-
公开(公告)号:US20210211876A1
公开(公告)日:2021-07-08
申请号:US17141643
申请日:2021-01-05
Applicant: ZUMIGO, INC.
Inventor: Chirag C. BAKSHI , Harish MANEPALLI , Venkatarama PARIMI , Desmond Kwok-Hon Chan
IPC: H04W12/06 , H04L29/06 , H04W12/033
Abstract: An authentication server enrolls a user's mobile device as a trusted device with a vendor software after verifying the network ID of the user's mobile device. The authentication server associates the network ID in an authentication entry with authentication information such as a push notification token and cryptographic key. Later, when the user attempts to log in to the vendor software, the authentication server may attempt to cryptographically authenticate the user. Otherwise, the authentication server may use the push notification token to transmit an OTP to the user's mobile device as a push notification.
-
2.
公开(公告)号:US20200245142A1
公开(公告)日:2020-07-30
申请号:US16262811
申请日:2019-01-30
Applicant: ZUMIGO, INC.
Inventor: Harish MANEPALLI , Chirag C. BAKSHI , Venkatarama PARIMI , Lyndi Rebecca LONG
Abstract: The device history of a mobile telephone number, or “mobile number,” is tracked to facilitate detection of risk indicators associated with the mobile number by an application server or other authentication entity. When access to a secure account is requested from a mobile device that is activated with the mobile number, certain risk indicators can be determined based on the tracked device history of the mobile number. A history is tracked of cellular devices that have been previously activated with a particular mobile number and when each such cellular device was activated with the mobile number. When a user performs an activity with a mobile device that requires authentication based on a mobile number of the mobile device, such as an online access, risk indicators associated with the mobile number can be detected and acted on accordingly.
-
3.
公开(公告)号:US20200244656A1
公开(公告)日:2020-07-30
申请号:US16442323
申请日:2019-06-14
Applicant: ZUMIGO, INC.
Inventor: Harish MANEPALLI , Chirag C. BAKSHI , Venkatarama PARIMI , Lyndi Rebecca LONG
IPC: H04L29/06 , G06F16/953 , H04W12/06
Abstract: An authorization process employs a network ID as a possession factor for a secure account, such as a bank account or e-mail account, and determines one or more risk indicators associated with the possession factor. The authorization process is successfully completed when a risk score that is based on the risk indicators is less than a certain risk threshold. The risk indicators include a device history of the network ID and/or at least one attribute of a cellular account associated with the network ID. The device history identifies other mobile devices and/or SIM cards, if any, that have been previously activated with the network ID, while the one or more attributes can further indicate potentially fraudulent activity associated with the cellular account through which wireless services for the network ID are currently provided.
-
4.
公开(公告)号:US20230284015A1
公开(公告)日:2023-09-07
申请号:US18316166
申请日:2023-05-11
Applicant: Zumigo, Inc.
Inventor: Chirag C. BAKSHI , Harish MANEPALLI , Venkatarama PARIMI , Desmond Kwok-Hon Chan
IPC: H04W12/06 , H04L9/40 , H04W12/033
CPC classification number: H04W12/068 , H04L63/0435 , H04L63/0838 , H04W12/033
Abstract: An authentication server enrolls a user’s mobile device as a trusted device with a vendor software after verifying the network ID of the user’s mobile device. The authentication server associates the network ID in an authentication entry with authentication information such as a push notification token and cryptographic key. Later, when the user attempts to log in to the vendor software, the authentication server may attempt to cryptographically authenticate the user. Otherwise, the authentication server may use the push notification token to transmit an OTP to the user’s mobile device as a push notification.
-
公开(公告)号:US20230063852A1
公开(公告)日:2023-03-02
申请号:US17458078
申请日:2021-08-26
Applicant: Zumigo, Inc.
Inventor: Harish MANEPALLI , Chirag C. BAKSHI
Abstract: A mobile network based authentication system for authenticating a user's access to a restricted-access account includes an application server and an identification server. The application server is configured to authenticate the user's access to the restricted-access account by transmitting a one-time password to a mobile computing device of the user and confirming that the one-time password has been entered by the user. The identification server communicates with the application server after the application server receives a request from the user to access the restricted-access account and before the application transmits the one-time password to the mobile device, to verify that an attribute of the restricted-access account is linked to a network identification of the mobile computing device.
-
公开(公告)号:US20210176249A1
公开(公告)日:2021-06-10
申请号:US17107649
申请日:2020-11-30
Applicant: Zumigo, Inc.
Inventor: Chirag C. BAKSHI , Harish MANEPALLI , Venkatarama PARIMI
Abstract: A computer-implemented method of authenticating a user logged into a restricted-access account over a computer network, includes the steps of: receiving a request to authenticate the user over the computer network; verifying that authentication data of the user matches verification data that is acquired over the computer network and associated with a network identification of a mobile device that is linked to the restricted-access account of the user; verifying that a location of an IP address from which the user is accessing the restricted-access account matches a current location of the mobile device; and authenticating the user upon determining that the authentication data of the user matches the verification data and the location of the IP address matches the current location.
-
公开(公告)号:US20190139024A1
公开(公告)日:2019-05-09
申请号:US16168713
申请日:2018-10-23
Applicant: Zumigo, Inc.
Inventor: Chirag C. BAKSHI , Harish MANEPALLI , Venkatarama PARIMI
Abstract: A fraudulent online payment transaction involving a stolen account number is prevented via a multiple factor authentication of the transaction. When an online payment transaction is initiated from a computing device, a mobile device that is associated with the account is employed as a physical token, and the online payment transaction is authorized based on possession of the mobile device. Real-time information associated with the user initiating the online payment transaction and real-time information associated with the mobile device are employed to verify user identity and user location. User identity is verified by comparing the name associated with the online payment transaction with the name that is currently registered as the user name for a mobile device. User location is verified by comparing the location at which the online payment transaction is initiated with the current location detected for the mobile device.
-
公开(公告)号:US20240323692A1
公开(公告)日:2024-09-26
申请号:US18300276
申请日:2023-04-13
Applicant: Zumigo, Inc.
Inventor: Venkatarama S. PARIMI , Chirag C. BAKSHI , Saravanan JAGADHESON
IPC: H04W12/108 , H04W12/06 , H04W12/40 , H04W12/69
CPC classification number: H04W12/108 , H04W12/06 , H04W12/40 , H04W12/69
Abstract: A method of authenticating a customer to allow the customer to log in to an account, includes the steps of: in response to a request to authenticate the customer based on a first mobile identifier (ID), generating a code that encodes a uniform resource locator (URL), and then transmitting the generated code to a computer that is managing access to the account; examining a network packet routed according to the URL and determining a second mobile ID using the network packet; comparing the first mobile ID to the second mobile ID; and based on a determination that the first mobile ID matches the second mobile ID, determining that the customer is authenticated, and then transmitting a message to the computer that the customer is permitted to log in to the account.
-
9.
公开(公告)号:US20240292218A1
公开(公告)日:2024-08-29
申请号:US18657686
申请日:2024-05-07
Applicant: Zumigo, Inc.
Inventor: Harish MANEPALLI , Chirag C. BAKSHI
CPC classification number: H04W12/068 , H04L63/0838 , H04L63/0884 , H04W48/08 , G06Q20/3221 , G06Q40/03
Abstract: A mobile network based authentication system for authenticating a user's access to a restricted-access account includes an application server and an identification server. The application server is configured to authenticate the user's access to the restricted-access account by transmitting a one-time password to a mobile computing device of the user and confirming that the one-time password has been entered by the user. The identification server communicates with the application server after the application server receives a request from the user to access the restricted-access account and before the application transmits the one-time password to the mobile device, to verify that an attribute of the restricted-access account is linked to a network identification of the mobile computing device.
-
10.
公开(公告)号:US20200167862A1
公开(公告)日:2020-05-28
申请号:US16201638
申请日:2018-11-27
Applicant: ZUMIGO, INC.
Inventor: Harish MANEPALLI , Chirag C. BAKSHI
Abstract: Identity matching via a mobile device is facilitated when a user attempts to access a restricted-access account with the mobile device. The identity of the user is verified based on the mobile number of the mobile device, personal identifying information provided by the user, user information for the mobile account associated with the mobile number, and user information from a credit bureau. The user information for the mobile account can be retrieved from the mobile carrier that provides the mobile account, and the user information from the credit bureau can be determined based on the user information for the mobile account. Thus, an authorization entity can verify that the identity of the user attempting to access the restricted-access account matches the identity of the holder of the account, even when the holder of the account is not the primary name associated with the mobile account for the mobile device.
-
-
-
-
-
-
-
-
-