IP Library Granted Patent US 11,095,633
Granted Patent B2
US 11,095,633 · App. 16/044,737 · Granted Aug 17, 2021

Non-repeatable challenge-response authentication

Inventors: Yehoshua Zvi Licht (Alpharetta, GA); Joseph Arnold White (Encinitas, CA)
Assignee: NCR Corporation
H04L63/08H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,095,633
App. No.
16/044,737
Granted
Aug 17, 2021
Kind
B2
Abstract

User data is aggregated across a plurality of electronic communication channels and domains. An online system initially authenticates a user for access to the online system over a network. The online system provides a user identifier for the user to an authentication service. The authentication service generates a non-repeatable challenge from the aggregated user data for the user identifier and provides the non-repeatable challenge to the online system. The online system provides the challenge to the user and receives a response from the user. The online system provides the response to the authentication service and the authentication sends a success or failure back to the online system based on the response to the challenge, and based on the success or failure the online system makes a final determination for authenticating the user for accessing to the online system.

Claims (19)

1. A method, comprising:

generating a user-specific and non-repeatable challenge and a response for a user who was already authenticated with a first factor authentication by an authentication mechanism of an online system and the user is being authenticated for a second factor authentication by an authentication system, wherein the authentication mechanism of the online system interfaced to the authentication system, wherein generating further includes obtaining the user-specific and non-repeatable challenge from a plurality of different communication channels associated with a history of user activity, and wherein at least one of the different communication channels includes a social media communication channel, wherein the user-specific and non-repeatable challenge is temporal based;

providing the user-specific and non-repeatable challenge to the authentication system;

receiving a proposed response from the authentication system;

sending an indication of success or failure to the authentication system based on comparison of the proposed response and the response, wherein the authentication system provides the success or the failure to the online system as a second-factor authentication result for the second factor authentication;

maintaining an identifier for user-specific and non-repeatable challenge, flagging the identifier as asked of the user, and ensuring the response is not stored or retained, wherein flagged identifiers ensure that each previously provided user-specific and non-repeatable challenge is only presented to the user one time and is never repeated; and

iterating back to the generating when the indication is the failure by generating a different user-specific and non-repeatable challenge and a different response for the user until the indication is a success for the second factor authentication or until a preset number of iterations have been processed where the indication remains as the failure, wherein the present number of iterations is defined by an authentication policy set by the online system.

2. The method of claim 1 , wherein generating further includes identifying a domain template linked to a user in response to user identifying information for the user supplied by the authentication system.

3. The method of claim 2 further comprising:

randomly selecting a question from the domain template; and

ensuring that the selected question has never been used before for the user during any authentication session with any authentication system.

4. The method of claim 3 further comprising, searching user behavioral aggregated data using the user identifying information and the selected question.

5. The method of claim 4 further comprising, populating variables identified in the domain template received as results from the searching.

6. The method of claim 5 , wherein providing further includes providing a populated domain template as the user-specific and non-repeatable challenge and retaining identification of the response as an expected response to the user-specific and non-repeatable challenge.

7. The method of claim 1 , wherein generating further includes generating the user-specific and non-repeatable challenge and the response based on a recent in time activity of the user, wherein the recent in time activity is a same day or within a few days of when the user requested authentication to the authentication system.

8. The method of claim 7 , wherein generating further includes identifying the recent in time activity as one of: a financial transaction made by the user, a venue visited by the user, a social post to a social media site made by the user, and a location visited by the user.

9. The method of claim 1 , wherein providing further includes providing the response embedded in the user-specific and non-repeatable challenge along with improper responses for user selection of one of: the response and one of the improper responses.

10. The method of claim 1 further comprising, dynamically adjusting the generating upon detection of new behavioral patterns with the user.

11. The method of claim 1 further comprising, maintaining a metric as to whether the indication was successful or unsuccessful and processing the metric with other metrics to adjust the generating.

Assignments (6)
CHANGE OF NAME Recorded Dec 7, 2023
From: NCR CORPORATION
To: NCR VOYIX CORPORATION
Reel/Frame 065820/0704 →
RELEASE OF PATENT SECURITY INTEREST Recorded Oct 25, 2023
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: NCR VOYIX CORPORATION
Reel/Frame 065346/0531 →
SECURITY INTEREST Recorded Oct 25, 2023
From: NCR VOYIX CORPORATION
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 065346/0168 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2021
From: LICHT, YEHOSHUA ZVI; WHITE, JOSEPH ARNOLD
To: NCR CORPORATION
Reel/Frame 056215/0382 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS SECTION TO REMOVE PATENT APPLICATION: 15000000 PREVIOUSLY RECORDED AT REEL: 050874 FRAME: 0063. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Apr 12, 2021
From: NCR CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 057047/0161 →
SECURITY INTEREST Recorded Oct 29, 2019
From: NCR CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 050874/0063 →
Continuity (2)
Division 15055564 · Feb 27, 2016
Related Publication 20180332022A1 · Nov 15, 2018