IP Library › Granted Patent US 12,255,893
Granted Patent B1
US 12,255,893 · App. 17/244,548 · Granted Mar 18, 2025

Peer-to-peer authentication with a secure channel communication

Inventors: Elroi Luria (Ramat Gan, IL); Shay Davidpur (Ness Ziona, IL); Dina Vaingolts (Ramat Gan, IL); Yaniv Bouhadana (Netanya, IL); Oded Margalit (Ramat Gan, IL)
Assignee: Citibank, N.A.
H04L63/0869H04L63/083H04L63/20H04L67/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,255,893
App. No.
17/244,548
Granted
Mar 18, 2025
Kind
B1
Abstract

An identity verification system enables peer-to-peer authentication in a potentially insecure channel by leveraging a secure channel communication. The system authenticates a user via an identity verification application. The system provides a validation code to the user. The user communicates the validation code to a counterparty of the peer-to-peer communication. The system receives a request to authenticate the counterparty with the validation code and counterparty authentication data. The system authenticates the counterparty and sends the user the authentication of the counterparty. Alternatively, the user device communicates a request to generate a secure code for participants in a first insecure group application session. The user device selects an authenticated counterparty to receive the secure code from a list of authenticated counterparties. The user creates a second application session using the secure code as a password. Unauthenticated counterparties would not receive the secure code and are restricted from the new session.

Claims (35)

1. A system to allow counterparties communicating on insecure communication networks to verify one another via separate identity verification network systems, the system being configured for executing application code instructions that are stored in a storage device to cause the system to:

determine that a malicious user has accessed an insecure communications channel associated with a first application, wherein a user using a user computing device is in communications with a counterparty using a counterparty computing device;

in response to determining that the malicious user has accessed the insecure communications channel associated with the first application and using a second application on the user computing device, transmit, to an identity verification network server and from the user computing device, a request to authenticate each user using the insecure communications channel by using user authentication data, wherein the request is transmitted over a communications channel that is separate and independent from the insecure communications channel;

receive, from the identity verification network server, a validation code upon authenticating the user, wherein the identity verification network server authenticates the counterparty and, based on authenticating the counterparty, transmits the validation code to the counterparty computing device, and wherein the validation code is withheld from the malicious user;

in response to receiving the validation code, generate a new secure communication session between the user computing device and the counterparty computing device that is accessed using a passcode that is generated based on the validation code having been received by both the user computing device and the counterparty computing device; and

communicate, to the counterparty computing device, an indication of the new secure communication session.

2. The system of claim 1 , wherein the application code instructions further cause the system to communicate an indicator of authentication of the user to the counterparty computing device.

3. The system of claim 1 , wherein the application code instructions further cause the system to associate the counterparty with the user based on the validation code.

4. The system of claim 1 , wherein authentication of the counterparty comprises one or more of a picture and a name of the counterparty.

5. The system of claim 1 , wherein the validation code is an alphanumeric code.

6. The system of claim 1 , wherein the validation code is a machine-readable code.

7. The system of claim 1 , wherein the user authentication data is a biometric data entry.

8. The system of claim 1 , wherein the user communicates the validation code to the counterparty.

9. The system of claim 8 , wherein the user communicates the validation code verbally.

10. The system of claim 1 , wherein the user computing device automatically communicates the validation code to the counterparty computing device upon receiving the validation code.

11. The system of claim 1 , wherein the validation code is a randomly-generated code generated by a processor.

12. The system of claim 1 , wherein the application code instructions for generating the new secure communication session between the user computing device and the counterparty computing device, cause:

generating a new video conference session having a secure passcode for accessing the new video conference session, wherein the secure passcode is generated based on the validation code received by both the user computing device and the counterparty computing device.

13. The system of claim 1 , wherein the application code instructions for generating the new secure communication session between the user computing device and the counterparty computing device, cause:

generating a new video conference session having a secure passcode for accessing the new video conference session; and

setting the secure passcode to the validation code received by both the user computing device and the counterparty computing device.

14. A method, comprising:

joining, by a user computing device, a first insecure group application session of a first application on an insecure group network system;

determining that a malicious user has accessed the first insecure group application session of the first application;

in response to determining that the malicious user has accessed the first insecure group application session of the first application, communicating, by the user computing device and to an identity verification system device, a request to generate a secure code and to communicate the secure code to a counterparty computing device, the counterparty computing device being associated with a counterparty on a list of one or more authenticated counterparties in the first insecure group application session;

receiving, by the user computing device and from the identity verification system device, the secure code, wherein the secure code is received by the counterparty computing device, and wherein the secure code is withheld from the malicious user; and

in response to receiving the secure code, generating, by the user computing device, a second insecure group application session between the user computing device and the counterparty computing device, the second insecure group application session being accessed using a passcode that is generated based on the secure code having been received by both the user computing device and the counterparty computing device.

15. The method of claim 14 , further comprising authenticating, by the identity verification system device, the user computing device and one or more counterparties in the first insecure group application session.

16. The method of claim 14 , further comprising joining, by the user computing device and the counterparty computing device, the second insecure group application session by signing in with the secure code.

17. The method of claim 14 , wherein the user computing device communicates the request to generate the secure code based on a determination that a suspicious party is participating in the first insecure group application session.

18. The method of claim 14 , wherein the user computing device selects the counterparty computing device to which the identity verification system device is to send the secure code from the list of one or more authenticated counterparties.

19. The method of claim 14 , further comprising communicating, by the identity verification system device, the list of one or more authenticated counterparties in the first insecure group application session to the user computing device.

20. The method of claim 14 , wherein generating the second insecure group application session comprises:

generating a new video conference session having a secure passcode for accessing the new video conference session; and

setting the secure passcode to the secure code received by both the user computing device and the counterparty computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2021
From: DAVIDPUR, SHAY; LURIA, ELROI; VAINGOLTS, DINA; BOUHADANA, YANIV; MARGALIT, ODED
To: CITIBANK, N.A.
Reel/Frame 056092/0314 →
References Cited (10)
US 8151116B2 · van der Horst · 2012 [cited by examiner]
US 8490162B1 · Popoveniuc · 2013 [cited by examiner]
US 8613066B1 · Brezinski · 2013 [cited by examiner]
US 9071616B2 · Lau · 2015 [cited by examiner]
US 10708774B2 · Koo · 2020 [cited by examiner]
US 10721225B1 · Baszucki · 2020 [cited by examiner]
US 20210218725A1 · Fang · 2021 [cited by examiner]
US 20220417228A1 · Singh · 2022 [cited by examiner]
US 20230007002A1 · Lelcuk · 2023 [cited by examiner]
US 20230125139A1 · Luo · 2023 [cited by examiner]