US2008034219A1PendingUtilityA1
Biometric Authentication for Remote Initiation of Actions and Services
Individually held — no corporate assignee on recordPriority: May 18, 2001Filed: Aug 29, 2007Published: Feb 7, 2008
Est. expiryMay 18, 2021(expired)· nominal 20-yr term from priority
Inventors:David M. T. Ting
H04L 63/1441H04L 63/0407H04L 63/0861H04L 2463/102H04L 63/1466H04L 63/20G06F 21/57G06F 21/32
53
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
In one aspect, the invention relates to generating a trusted communication channel with a client. An agent module is provided at the client along with a task set including one or more tasks. One or more client components needed to complete each of the tasks of the task set is determined, and it is further determined whether each of the needed client components is trustworthy. An equivalent component for components determined to be untrustworthy may be provided.
Claims
exact text as granted — not AI-modified1 .- 42 . (canceled)
43 . A method for authenticating a user on a client machine, the method comprising:
determining a task set for processing user authentication data at the client machine; determining a set of software components for executing the task set; determining if the components are trustworthy; providing a reference set of user authentication data to the client machine only if such software components are determined to be trustworthy and not providing the reference set of user authentication data otherwise; and comparing, on the client machine, the reference set of authentication data with a candidate set of authentication data.
44 . The method of claim 43 further comprising:
determining that one or more software components are not trustworthy; and transmitting to the client machine substitute software components having equivalent functionality as the software components determined not to be trustworthy.
45 . The method of claim 43 further comprising retrieving, on the client machine, the candidate set of authentication data using at least one of the software components determined to be trustworthy.
46 . The method of claim 45 wherein the candidate set of authentication data comprises biometric data.
47 . The method of claim 43 further comprising transmitting the candidate set of authentication data, to the client machine using the software components determined to be trustworthy.
48 . The method of claim 47 wherein the candidate set of authentication data comprises biometric data.
49 . The method of claim 48 further comprising:
comparing the candidate set of biometric data with the reference set of user authentication data to verify a user associated with the client machine; and determining if there is a sufficient match between the candidate set of biometric data and the reference set of biometric data and if so, transmitting an application program for execution on the client machine, otherwise not transmitting the application program.
50 . The method of claim 48 further comprising:
comparing the candidate set of biometric data with the reference set of user authentication data to authenticate a user associated with the client machine, and, if there is a sufficient match between the candidate set of biometric data and the reference set of biometric data, providing a new task set based at least in part on the authenticated user.
51 . The method of claim 50 further comprising:
determining an additional set of software components for executing the new task set; and determining if the additional set of software components are trustworthy.
52 . The method of claim 50 wherein the new task set includes a task of retrieving user credentials for the authenticated user, the method further comprising:
retrieving the reference set of user authentication data associated with an electronic vault associated with the authenticated user; and retrieving the user credentials from the electronic vault.
53 . The method of claim 43 further comprising retrieving the reference set of user authentication data from a template.
54 . A system for generating a trusted communication channel for receiving user authentication data, the system comprising:
a task set for processing user authentication data on a client device; a set of software components for executing the task set on the client device; an agent module configured to determine if the software components are trustworthy, and only if so, to retrieve to the client device a reference set of authentication data, the agent module not providing the reference set of user authentication data otherwise; and a comparator module for comparing the retrieved reference set of authorization data with a candidate set of authorization data.
55 . The system of claim 54 wherein the agent module is further configured to retrieve the candidate set of authentication data using at least one of the software components determined to be trustworthy.
56 . The system of claim 55 wherein the candidate set of authentication data comprises biometric data.
57 . The system of claim 54 further comprising a transceiver module configured to transmit the candidate set of authentication data using at least one of the software components determined to be trustworthy.
58 . The system of claim 57 wherein the candidate set of authentication data comprises biometric data.
59 . The system of claim 54 further comprising a transceiver module configured to receive a new task set, and wherein the agent module is further configured to determine an additional set of software components for executing the new task set and to determine if the additional set of software components are trustworthy.
60 . The system of claim 54 wherein the agent module is further configured to determine if one or more software components are not trustworthy and the system further comprising
a transceiver module configured to request and receive one or more trustworthy software components having equivalent functionality as the software components determined not to be trustworthy.
61 . A system for generating a trusted communication channel, the system comprising:
a client device comprising:
a task set for processing user authentication data; and
a set of software components for executing the task set;
a server in communication with the client device, the server having a reference set of authentication data; an agent module residing on the client device and configured to determine if the software components are trustworthy, and only if so, to retrieve to the client device the reference set of authentication data, the agent module not retrieving the reference set of authentication data otherwise; and a comparator module for comparing the retrieved reference set of authorization data with a candidate set of authorization data.
62 . The server of claim 61 wherein the reference set of authentication data comprises biometric data.
63 . The system of claim 61 wherein the agent module is further configured to determine if one or more software components are not trustworthy and the server further comprises:
a transceiver module configured to transmit the substitute software components having equivalent functionality as the software_components determined not to be trustworthy.
64 . The system of claim 61 wherein the agent module is further configured to retrieve the candidate set of authentication data using one or more software components determined to be trustworthy.
65 . The system of claim 64 wherein the candidate set of authentication data comprises biometric data.
66 . The system of claim 61 further comprising a transceiver module configured to transmit the candidate set of authentication data using one or more software components determined to be trustworthy.
67 . The system of claim 66 wherein the candidate set of authentication data comprises biometric data.
68 . The system of claim 63 wherein the transceiver module is further configured to allow transmission of an application program for execution on the client device based on the comparison by the comparator module.
69 . The system of claim 63 wherein the transceiver module is further configured to transmit a new task set to the client device_based on the comparison by the comparator module.
70 . The system of claim 66 wherein the agent module is further configured to determine an additional set of software components for executing a new task set and to determine if the additional set of software components are trustworthy.
71 . The system of claim 61 wherein the server further comprises an electronic vault.
72 . The system of claim 61 wherein an electronic vault comprising one or more realms having one or more vaults having one or more folders.
73 . An article of manufacture having computer-readable program portions embodied thereon for generating a trusted communication channel with a client, the article comprising:
a computer-readable program portion for determining a task set for processing user authentication data; a computer-readable program portion for determining a set of software components for executing the task set; a computer-readable program portion for determining if the software components are trustworthy; a computer-readable program for providing a reference set of authentication data to a client if the software components are determined to be trustworthy and not providing the reference set of authentication data otherwise; and a computer-readable program portion for comparing, on the client, the reference set of authentication data with a candidate set of authentication data.Join the waitlist — get patent alerts
Track US2008034219A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.