US2016285851A1PendingUtilityA1

Systems and methods for authenticating a user and device

Assignee: PAYPAL INCPriority: Jun 14, 2012Filed: Jun 10, 2016Published: Sep 29, 2016
Est. expiryJun 14, 2032(~5.9 yrs left)· nominal 20-yr term from priority
G06F 21/33H04L 63/08H04L 63/083H04L 63/0861H04L 63/0876H04L 63/105G06Q 20/4016G06Q 20/4014G06F 21/316H04L 2463/082H04L 63/0853
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for authenticating a user request for authentication are provided. An authentication device that may be part of such a system includes a network interface component coupled to a network and configured to receive at least one data packet having authentication information including at least a username of a user and user credentials. The device also includes a memory coupled to the network interface component and configured to store the received authentication information, one or more instructions for authenticating the user, and account information of the user. The device further includes one or more processors configured to analyze the received information, calculate a score based on the received information, determine a threshold, compare the calculated score with the determined threshold, and authenticate the user and a device from which the data packet is received if the calculated score is greater than or equal to the determined threshold.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system comprising:
 a non-transitory memory; and   one or more hardware processors coupled to the non-transitory memory and configured to read instructions from the non-transitory memory to cause the system to perform operations comprising:
 determining first authentication information received by a computing device, 
   wherein the first authentication information is associated with a user account;
 determining additional information is required to provide the computing device with access to the user account based at least on the first authentication information received, wherein the system is configured to provide the computing device with the access to the user account based at least on the first authentication information received; 
 receiving second authentication information by the computing device based on the additional information required to provide the computing device with the access to the user account; 
 comparing the additional information required with the second authentication information received; and 
 providing the computing device with access to the user account based at least on the comparison of the additional information required with the second authentication information received. 
   
     
     
         2 . The system of  claim 1 , wherein:
 the first authentication information received comprises biometric information received by the computing device at a first time;   the additional information required is determined based at least on the biometric information received at the first time; and   the system is configured to provide the computing device with the access to the user account based at least on the biometric information received at a second time different than the first time.   
     
     
         3 . The system of  claim 1 , wherein:
 the first authentication information received comprises biometric information received by the computing device on one or more prior occasions; and   the additional information required is determined based at least on a number of the one or more prior occasions.   
     
     
         4 . The system of  claim 1 , wherein the operations further comprise providing the computing device with a uniform resource locator (URL) associated with a web page configured to receive the additional information. 
     
     
         5 . The system of  claim 4 , wherein the second authentication information received comprises a cookie and/or a flash object associated with the web page. 
     
     
         6 . The system of  claim 1 , wherein the second authentication information received comprises a device identification of the computing device. 
     
     
         7 . The system of  claim 1 , wherein the second authentication information received comprises a PIN or password. 
     
     
         8 . A method comprising:
 determining first authentication information received by a computing device, wherein the first authentication information is associated with a user account;   determining additional information is required to provide the computing device with access to the user account based at least on the first authentication information received;   providing the computing device with the access to the user account based at least on the first authentication information received;   receiving second authentication information by the computing device based on the additional information required to provide the computing device with the access to the user account;   comparing the additional information required with the second authentication information received; and   providing the computing device with access to the user account based at least on the comparison of the additional information required with the second authentication information received.   
     
     
         9 . The method of  claim 8 , wherein:
 the first authentication information received comprises biometric information received by the computing device at a first time;   the additional information required is determined based at least on the biometric information received at the first time; and   the method further comprises providing the computing device with the access to the user account based at least on the biometric information received at a second time different than the first time.   
     
     
         10 . The method of  claim 8 , wherein:
 the first authentication information received comprises biometric information received by the computing device on one or more prior occasions; and   the additional information required is determined based at least on a number of the one or more prior occasions.   
     
     
         11 . The method of  claim 8 , further comprising providing the computing device with a uniform resource locator (URL) associated with a web page configured to receive the additional information. 
     
     
         12 . The method of  claim 11 , wherein the second authentication information received comprises a cookie and/or a flash object associated with the web page. 
     
     
         13 . The method of  claim 8 , wherein the second authentication information received comprises a device identification of the computing device. 
     
     
         14 . The method of  claim 8 , wherein the second authentication information received comprises a PIN or password. 
     
     
         15 . A non-transitory machine-readable medium having stored thereon machine-readable instructions executable to cause a machine to perform operations comprising:
 determining first authentication information received by a computing device, wherein the first authentication information is associated with a user account;   determining additional information is required to provide the computing device with access to the user account based at least on the first authentication information received, wherein the machine is configured to provide the computing device with the access to the user account based at least on the first authentication information received;   receiving second authentication information by the computing device based on the additional information required to provide the computing device with the access to the user account;   comparing the additional information required with the second authentication information received; and   providing the computing device with access to the user account based at least on the comparison of the additional information required with the second authentication information received.   
     
     
         16 . The non-transitory machine-readable medium of  claim 15 , wherein:
 the first authentication information received comprises biometric information received by the computing device at a first time;   the additional information required is determined based at least on the biometric information received at the first time; and   the machine is configured to provide the computing device with the access to the user account based at least on the biometric information received at a second time different than the first time.   
     
     
         17 . The non-transitory machine-readable medium of  claim 15 , wherein:
 the first authentication information received comprises biometric information received by the computing device on one or more prior occasions; and   the additional information required is determined based at least on a number of the one or more prior occasions.   
     
     
         18 . The non-transitory machine-readable medium of  claim 15 , wherein the operations further comprise providing the computing device with a uniform resource locator (URL) associated with a web page configured to receive the additional information. 
     
     
         19 . The non-transitory machine-readable medium of  claim 18 , wherein the second authentication information received comprises a cookie and/or a flash object associated with the web page. 
     
     
         20 . The non-transitory machine-readable medium of  claim 15 , wherein the second authentication information received comprises a device identification of the computing device.

Join the waitlist — get patent alerts

Track US2016285851A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.