider, one or more second data entries associated with a user account of a user at a third-party service provider, wherein the one or more second data entries are user-generated data entries for the user account of the third-party service provider;

generating, by the computing device, one or more first data entries to be stored at the computing device based on the second data entries;

receiving, by the computing device and from a user device, a request to authenticate a user to access a service provided by the service provider, wherein the request to authenticate includes an indication of at least one of the first data entries that are stored at the computing device;

in response to the request to authenticate, retrieving, by the computing device and from the user account of the user at the third-party service provider, at least one of the second data entries that corresponds to the at least one of the first data entries; and

authenticating, by the computing device, the user to access the service provided by the service provider based on a comparison of the at least one of the first data entries stored at the computing device to the at least one of the second data entries retrieved from the user account of the user at the third-party service provider.

2. The method of claim 1 , wherein authenticating the user comprises verifying correspondence between the at least one of the first data entries stored at the computing device and the at least one of the second data entries retrieved from the user account of the user at the third-party service provider.

3. The method of claim 2 ,

wherein generating the one or more first data entries based on the second data entries comprises applying a modification to at least one portion of data included in the second data entries; and

wherein verifying the correspondence comprises verifying that a difference between the at least one of the first data entries and the at least one of the second data entries comprises the modification applied to the at least one portion of the data included in the at least one of the second data entries to generate the at least one of the first data entries.

4. The method of claim 1 , wherein the one or more second data entries comprise a plurality of second data entries, and wherein receiving the plurality of second data entries comprises receiving the plurality of second data entries from two or more user accounts of the user at two or more third-party service providers.

5. The method of claim 4 , wherein receiving the plurality of second data entries from the two or more user accounts of the user at the two or more third-party service providers comprises accessing each of the user accounts of the user at each of the third-party service providers using credentials for the respective one of the user accounts that are stored at the computing device.

6. The method of claim 4 , wherein retrieving the at least one of the second data entries that corresponds to the at least one of the first data entries comprises:

identifying the user account of the user at the third-party service provider from the two or more user accounts of the user at the two or more third-party service providers at which the at least one of the second data entries is stored; and

accessing the user account of the user at the third-party service provider using credentials for the user account that are stored at the computing device.

7. The method of claim 4 ,

wherein the request to authenticate the user includes an indication of two or more of the first data entries that are stored at the computing device, wherein the two or more of the first data entries correspond to two or more of the second data entries that are stored at different ones of the two or more user accounts of the user at the two or more third-party service providers;

wherein retrieving each of the two or more of the second data entries comprises accessing each of the two or more user account of the user at the two or more third-party service providers using credentials for the user accounts that are stored at the computing device; and

wherein authenticating the user comprises verifying correspondence between each of the two or more of the first data entries stored at the computing device and a respective one of the two or more of the second data entries retrieved from the two or more user accounts of the user at the two or more third-party service providers.

8. The method of claim 1 , wherein generating the one or more first data entries based on the second data entries comprises modifying at least one portion of data included in the second data entries.

9. The method of claim 8 , wherein the second data entries comprise user-generated text, and wherein modifying the portion of data included in the second data entries comprises applying an encryption technique to the text.

10. The method of claim 8 , wherein the second data entries comprise user-generated images, and wherein modifying the portion of data included in the second data entries comprises modifying the images, adding an electronic tag to the images, or modifying binary code associated with the images.

11. The method of claim 8 , wherein the second data entries comprise user-generated videos, and wherein modifying the portion of data included in the second data entries comprises modifying a frame of the videos or modifying a frame rate of the videos.

12. The method of claim 1 , wherein the user account of the user at the third-party service provider comprises a social media account registered to the user, and wherein the second data entries comprise at least one of text, an image, or a video posted to the social media account of the user.

13. A computing device of a service provider, the computing device comprising:

one or more memory units; and

one or more processors in communication with the memory units, the one or more processors configured to:

receiving one or more second data entries associated with a user account of a user at a third-party service provider, wherein the one or more second data entries are user-generated data entries for the user account of the third-party service provider;

generate one or more first data entries to be stored at the computing device;

receive, from a user device, a request to authenticate a user to access a service provided by the service provider, wherein the request to authenticate includes an indication of at least one of the first data entries that are stored at the computing device;

in response to the request to authenticate, retrieve, from the user account of the user at the third-party service provider, at least one of the second data entries that corresponds to the at least one of the first data entries; and

authenticate the user to access the service provided by the service provider based on a comparison of the at least one of the first data entries stored at the computing device to the at least one of the second data entries retrieved from the user account of the user at the third-party service provider.

14. The computing device of claim 13 , wherein to authenticate the user, the one or more processors are configured to verify correspondence between the at least one of the first data entries stored at the computing device and the at least one of the second data entries retrieved from the user account of the user at the third-party service provider.

15. The computing device of claim 14 ,

wherein to generate the one or more first data entries based on the second data entries, the one or more processors are configured to apply a modification to at least one portion of data included in the second data entries; and

wherein to verify the correspondence, the one or more processors are configured to verify that a difference between the at least one of the first data entries and the at least one of the second data entries comprises the modification applied to the at least one portion of the data included in the at least one of the second data entries to generate the at least one of the first data entries.

16. The computing device of claim 13 , wherein the one or more second data entries comprise a plurality of second data entries, and wherein the one or more processors are configured to:

receive the plurality of second data entries from two or more user accounts of the user at two or more third-party service providers; and

to retrieve the at least one of the second data entries that corresponds to the at least one of the first data entries:

identify the user account of the user at the third-party service provider from the two or more user accounts of the user at the two or more third-party service providers at which the at least one of the second data entries is stored, and

access the user account of the user at the third-party service provider using credentials for the user account that are stored at the computing device.

17. The computing device of claim 13 , wherein the one or more second data entries comprise a plurality of second data entries, and wherein the one or more processors are configured to receive the plurality of second data entries from two or more user accounts of the user at two or more third-party service providers;

wherein the request to authenticate the user includes an indication of two or more of the first data entries that are stored at the computing device, wherein the two or more of the first data entries correspond to two or more of the second data entries that are stored at different ones of the two or more user accounts of the user at the two or more third-party service providers;

wherein to retrieve each of the two or more of the second data entries, the one or more processors are configured to access each of the two or more user account of the user at the two or more third-party service providers using credentials for the user accounts that are stored at the computing device; and

wherein to authenticate the user, the one or more processors are configured to verify correspondence between each of the two or more of the first data entries stored at the computing device and a respective one of the two or more of the second data entries retrieved from the two or more user accounts of the user at the two or more third-party service providers.

18. The computing device of claim 13 , wherein to generate the one or more first data entries based on the second data entries, the one or more processors are configured to modify at least one portion of data included in the second data entries.

19. The computing device of claim 13 , wherein the user account of the user at the third-party service provider comprises a social media account registered to the user, and wherein the second data entries comprise at least one of text, an image, or a video posted to the social media account of the user.

20. A non-transitory computer readable medium having instructions stored thereon that, when executed, cause one or more processors of a computing device of a service provider to:

receive one or more second data entries associated with a user account of a user at a third-party service provider, wherein the one or more second data entries are user-generated data entries for the user account of the third-party service provider;

generate one or more first data entries to be stored at the computing device based on the second data entries;

receive, from a user device, a request to authenticate a user to access a service provided by the service provider, wherein the request to authenticate includes an indication of at least one of the first data entries that are stored at the computing device;

in response to the request to authenticate, retrieve, from the user account of the user at the third-party service provider, at least one of the second data entries that corresponds to the at least one of the first data entries; and

authenticate the user to access the service provided by the service provider based on a comparison of the at least one of the first data entries stored at the computing device to the at least one of the second data entries retrieved from the user account of the user at the third-party service provider.

Continuity (3)
Continuation 16707806 · Dec 9, 2019
Continuation 16005438 · Jun 11, 2018
Continuation 14881123 · Oct 12, 2015
References Cited (39)
US 7231657B2 · Honarvar et al. · 2007 [cited by applicant]
US 7496637B2 · Han et al. · 2009 [cited by applicant]
US 8391825B2 · Arseneau et al. · 2013 [cited by applicant]
US 8667279B2 · Rao · 2014 [cited by applicant]
US 8838748B2 · Nair et al. · 2014 [cited by applicant]
US 9674205B2 · Kirkham et al. · 2017 [cited by applicant]
US 10025914B1 · Hatch · 2018 [cited by applicant]
US 10509900B1 · Shahbazi · 2019 [cited by examiner]
US 10521573B1 · Hatch · 2019 [cited by applicant]
US 11068570B1 · Hatch · 2021 [cited by applicant]
US 20020048369A1 · Ginter et al. · 2002 [cited by applicant]
US 20030149781A1 · Yared et al. · 2003 [cited by applicant]
US 20060282660A1 · Varghese et al. · 2006 [cited by applicant]
US 20070018952A1 · Arseneau et al. · 2007 [cited by applicant]
US 20070174709A1 · Sluiman et al. · 2007 [cited by applicant]
US 20070201502A1 · Abramson · 2007 [cited by applicant]
US 20080189420A1 · Herrod et al. · 2008 [cited by applicant]
US 20090138951A1 · Birk et al. · 2009 [cited by applicant]
US 20090282460A1 · Brooks · 2009 [cited by applicant]
US 20100125504A1 · Agha · 2010 [cited by applicant]
US 20110265165A1 · Lam · 2011 [cited by applicant]
US 20120066752A1 · Vysogorets et al. · 2012 [cited by applicant]
US 20130145148A1 · Shablygin et al. · 2013 [cited by applicant]
US 20130278631A1 · Border et al. · 2013 [cited by applicant]
US 20150161366A1 · Ghosh et al. · 2015 [cited by applicant]
US 20150310188A1 · Ford et al. · 2015 [cited by applicant]
US 20160212116A1 · Becker et al. · 2016 [cited by applicant]
US 20160358178A1 · Ghosh et al. · 2016 [cited by applicant]
US 20170372316A1 · Ghosh et al. · 2017 [cited by applicant]
WO 2014182957A1 · 2014 [cited by applicant]
Hanumanthappa et al., 2012 IEEE International Conference on Innovations in Information Technology (IIT), “Privacy Preserving and Ownership Authentication in Ubiquitous Computing Devices using Secure Three Way Authentica… [cited by examiner]
Alotaibi et al., 2015 IEEE Conferences, “Enhancing OAuth Services Security by an Authentication Service with Face Recognition”, pp. 1-6 (Year: 2015). [cited by examiner]
Prosecution History from U.S. Appl. No. 14/881,123, dated Jul. 3, 2017 through Jun. 22, 2018, 96 pp. [cited by applicant]
Paul et al., “5G-Enabled Decentralised Services”, 2015 IEEE, Date of Conference: May 11-14, 2015, 5 pages. [cited by applicant]
Prosecution History from U.S. Appl. No. 16/005,438, dated Dec. 26, 2018 through Nov. 25, 2019, 72 pp. [cited by applicant]
Rodriguez et al., “Extending e-business to pervasive computing devices”, IBM.com/redbooks, Apr. 2001, pp. 1-277. [cited by applicant]
Sundareswaran et al., “Ensuring Distributed Accountability for Data Sharing in the Cloud”, IEEE Transactions on Dependable and Secure Computing, vol. 9, No. 4, Jul./Aug. 2012, pp. 556-568. [cited by applicant]
Zhang et al., “NDCMC: A Hybrid Data Collection Approach for Large-Scale WSNs Using Mobile Element and Hierarchical Clustering”, IEEE Internet of Things Journal, vol. 3, No. 4, Aug. 2016, pp. 533-543. [cited by applicant]
Prosecution History from U.S. Appl. No. 16/707,806, dated Oct. 30, 2019, through Mar. 25, 2021, 25 pp. [cited by applicant]