IP Library Granted Patent US 11,496,452
Granted Patent B2
US 11,496,452 · App. 16/046,370 · Granted Nov 8, 2022

Non-repeatable challenge-response authentication

Inventors: Yehoshua Zvi Licht (Alpharetta, GA); Joseph Arnold White (Encinitas, CA)
Assignee: NCR Corporation
H04L63/08H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,496,452
App. No.
16/046,370
Granted
Nov 8, 2022
Kind
B2
Abstract

User data is aggregated across a plurality of electronic communication channels and domains. An online system initially authenticates a user for access to the online system over a network. The online system provides a user identifier for the user to an authentication service. The authentication service generates a non-repeatable challenge from the aggregated user data for the user identifier and provides the non-repeatable challenge to the online system. The online system provides the challenge to the user and receives a response from the user. The online system provides the response to the authentication service and the authentication sends a success or failure back to the online system based on the response to the challenge, and based on the success or failure the online system makes a final determination for authenticating the user for accessing to the online system.

Claims (7)

1. A system, comprising:

a hardware processor;

an authentication service configured to: (i) execute on the hardware processor; (ii) generate non-repeatable user-specific and temporal-based challenge-response questionnaires as requested by an authentication system for users based on recent electronically tracked activities for the users, wherein the users are already authenticated for a first factor authentication from an authentication mechanism of an online system, wherein the authentication mechanism is interfaced to the authentication system to request a second factor authentication on the user, and wherein the recent electronically tracked activities are gathered from a plurality of different communication channels associated with the user's recent electronically tracked activities, and wherein at least one of the different communication channels includes a social media communication channel, iii) provide indications to the authentication system as to whether proposed responses by the users were correct or incorrect, and providing the indications by the authentication system to the online system as second factor authentication results for the users, wherein when an indication for a given user is incorrect, asking the given user whether the given user would like to try another set of challenge-response questionnaire and when selected by the given user iterate back to (ii) for a different non-repeatable user-specific and temporal-based challenge-response questionnaire and check a different proposed response by the given user and continue the iterations for a preset number of iterations unless the given user correctly answers a given non-repeatable user-specific and temporal-based challenge response questionnaire during a given iteration, and wherein the preset number of iterations is defined in an authentication policy set by the online system, wherein each of the user-specific and temporal-based challenge-response questionnaires comprises questions based on recent in time transaction activity associated with each user.

2. The system of claim 1 , wherein the authentication service is configured to: iv) perform a second factor authentication for the authentication system, wherein the authentication system performs a first factor authentication against the users.

3. The system of claim 1 , the authentication is configured to one of:

interface as a Software as a Service (SaaS) with the authentication system,

and integrate within a processing environment of an online system associated with the authentication system.

Assignments (5)
CHANGE OF NAME Recorded Dec 7, 2023
From: NCR CORPORATION
To: NCR VOYIX CORPORATION
Reel/Frame 065820/0704 →
RELEASE OF PATENT SECURITY INTEREST Recorded Oct 25, 2023
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: NCR VOYIX CORPORATION
Reel/Frame 065346/0531 →
SECURITY INTEREST Recorded Oct 25, 2023
From: NCR VOYIX CORPORATION
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 065346/0168 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS SECTION TO REMOVE PATENT APPLICATION: 15000000 PREVIOUSLY RECORDED AT REEL: 050874 FRAME: 0063. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Apr 12, 2021
From: NCR CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 057047/0161 →
SECURITY INTEREST Recorded Oct 29, 2019
From: NCR CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 050874/0063 →
Continuity (2)
Division 15055564 · Feb 27, 2016
Related Publication 20180337909A1 · Nov 22, 2018