IP Library Granted Patent US 9,838,872
Granted Patent B2
US 9,838,872 · App. 14/922,727 · Granted Dec 5, 2017

System and method for mobile identity protection for online user authentication

Inventors: Charles L. Dennis (Issaquah, WA); Randall A Snyder (Las Vegas, NV); Michael F Buhrmann (North Bend, WA); Patrick J. Boyle (Seattle, WA)
Assignee: Visa International Service Association
H04W12/06G06F21/35G06Q20/108G06Q20/32H04L63/08H04L63/0876H04L63/10H04L63/1416H04W12/08H04W12/12H04L63/0853H04W84/005
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,838,872
App. No.
14/922,727
Granted
Dec 5, 2017
Kind
B2
Abstract

An automated system and method for authenticating entities or individuals attempting to access a computer application, network, system or device using a wireless device is provided. The system employs one or more short-range wireless interfaces (e.g. BLUETOOTH or Wi-Fi) or long-range wireless interfaces (e.g. cellular or WiMAX)to detect the presence or location of the wireless device and it's proximity to the secure system to be accessed. The wireless device incorporates a unique identifier and secure authentication key information associated with the user of the wireless device. An authentication result is generated and may be used for a variety of applications. The application may process the result and determine the degree of access for which the entity or individual is allowed.

Claims (39)

1. A method for detecting fraud using a wireless device of an entity, the method comprising:

obtaining, by an authentication application, data regarding an application access event from a data network, the application access event being an attempt to access an application by the entity, and wherein the application access event is automatically invoked when the wireless device of the entity is proximate to a mobile access point associated with the application;

obtaining, by the authentication application, a unique identifier representing the entity;

obtaining, by the authentication application, a location of the application access event from the mobile access point;

obtaining, by the authentication application, a location of the wireless device;

generating, by the authentication application, an authentication result based on at least the location of the application access event and a time that the location of the application access event was obtained, and the location of the wireless device; and

allowing or not allowing the entity to access the application based upon the authentication result.

2. The method of claim 1 , wherein the unique identifier is a mobile directory number.

3. The method of claim 1 , wherein the data regarding the application access event comprises an application ID representing the application.

4. The method of claim 1 , wherein the mobile access point is a personal computer.

5. The method of claim 1 , wherein the authentication result is used to deny access to the application.

6. An apparatus comprising:

a processor; and

a computer readable medium, the computer readable medium comprising code, executable by the processor, to implement a method comprising:

obtaining data regarding an application access event from a data network, the application access event being an attempt to access an application by an entity, and wherein the application access event is automatically invoked when a wireless device of the entity is proximate to a mobile access point associated with the application;

obtaining a unique identifier representing the entity;

obtaining a location of the application access event from the mobile access point;

obtaining a location of the wireless device;

generating an authentication result based on at least the location of the application access event and a time that the location of the application access event was obtained, and the location of the wireless device; and

allowing or not allowing the entity to access the application based upon the authentication result.

7. The apparatus of claim 6 , wherein the unique identifier is a mobile directory number.

8. The apparatus of claim 6 , wherein the data regarding the application access event comprises an application ID representing the application.

9. The apparatus of claim 6 , wherein the mobile access point is a base station.

10. The apparatus of claim 6 , wherein the authentication result is used to deny access to the application.

11. A method of authenticating an entity using a wireless device associated with the entity and configured to generate a wireless signal, the method comprising the steps of:

detecting the wireless device entering into proximity of an electronic device configured to provide the entity, upon authentication of the entity, access to use of an application requiring secure access;

obtaining from the wireless signal a unique identifier associated with the wireless device;

obtaining a location of the wireless device based on the unique identifier;

obtaining data regarding a location of the electronic device;

generating an authentication result authenticating the entity based on at least the unique identifier associated with the wireless device, the location of the wireless device, and data regarding the location of the electronic device; and

enabling the entity to use the application requiring secure access.

12. The method of claim 11 , wherein the authentication result is generated by at least comparing the location of the electronic device and the location of the wireless device.

13. The method of claim 11 , wherein the unique identifier is a mobile directory number.

14. The method of claim 11 , wherein the data regarding the location of the electronic device comprises an IP address of the electronic device.

15. The method of claim 11 , wherein the electronic device is a base station.

16. The method of claim 11 , wherein the application is on the electronic device.

17. The method of claim 11 , wherein the wireless device is a mobile phone.

18. The method of claim 11 , wherein the application is present on the electronic device.

19. The method of claim 11 , wherein communication with the wireless device is encrypted.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2016
From: FINSPHERE CORPORATION
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 037973/0191 →
Continuity (39)
Continuation 12343015 · Dec 23, 2008
Continuation In Part 14867382 · Sep 28, 2015
Continuation 14457740 · Aug 12, 2014
Continuation 12992064
Continuation 14922727
Continuation In Part 14054047 · Oct 15, 2013
Continuation 13303809 · Nov 23, 2011
Continuation 12332878 · Dec 11, 2008
Continuation 14922727
Continuation In Part 14196861 · Mar 4, 2014
Continuation 11933803 · Nov 1, 2007
Continuation 14922727
Continuation In Part 13030759 · Feb 18, 2011
Continuation In Part 14922727
Continuation In Part 13030794 · Feb 18, 2011
Continuation In Part 14922727
Continuation In Part 13382900
Continuation In Part 14922727
Continuation In Part 13387991
Continuation In Part 14922727
Continuation In Part 13752271 · Jan 28, 2013
Continuation In Part 14922727
Continuation In Part 13903663 · May 28, 2013
Provisional Application 61027892 · Feb 12, 2008
Provisional Application 61053152 · May 14, 2008
Provisional Application 61058621 · Jun 4, 2008
Provisional Application 61027892 · Feb 12, 2008
Provisional Application 60979663 · Oct 12, 2007
Provisional Application 60909718 · Apr 3, 2007
Provisional Application 60895144 · Mar 16, 2007
Provisional Application 61305830 · Feb 18, 2010
Provisional Application 61306369 · Feb 19, 2010
Provisional Application 61223671 · Jul 7, 2009
Provisional Application 61223677 · Jul 7, 2009
Provisional Application 61230628 · Jul 31, 2009
Provisional Application 61591232 · Jan 26, 2012
Provisional Application 61659934 · Jun 14, 2012
Provisional Application 61652173 · May 26, 2012
Related Publication 20160227405A1 · Aug 4, 2016