US2013346313A1PendingUtilityA1

Methods and systems for user authentication

Assignee: MASTERCARD INTERNATIONAL INCPriority: Aug 14, 2009Filed: Aug 26, 2013Published: Dec 26, 2013
Est. expiryAug 14, 2029(~3.1 yrs left)· nominal 20-yr term from priority
G06Q 20/40H04L 9/3271H04L 63/08H04L 63/12G06Q 20/4014G06F 2221/2153G06F 2221/2151G06Q 40/02H04L 2209/56G06F 2221/2101G06Q 20/10H04L 2463/102G06F 21/31G07F 19/00
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and systems for authenticating a user are provided. In an embodiment, an authentication service device receives a request to authenticate a user, and transmits a transaction history database query based on business rules concerning transactions conducted by the user. The response to the query includes a plurality of transactions, and the authentication service device generates a user authentication form that includes a set of transactions, and at least two of the transactions include a redacted transaction detail field. The user authentication form is transmitted to a user device, and user responses to the redacted transaction detail fields are received. The user is authenticated based on a monetary amount response that falls within a predetermined variance threshold, at least one positive information response, and on the user satisfying a permissible number of retry(s) requirement.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 receiving, by an authentication service device from a service provider device, a request to authenticate a user, the request comprising user identification data and financial account data associated with the user;   transmitting, by the authentication service device based on the financial account data, a transaction history database query to a transaction history database, the query based on business rules concerning transactions conducted by the user and stored in the transaction history database, wherein each transaction comprises a plurality of transaction detail fields;   receiving a response comprising a plurality of transactions that satisfy the query;   generating, by the authentication service device, a user authentication form comprising a set of transactions of the plurality of transactions, wherein at least two of the set of transactions include at least one redacted transaction detail field, and wherein the user authentication form is generated based on authentication rules provided by the service provider device that specify a minimum number of transactions requirement, at least one transaction amount detail field redaction requirement, and a permissible number of user retry(s) requirement;   transmitting the user authentication form including the redacted transaction detail fields to a user device;   receiving, by the authentication service device, user responses to the redacted transaction detail fields; and   authenticating, by the authentication service device, the user based on a monetary amount response within a predetermined variance threshold, on at least one positive information response, and on the user satisfying the permissible number of retry(s) requirement.   
     
     
         2 . The method of  claim 1 , further comprising transmitting, by the authentication service device to the service provider device, the authentication result. 
     
     
         3 . The method of  claim 1 , further comprising:
 receiving from a service provider device, updated authentication rules; and   replacing, by the authentication device, the authentication rules with the updated authentication rules prior to generating a user identification form.   
     
     
         4 . The method of  claim 1 , wherein the business rules for creating the transaction history database query includes requiring a set of transactions to be within a predetermined date range. 
     
     
         5 . The method of  claim 4 , wherein the predetermined date range is specified by a user. 
     
     
         6 . The method of  claim 1 , wherein the business rules for creating the transaction history database query includes requiring at least one transaction to have been conducted at particular type of merchant. 
     
     
         7 . The method of  claim 1 , wherein the user authentication form further comprises at least one transaction that includes a redacted bogus transaction detail field. 
     
     
         8 . The method of  claim 1 , wherein the transaction history database includes a plurality of transactions conducted by a plurality of users. 
     
     
         9 . The method of  claim 1 , wherein authenticating further comprises determining that the amount of correct information responses of the user satisfies a predetermined authentication threshold. 
     
     
         10 . An authentication apparatus, comprising:
 a processor; and   a non-transitory storage device operably coupled to the processor and storing instructions configured to cause the processor to:
 receive a request to authenticate a user from a service provider device, the request comprising user identification data and financial account data associated with the user; 
 transmit a transaction history database query to a transaction history database, the query based on business rules concerning transactions conducted by the user and stored in the transaction history database, wherein each transaction comprises a plurality of transaction detail fields; 
 receive a response comprising a plurality of transactions that satisfy the query; 
 generate a user authentication form comprising a set of transactions of the plurality of transactions, wherein at least two of the set of transactions include at least one redacted transaction detail field, and wherein the user authentication form is generated based on authentication rules provided by the service provider device that specify a minimum number of transactions requirement, at least one transaction amount detail field redaction requirement, and a permissible number of user retry(s) requirement; 
 transmit the user authentication form including the redacted transaction detail fields to a user device; 
 receive user responses to the redacted transaction detail fields; and 
 authenticate the user based on a monetary amount response within a predetermined variance threshold, on at least one positive information response, and on the user satisfying the permissible number of retry(s) requirement. 
   
     
     
         11 . The apparatus of  claim 10 , wherein the storage device further stores at least one of a transaction history database and an authentication rules database. 
     
     
         12 . The apparatus of  claim 10 , further comprising a communication device operatively coupled to the processor and adapted to communicate with at least one of a point of sale device, a user device, and a service provider device. 
     
     
         13 . A non-transitory computer-readable medium storing instructions configured to cause a processor to:
 receive a request to authenticate a user from a service provider device, the request comprising user identification data and financial account data associated with the user;   transmit a transaction history database query to a transaction history database, the query based on business rules concerning transactions conducted by the user and stored in the transaction history database, wherein each transaction comprises a plurality of transaction detail fields;   receive a response comprising a plurality of transactions that satisfy the query;   generate a user authentication form comprising a set of transactions of the plurality of transactions, wherein at least two of the set of transactions include at least one redacted transaction detail field, and wherein the user authentication form is generated based on authentication rules provided by the service provider device that specify a minimum number of transactions requirement, at least one transaction amount detail field redaction requirement, and a permissible number of user retry(s) requirement; transmit the user authentication form including the redacted transaction detail fields to a user device;   receive user responses to the redacted transaction detail fields; and   authenticate the user based on a monetary amount response within a predetermined variance threshold, on at least one positive information response, and on the user satisfying the permissible number of retry(s) requirement.   
     
     
         14 . The non-transitory computer-readable medium of  claim 13 , further comprising instructions configured to cause the processor to transmit to the authentication result to a service provider device. 
     
     
         15 . The non-transitory computer-readable medium of  claim 13 , further comprising instructions configured to cause the processor to:
 receive updated authentication rules; and   replace the authentication rules with the updated authentication rules prior to generating a user identification form.   
     
     
         16 . The non-transitory computer-readable medium of  claim 13 , wherein the business rules for creating the transaction history database query comprise rules configured to cause the processor to transmit a transaction history database query requiring the set of transactions to be within a predetermined date range. 
     
     
         17 . The non-transitory computer-readable medium of  claim 13 , wherein the business rules for creating the transaction history database query comprise rules configured to cause the processor to transmit a transaction history database query requiring at least one transaction to have been conducted at particular type of merchant. 
     
     
         18 . The non-transitory computer-readable medium of  claim 13 , wherein the authentication rules for generating the user authentication form comprise rules configured to cause the processor to include at least one transaction that includes a redacted bogus transaction detail field. 
     
     
         19 . The non-transitory computer-readable medium of  claim 13 , wherein the instructions for authenticating the user further comprises instructions configured to cause the processor to determine that the amount of correct information responses of the user satisfies a predetermined authentication threshold.

Join the waitlist — get patent alerts

Track US2013346313A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.