Mobile device-based authentication
Abstract
Mobile device-based authentication is disclosed. A first biometric input corresponding to a first biometric feature of the user is captured on the mobile device. A first set of biometric data is derived from the captured first biometric input. The first set of biometric data is transmitted to a remote authentication server. Thereafter, a secondary authentication instruction is transmitted to the site resource in response. Access to the site resource is permitted based upon a validation of the first set of biometric data, and a second biometric input that is captured on the site resource in response to the secondary authentication instruction received thereon. The first set of biometric data and the second set of biometric data are validated by remote authentication server substantially contemporaneously.
Claims
exact text as granted — not AI-modified1 . A method of authenticating a user to a site resource, comprising:
capturing a first biometric input from the user on an integrated first biometric reader on a mobile device, the first biometric input corresponding to a first biometric feature of the user; deriving a first set of biometric data from the captured first biometric input; transmitting the first set of biometric data to a remote authentication server from the mobile device; transmitting a secondary authentication instruction to the site resource in response to receipt of the first biometric input; capturing a second biometric input from the user on a second biometric reader connected to the site resource in response to the secondary authentication instruction, the second biometric input corresponding to a second biometric feature of the user; deriving a second set of biometric data from the captured second biometric input; transmitting the second set of biometric data to the remote authentication server from the site resource; and authenticating the user for access to the site resource based upon a validation of the first set of biometric data and the second set of biometric data against a pre-enrolled set of biometric data for the user stored on the remote authentication server; wherein the first set of biometric data and the second set of biometric data is transmitted to the remote authentication server substantially contemporaneously and validated for a successful authentication.
2 . The method of claim 1 , wherein the authentication fails upon a time lapse exceeding a predetermined threshold between the transmission and validation of the first set of biometric data and the transmission and validation of the second set of biometric data to the remote authentication server.
3 . The method of claim 1 , wherein the capturing of the biometric input is in response to an authentication request input from the user on the mobile device.
4 . The method of claim 3 , wherein the authentication request input is received from the user following a challenge-response sequence.
5 . The method of claim 1 , wherein the first biometric reader and the second biometric reader are selected from a group consisting of: a fingerprint scanner, an audio microphone, and an imaging camera.
6 . The method of claim 1 , wherein the site resource is selected from a group consisting of: an automated teller machine (ATM), a point of sale (POS) terminal, and a personal computer system.
7 . The method of claim 1 , wherein the first biometric feature and the second biometric feature of the user are different.
8 . The method of claim 1 , wherein the first biometric feature and the second biometric feature of the user are the same.
9 . The method of claim 1 , wherein the secondary authentication instruction to the site resource is transmitted over the wireless Near Field Communication (NFC) protocol.
10 . The method of claim 1 , wherein the secondary authentication instruction to the site resource is transmitted over the wireless Bluetooth low power protocol.
11 . (canceled)
12 . (canceled)
13 . (canceled)
14 . (canceled)
15 . (canceled)
16 . (canceled)
17 . (canceled)
18 . (canceled)
19 . (canceled)
20 . (canceled)
21 . (canceled)
22 . (canceled)Join the waitlist — get patent alerts
Track US2013254862A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.