Patent Issued for System And Methods To Establish User Profile Using Multiple Channels (USPTO 10,924,479)
2021 FEB 26 (NewsRx) -- By a
The patent’s inventors are Jain,
This patent was filed on
From the background information supplied by the inventors, news correspondents obtained the following quote: “Consumers access services and information hosted by a network via a remote device. For instance, consumers may access health care related websites and internet-based applications to review numerous types of health-related information and services. For example, a consumer may log into a health care organization website or application in order to view available products or utilize one of many services offered by the health care organization. Increasingly, consumers not only access these websites and applications with personal computers, but also with smart phones and other electronic devices. In order to provide data security for sensitive information, websites and applications must employ a secure authentication system that can accommodate the full range of devices. Further, increased data security is generally commensurate with inconvenience for consumers, and increased data security may not be necessary for all consumers.”
Supplementing the background information on this patent, NewsRx reporters also obtained the inventors’ summary information for this patent: “In certain embodiments, a method of establishing a user profile using multiple channels, such as device, application and authentication channels is provided. Embodiments allow compatibility of the user profile across several authentication systems. The user profile is created upon registration and is updated with attributes after authenticating and authorizing the user according to a pre-defined assurance level. The user profile contains attributes pertaining to the user and user device, including user device, application and authentication attributes. These attributes can be analyzed by authentication systems to optimize data security.
“Embodiments of the disclosure provide a method for creating a user profile for authenticating a user to access information and services protected by an authentication system. The method includes: performing an authentication of a user attempting access to the information and services from a user device, wherein the information and services are protected by the authentication system; determining whether the user is a new user never before having accessed the information and services protected by the authentication system; collecting attributes uniquely identifying the user and compiling those as part of the user profile; and storing the user profile in a database associated with the authentication system.
“Further embodiments of the disclosure provide a method for authenticating a user to access information and services protected by an authentication system. The method includes: performing an authentication of a user device accessing the information and services protected by the authentication system; capturing device, application and user authentication attributes during the authentication; comparing the captured device, application and user authentication attributes against previously obtained device, application and user authentication attributes stored as part of a user profile; calculating a risk score based on the comparison of the captured device, application and user authentication attributes against the previously obtained device, application and user authentication attributes; and determining whether to grant access to the information and services based on the risk score.
“Yet other embodiments of the disclosure provide a non-transitory computer readable storage device for authenticating a user to access information and services protected by an authentication system. The non-transitory computer readable storage device having computer executable instructions for performing the steps of: performing an authentication of a user device accessing the information and services protected by the authentication system; capturing device, application and user authentication attributes during the authentication; comparing the captured device, application and user authentication attributes against previously obtained device, application and user authentication attributes stored as part of a user profile; calculating a risk score based on the comparison of the captured device, application and user authentication attributes against the previously obtained device, application and user authentication attributes; and determining whether to grant access to the information and services based on the risk score.”
The claims supplied by the inventors are:
“The invention claimed is:
“1. A method for authenticating a user to access information and services protected by an authentication system, the method comprising: receiving a request from a user device to access the information and services protected by the authentication system; capturing device, application and user authentication attributes during the authentication; comparing the captured device, application and user authentication attributes against previously obtained device, application and user authentication attributes stored in a database associated with the user device and stored as part of a user profile containing the previously obtained device, application and user attributes, wherein the user profile is stored in association with one or more user device profiles, one or more user application profiles, and one or more user authentication profiles, and wherein the one or more user device profiles uniquely identifies at least one device associated with the user; calculating a risk score based on the comparison of the captured device, application and user authentication attributes against the previously obtained device, application and user authentication attributes; and determining whether to grant the user device access to the information and services based on the risk score, wherein the determining whether to grant access to the information and services based on the risk score comprises: comparing the risk score to one or more of a first predetermined threshold risk level and a second predetermined threshold risk level, wherein the first predetermined threshold risk level is set such that when the risk score meets or exceeds the first predetermined threshold risk level, authentication of the user to access the information and services is achieved with high assurance, and the second predetermined threshold risk level is set such that when the risk score meets or exceeds the second predetermined threshold risk level but not the first predetermined threshold risk level, authentication of the user to access the information and services is achieved with low assurance; granting access to the information and services in response to the risk score meeting or exceeding either the first predetermined threshold risk level or the second predetermined risk level, wherein when the risk score meets or exceeds the first predetermined threshold risk level, the method further comprises: updating the user profile with the captured device, application and user authentication attributes in response to the authentication of the user to access the information and services being achieved with high assurance, and wherein when the risk score meets or exceeds the second predetermined threshold risk level but not the first predetermined risk threshold level, the method further comprises: comparing device attributes of the captured device, application and user authentication attributes against device attributes of the previously obtained device, application and user authentication attributes; in response to common device attributes between the captured device, application and user authentication attributes and the previously obtained device, application and user authentication attributes, upgrading from the low assurance of the authentication to an authentication with high assurance and updating the user profile with the captured device, application and user authentication attributes; and in response to no common device attributes between the captured device, application and user authentication attributes and the previously obtained device, application and user authentication attributes, the authentication remains at low assurance and the user profile is not updated with the captured device, application and user authentication attributes.
“2. The method of claim 1, further comprising obtaining identification information of the user from the captured device, application and user authentication attributes.
“3. The method of claim 2, further comprising accessing contents of the user profile stored in a database using the identification information of the user.
“4. The method of claim 2, wherein obtaining the identification information of the user comprises obtaining a handle of the user profile based on the identification information of the user.
“5. The method of claim 4, further comprising accessing the contents of the user profile stored in a database using the handle of the user profile.
“6. The method of claim 1, wherein the user profile contains multiple channels including the one or more user device profiles, one or more user authentication profiles, and one or more user application profiles.
“7. The method of claim 1, wherein the user profile is interchangeable across different authentication systems.
“8. The method of claim 7, wherein the user authentication attributes are accessible regardless of the authentication system used.
“9. The method of claim 1, wherein the user profile is accessible by a plurality of user devices associated with the user.
“10. The method of claim 1, wherein the device, application and user authentication attributes pertaining to the user device comprise a device type, a device hardware and software configuration, an access technology used to access the information and services, and device hygiene data.
“11. A method for authenticating a user to access information and services protected by an authentication system, the method comprising: receiving a request from a user device to access the information and services protected by the authentication system; capturing device, application and user authentication attributes during the authentication; comparing the captured device, application and user authentication attributes against previously obtained device, application and user authentication attributes stored in a database associated with the user device and stored as part of a user profile containing the previously obtained device, application and user attributes, wherein the user profile is stored in association with one or more user device profiles, one or more user application profiles, and one or more user authentication profiles, and wherein the one or more user device profiles uniquely identifies at least one device associated with the user; calculating a risk score based on the comparison of the captured device, application and user authentication attributes against the previously obtained device, application and user authentication attributes; and determining whether to grant the user device access to the information and services based on the risk score, wherein the determining whether to grant access to the information and services based on the risk score comprises: comparing the risk score to one or more of a first predetermined threshold risk level and a second predetermined threshold risk level, wherein the first predetermined threshold risk level is set such that when the risk score meets or exceeds the first predetermined threshold risk level, authentication of the user to access the information and services is achieved with high assurance, and the second predetermined threshold risk level is set such that when the risk score meets or exceeds the second predetermined threshold risk level but not the first predetermined threshold risk level, authentication of the user to access the information and services is achieved with low assurance; granting access to the information and services in response to the risk score meeting or exceeding the second predetermined threshold risk level and not the first predetermined threshold risk level; comparing device attributes of the captured device, application and user authentication attributes against device attributes of the previously obtained device, application and user authentication attributes; in response to common device attributes between the captured device, application and user authentication attributes and the previously obtained device, application and user authentication attributes, upgrading from the low assurance of the authentication to an authentication with high assurance and updating the user profile with the captured device, application and user authentication attributes; and in response to no common device attributes between the captured device, application and user authentication attributes and the previously obtained device, application and user authentication attributes, the authentication remains at low assurance and the user profile is not updated with the captured device, application and user authentication attributes.
“12. The method of claim 11, wherein the device, application and user authentication attributes pertaining to the user device comprise a device type, a device hardware and software configuration, an access technology used to access the information and services, and device hygiene data.
“13. A non-transitory computer readable storage device for authenticating a user to access information and services protected by an authentication system, the non-transitory computer readable storage device having computer executable instructions for performing the steps of: receiving a request from a user device to access the information and services protected by the authentication system; capturing device, application and user authentication attributes during the authentication; comparing the captured device, application and user authentication attributes against previously obtained device, application and user authentication attributes stored in a database associated with the user device and stored as part of a user profile containing the previously obtained device, application and user attributes, wherein the user profile is stored in association with one or more user device profiles, one or more user application profiles, and one or more user authentication profiles, and wherein the one or more device profiles uniquely identifies at least one device associated with the user; calculating a risk score based on the comparison of the captured device, application and user authentication attributes against the previously obtained device, application and user authentication attributes; and determining whether to grant the user device access to the information and services based on the risk score, wherein the determining whether to grant access to the information and services based on the risk score comprises: comparing the risk score to one or more of a first predetermined threshold risk level and a second predetermined threshold risk level, wherein the first predetermined threshold risk level is set such that when the risk score meets or exceeds the first predetermined threshold risk level, authentication of the user to access the information and services is achieved with high assurance, and the second predetermined threshold risk level is set such that when the risk score meets or exceeds the second predetermined threshold risk level but not the first predetermined threshold risk level, authentication of the user to access the information and services is achieved with low assurance; granting access to the information and services in response to the risk score meeting or exceeding either the first predetermined threshold risk level or the second predetermined risk level, wherein when the risk score meets or exceeds the first predetermined threshold risk level, the method further comprises: updating the user profile with the captured device, application and user authentication attributes in response to the authentication of the user to access the information and services being achieved with high assurance, and wherein when the risk score meets or exceeds the second predetermined threshold risk level but not the first predetermined risk threshold level, the method further comprises: comparing device attributes of the captured device, application and user authentication attributes against device attributes of the previously obtained device, application and user authentication attributes; in response to common device attributes between the captured device, application and user authentication attributes and the previously obtained device, application and user authentication attributes, upgrading from the low assurance of the authentication to an authentication with high assurance and updating the user profile with the captured device, application and user authentication attributes; and in response to no common device attributes between the captured device, application and user authentication attributes and the previously obtained device, application and user authentication attributes, the authentication remains at low assurance and the user profile is not updated with the captured device, application and user authentication attributes.
“14. A non-transitory computer readable storage device for authenticating a user to access information and services protected by an authentication system, the non-transitory computer readable storage device having computer executable instructions for performing the steps of: receiving a request from a user device to access the information and services protected by the authentication system; capturing device, application and user authentication attributes during the authentication; comparing the captured device, application and user authentication attributes against previously obtained device, application and user authentication attributes stored in a database associated with the user device and stored as part of a user profile containing the previously obtained device, application and user attributes, wherein the user profile is stored in association with one or more user device profiles, one or more user application profiles, and one or more user authentication profiles, and wherein the one or more device profiles uniquely identifies at least one device associated with the user; calculating a risk score based on the comparison of the captured device, application and user authentication attributes against the previously obtained device, application and user authentication attributes; and determining whether to grant the user device access to the information and services based on the risk score, wherein the determining whether to grant access to the information and services based on the risk score comprises: comparing the risk score to one or more of a first predetermined threshold risk level and a second predetermined threshold risk level, wherein the first predetermined threshold risk level is set such that when the risk score meets or exceeds the first predetermined threshold risk level, authentication of the user to access the information and services is achieved with high assurance, and the second predetermined threshold risk level is set such that when the risk score meets or exceeds the second predetermined threshold risk level but not the first predetermined threshold risk level, authentication of the user to access the information and services is achieved with low assurance; granting access to the information and services in response to the risk score meeting or exceeding the second predetermined threshold risk level and not the first predetermined threshold risk level; comparing device attributes of the captured device, application and user authentication attributes against device attributes of the previously obtained device, application and user authentication attributes; in response to common device attributes between the captured device, application and user authentication attributes and the previously obtained device, application and user authentication attributes, upgrading from the low assurance of the authentication to an authentication with high assurance and updating the user profile with the captured device, application and user authentication attributes; and in response to no common device attributes between the captured device, application and user authentication attributes and the previously obtained device, application and user authentication attributes, the authentication remains at low assurance and the user profile is not updated with the captured device, application and user authentication attributes.”
For the URL and additional information on this patent, see: Jain,
(Our reports deliver fact-based news of research and discoveries from around the world.)


Sens. Cardin, Stabenow Seek to Close Important Gaps in Kids' Dental Care
Changes in Flood Hazard Determinations
Advisor News
- How student loan debt impacts 401(k) balances
- The ‘sandwich generation’ faces compounded barriers to retirement savings
- Benefit Costs Squeeze Schools, Driving Cuts, Tax Hikes And Difficult Tradeoffs
- Why client insurance needs could change even if their life doesn’t
- Most Gen Z investors think less than a year ahead when making financial decisions
More Advisor NewsAnnuity News
- Oklahoma Insurance Dept. helps Oklahomans recover unclaimed life insurance benefits
- Bitcoin gains ground in retirement market with Equitable annuity option
- Best’s Special Report: First-Half 2026 Net Income in U.S. Life/Annuity Insurance Industry Dips Slightly
- The next phase of life insurance investing
- Ty J. Young Wealth Management Acquires Senior Insurance Services, Expanding Its Growing Annuity Firm: Ty J. Young Wealth Management
More Annuity NewsHealth/Employee Benefits News
Life Insurance News