IP Library Granted Patent US 12,273,341
Granted Patent B2
US 12,273,341 · App. 16/421,536 · Granted Apr 8, 2025

Mutual identity verification

Inventors: Dale Bowie (Benowa, AU); Jasmine Anne Smith (Southport, AU); Jared Ross Page (Southport, AU)
Assignee: International Business Machines Corporation
H04L63/0869H04L63/0861H04W12/06H04W12/69
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,341
App. No.
16/421,536
Granted
Apr 8, 2025
Kind
B2
Abstract

A method, system, and computer program product for frictionless mutual authentication of unsolicited communications may detect an incoming communication. A verification interface may be displayed on a consumer device. On the consumer device, a first valid verification may be received via the verification interface. In response to receiving the first valid verification, a challenge interface may be presented to an enterprise device. On the enterprise device, a second valid verification may be received via the challenge interface. In response to receiving the second valid verification, a verification credential may be presented to both the consumer device and the enterprise device. A connection for the incoming communication may be established between the consumer device and the enterprise device.

Claims (59)

1. A method for mutual authentication of communications, comprising:

detecting an incoming communication to a consumer device from an enterprise device;

in response to detecting the incoming communication, causing a verification interface to be displayed on the consumer device;

receiving, from the consumer device, a first valid verification via the verification interface;

in response to receiving the first valid verification, causing a challenge interface to be displayed on the enterprise device;

receiving, from the enterprise device, a second valid verification via the challenge interface;

in response to receiving the second valid verification, presenting, to both the consumer device and the enterprise device, a verification credential; and

based on the second valid verification, establishing, between the consumer device and the enterprise device, a new connection for the incoming communication.

2. The method of claim 1 , wherein the first valid verification includes an authentic biometric measurement of a user of the consumer device, wherein the biometric measurement confirms the identity of the user of the consumer device.

3. The method of claim 1 , wherein an invalid verification is received via the verification interface, the method further comprising:

determining a security criterion has been met; and

in response to determining the security criterion has been met, adding an identifier for the consumer device to a lockout list.

4. The method of claim 1 , wherein an invalid verification is received via the challenge interface, the method further comprising:

determining a security criterion has been met; and

in response to determining the security criterion has been met, adding an identifier for the enterprise device to a lockout list.

5. The method of claim 1 , wherein the first and second valid verifications are executed via an out-of-band line of communication.

6. The method of claim 3 , further comprising:

determining the identifier was erroneously added to the lockout list; and

in response to determining the identifier was erroneously added, removing the identifier from the lockout list.

7. The method of claim 4 , further comprising:

determining the identifier was erroneously added to the lockout list; and

in response to determining the identifier was erroneously added, removing the identifier from the lockout list.

8. The method of claim 5 , wherein the first and second valid verifications include keys derived from unique identifiers of the consumer device and the enterprise device, respectively.

9. A computer program product for mutual authentication of communications, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a device to cause the device to:

detect an incoming communication to a consumer device from an enterprise device;

in response to detecting the incoming communication, causing a verification interface to be displayed on the consumer device;

receive, from the consumer device, a first valid verification via the verification interface;

in response to receiving the first valid verification, causing a challenge interface to be displayed on the enterprise device;

receive, from the enterprise device, a second valid verification via the challenge interface;

in response to receiving the second valid verification, present, to both the consumer device and the enterprise device, a verification credential; and

based on the second valid verification, establish, between the consumer device and the enterprise device, a new connection for the incoming communication.

10. The computer program product of claim 9 , wherein the first valid verification includes an authentic biometric measurement of a user of the consumer device, wherein the biometric measurement confirms the identity of the user of the consumer device.

11. The computer program product of claim 9 , wherein an invalid verification is received via the verification interface, the program instructions further causing the device to:

determine a security criterion has been met; and

in response to determining the security criterion has been met, add an identifier for the consumer device to a lockout list.

12. The computer program product of claim 9 , wherein an invalid verification is received via the challenge interface, the program instructions further causing the device to:

determine a security criterion has been met; and

in response to determining the security criterion has been met, add an identifier for the enterprise device to a lockout list.

13. The computer program product of claim 9 , wherein the first and second valid verifications are executed via an out-of-band line of communication.

14. The computer program product of claim 11 , wherein the program instructions further cause the device to:

determine the identifier was erroneously added to the lockout list; and

in response to determining the identifier was erroneously added, remove the identifier from the lockout list.

15. The computer program product of claim 12 , wherein the program instructions further cause the device to:

determine the identifier was erroneously added to the lockout list; and

in response to determining the identifier was erroneously added, remove the identifier from the lockout list.

16. The computer program product of claim 13 , wherein the first and second valid verifications include keys derived from unique identifiers of the consumer device and the enterprise device, respectively.

17. A system for mutual authentication of communications, comprising:

a memory with program instructions stored thereon; and

a processor in communication with the memory, wherein the program instructions are executable by the processor to cause the system to:

detect an incoming communication to a consumer device from an enterprise device;

in response to detecting the incoming communication, causing a verification interface to be displayed on the consumer device;

receive, from the consumer device, a first valid verification via the verification interface;

in response to receiving the first valid verification, causing a challenge interface to be displayed on the enterprise device;

receive, from the enterprise device, a second valid verification via the challenge interface;

in response to receiving the second valid verification, present, to both the consumer device and the enterprise device, a verification credential; and

based on the second valid verification, establish, between the consumer device and the enterprise device, a new connection for the incoming communication.

18. The system of claim 17 , wherein the first valid verification includes an authentic biometric measurement of a user of the consumer device, wherein the biometric measurement confirms the identity of the user of the consumer device.

19. The system of claim 17 , wherein the first and second valid verifications are executed via an out-of-band line of communication.

20. The system of claim 19 , wherein the first and second valid verifications include keys derived from unique identifiers of the consumer device and the enterprise device, respectively.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2019
From: BOWIE, DALE; SMITH, JASMINE ANNE; PAGE, JARED ROSS
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 049274/0687 →
Continuity (1)
Related Publication 20200374287A1 · Nov 26, 2020
References Cited (14)
US 8028329B2 · Whitcomb · 2011 [cited by applicant]
US 8156334B2 · Ho · 2012 [cited by applicant]
US 8220030B2 · Singhal · 2012 [cited by applicant]
US 8549594B2 · Lin · 2013 [cited by applicant]
US 9197746B2 · Kurapati et al. · 2015 [cited by applicant]
US 9716715B2 · Daley et al. · 2017 [cited by applicant]
US 10110738B1 · Sawant · 2018 [cited by examiner]
US 10659459B1 · Gadwale · 2020 [cited by examiner]
US 20040254990A1 · Mittal · 2004 [cited by applicant]
US 20180294959A1 · Traynor et al. · 2018 [cited by applicant]
US 20200076792A1 · Ray · 2020 [cited by examiner]
US 20200195776A1 · Harrison · 2020 [cited by examiner]
US 20200259830A1 · Shaffer · 2020 [cited by examiner]
Reaves et al., “AuthentiCall: Efficient Identity and Content Authentication for Phone Calls”,This paper is included in the Proceedings of the 26th USENIX Security Symposium, Aug. 16-18, 2017 ⋅ Vancouver, BC, Canada, ISB… [cited by applicant]