Authenticating online users with distorted challenges based on transaction histories
Abstract
In one embodiment, a system includes one or more processors having memory coupled thereto. The memory stores instructions executable to cause the system to perform a method that includes generating a request based on 1) transaction information that is available to a user and a service provider and relating to one or more transactions by a user, and 2) at least one user-specified preference as to a type of the transaction information upon which the request is based, communicating the request to a device of the user, receiving a response to the request from the user device, and determining the authenticity of the user based on the response. The request can be in visually or audibly form, such as a Captcha.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system, comprising:
one or more processors; and memory, coupled to the one or more processors and having stored thereon instructions executable to cause the system to perform a method comprising: generating a request based on:
1) transaction information, available to a user and a service provider and relating to one or more transactions by the user; and
2) at least one user-specified preference as to a type of the transaction information upon which the request is based;
communicating the request to a device of the user; receiving a response to the request from the user device, and determining the authenticity of the user based on the response.
2 . The system of claim 1 , wherein the request communicated to the user in a visually or audibly altered form.
3 . The system of claim 1 , wherein the request is communicated to the user in the form of a Captcha.
4 . The system of claim 1 , wherein the method further comprises storing and retrieving transaction information of the user at a service provider based on identification data of the user.
5 . The system of claim 4 , wherein the service provider comprises a financial service provider.
6 . The system of claim 4 , wherein the identification data of the user comprises a name or a number.
7 . The system of claim 1 , wherein the method further comprises granting the user access to a user's account at a service provider based on the response.
8 . The system of claim 1 , wherein the one or more processors are in communication with at least one network, the at least one network comprising the internet, the Automated Clearing House (ACH) or the Electronic Payments Network (EPN).
9 . The system of claim 1 , wherein the method further comprises effecting a financial transaction with at least one third party on behalf of the user using the one or more processors and based on the determining of the authenticity of the user.
10 . The system of claim 9 , wherein the financial transaction is exclusively between the user and a service provider or involves a third party.
11 . A non-transitory machine-readable medium comprising a plurality of machine-readable instructions which when executed by one or more processors of a server are adapted to cause the server to perform a method comprising:
receiving data identifying a user; generating a request based on:
1) transaction information, available to the user and a service provider and relating to one or more transactions by the user; and
2) at least one user-specified preference as to a type of the transaction information upon which the request is based;
communicating the request to a device of the user; receiving a response to the request from the user device, and determining whether the user is authentic based on the response.
12 . The medium of claim 1 , wherein the request communicated to the user in a visually or audibly altered form.
13 . The medium of claim 11 , wherein the response comprises text data, voice data or both text data and voice data.
14 . The medium of claim 11 , wherein the method further comprises retrieving a lost or forgotten password or personal identification number (PIN) and transmitting it to the user's device.
15 . An apparatus for authenticating a user to a service provider, the apparatus comprising:
means for receiving user identification data sent by the user to the service provider; means for generating a request based on:
1) transaction information, known by the service provider and the user and relating to one or more transactions by the user; and
2) at least one user-specified preference as to a type of the transaction information upon which the request is based;
means for communicating the request to a device of the user; means for receiving a response to the request from the user device; and, means for determining whether the user is authentic based on the response.
16 . The apparatus of claim 15 , wherein the request is communicated to the user in a visually or audibly altered form.
17 . The apparatus of claim 15 , wherein at least one of the receiving means, generating means, communicating means and/or determining means comprises a data server, a personal computer, a tablet computer, a smart phone and/or a personal digital assistant.
18 . The apparatus of claim 15 , wherein the service provider is a financial service provider and further comprising means for effecting financial transactions between the user and the service provider using at least one network.
19 . The apparatus of claim 18 , further comprising means for effecting a financial transaction with a third party on behalf of the user over the at least one network.
20 . The apparatus of claim 19 , wherein the at least one network comprises the internet, the Automated Clearing House (ACH) or the Electronic Payments Network (EPN).Join the waitlist — get patent alerts
Track US2014316989A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.