US2015113616A1PendingUtilityA1

Mobile device-based authentication with enhanced security measures

Individually held — no corporate assignee on recordPriority: Sep 27, 2011Filed: Oct 18, 2013Published: Apr 23, 2015
Est. expirySep 27, 2031(~5.1 yrs left)· nominal 20-yr term from priority
G06F 2221/2111G06F 21/35G06Q 20/40145G06F 21/32H04L 2463/082H04L 63/0861H04L 63/18G06Q 20/3224H04L 63/0853G06Q 20/206H04W 12/068
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The tracking of user authentication is disclosed. A first user biometric data set is received from a mobile device on an authentication server, and a second user biometric data set is received from a site resource on the authentication server. The second user biometric is transmitted from the site resource in response to receipt of an authentication command from the mobile device on the site resource. The user is rejected for access to the site resource if either one of the first set of biometric data and the second set of biometric data is not validated against respective first and second sets of pre-enrolled biometric data for the user. A security procedure is initiated on at least one of the mobile device and a remote physical device separate from the mobile device in response to the rejecting of the user for access to the site resource.

Claims

exact text as granted — not AI-modified
1 . A method for tracking user authentication, comprising:
 receiving a first user biometric data set from a mobile device on an authentication server;   receiving a second user biometric data set from a site resource on the authentication server, the second user biometric being transmitted from the site resource in response to receipt of an authentication command from the mobile device on the site resource;   rejecting the user for access to the site resource if either one of the first set of biometric data and the second set of biometric data is not validated against respective first and second sets of pre-enrolled biometric data for the user stored independently of each other on the remote authentication server; and   initiating a security procedure independent of access to the site resource on either one or both of the mobile device and a remote physical device separate from the mobile device in response to the rejecting of the user for access to the site resource.   
     
     
         2 . The method of  claim 1 , wherein the security procedure includes recording at least one image from an on-board camera on the mobile device. 
     
     
         3 . The method of  claim 1 , wherein the security procedure includes recording at least one sequence of audio from an on-board microphone on the mobile device. 
     
     
         4 . The method of  claim 1 , wherein the security procedure includes recording at least one sequence of combined video and audio from an on-board microphone and an on-board camera both on the mobile device. 
     
     
         5 . The method of  claim 1 , wherein the security procedure includes capturing a DNA sample from a user of the mobile device. 
     
     
         6 . The method of  claim 1 , wherein the security procedure includes storing a set of coordinates retrieved from an on-board geolocation module on the mobile device. 
     
     
         7 . The method of  claim 1 , wherein the security procedure includes activating a remote physical security device from the remote authentication server. 
     
     
         8 . The method of  claim 7 , wherein the remote physical security device is a video camera covering a vicinity of the user as reported by an on-board geolocation module on the mobile device. 
     
     
         9 . The method of  claim 7 , wherein the remote physical security device is a confinement device activated against the user. 
     
     
         10 . A method for tracking user authentication, the method comprising:
 receiving a first user biometric data set from a mobile device on an authentication server;   receiving a second user biometric data set from a site resource on the authentication server, the second user biometric being transmitted from the site resource in response to receipt of an authentication command from the mobile device on the site resource;   setting an emergency mode if either one of the first set of biometric data and the second set of biometric data is validated against a pre-enrolled emergency biometric data different from a pre-enrolled authentication biometric data, the pre-enrolled authentication biometric data and the pre-enrolled emergency biometric data being stored on the remote authentication server; and   initiating a security procedure independent of access to the site resource on either one or both of the mobile device and a remote physical device separate from the mobile device in response to setting the emergency mode.   
     
     
         11 . The method of  claim 10 , further comprising:
 rejecting the user for access to the site resource if either one of the first set of biometric data and the second set of biometric data is not validated against respective first and second sets of the pre-enrolled authentication biometric data for the user stored independently of each other on the remote authentication server.   
     
     
         12 . The method of  claim 11 , wherein the pre-enrolled authentication biometric data corresponds to a first biometric feature of the user, and the pre-enrolled emergency biometric data corresponds to a second biometric feature of the user different from the first biometric feature. 
     
     
         13 . The method of  claim 12 , wherein the pre-enrolled emergency biometric data is for a first finger of the user, and the pre-enrolled authentication biometric data is for a second finger of the user. 
     
     
         14 . The method of  claim 10 , further comprising:
 setting a secondary emergency mode if either one of the first set of biometric data and the second set of biometric data is validated against a pre-enrolled secondary emergency biometric data stored on the remote authentication server;   wherein the secondary emergency mode corresponds to a third party being endangered, the third party being different from a user to which the first set of biometric data and the second set of biometric data correspond.   
     
     
         15 . The method of  claim 10 , wherein the security procedure includes recording at least one image from an on-board camera on the mobile device. 
     
     
         16 . The method of  claim 10 , wherein the security procedure includes recording at least one sequence of audio from an on-board microphone on the mobile device. 
     
     
         17 . The method of  claim 10 , wherein the security procedure includes recording at least one sequence of combined video and audio from an on-board microphone and an on-board camera both on the mobile device. 
     
     
         18 . The method of  claim 10 , wherein the security procedure includes capturing a DNA sample from a user of the mobile device. 
     
     
         19 . The method of  claim 10 , wherein the security procedure includes activating a remote physical security device from the remote authentication server. 
     
     
         20 . The method of  claim 19 , wherein the remote physical security device is a video camera covering a vicinity of the user as reported by an on-board geolocation module on the mobile device. 
     
     
         21 . The method of  claim 19 , wherein the remote physical security device is a confinement device activated against the user. 
     
     
         22 . The method of  claim 10 , further comprising:
 denying access to the site resource.   
     
     
         23 . The method of  claim 10 , further comprising:
 permitting limited access to the site resource.   
     
     
         24 . The method of  claim 10 , further comprising:
 permitting access to a decoy site resource.   
     
     
         25 . A method of authenticating a user to a site resource, comprising:
 capturing a first biometric input from the user on an integrated first biometric reader on a mobile device, the first biometric input corresponding to a first biometric feature of the user;   deriving a first set of biometric data from the captured first biometric input;   transmitting the first set of biometric data to a remote authentication server from the mobile device;   transmitting a secondary authentication instruction to the site resource directly from the mobile device in response to receipt of the first biometric input;   capturing a second biometric input from the user on a second biometric reader connected to the site resource in response to the secondary authentication instruction, the second biometric input corresponding to a second biometric feature of the user;   deriving a second set of biometric data from the captured second biometric input;   transmitting the second set of biometric data to the remote authentication server from the site resource;   rejecting the user for access to the site resource if either one of the first set of biometric data and the second set of biometric data is not concurrently and independently validated against respective first and second sets of pre-enrolled biometric data for the user stored independently of each other on the remote authentication server; and   initiating a security procedure on at least one of the mobile device and a remote physical device separate from the mobile device in response to the rejecting of the user for access to the site resource;   wherein the first set of biometric data and the second set of biometric data are transmitted to the remote authentication server for validation.   
     
     
         26 . The method of  claim 25 , wherein the user is rejected when the first set of biometric data and the second set of biometric data were captured and transmitted outside a predefined timeout period. 
     
     
         27 . The method of  claim 25 , wherein the user is rejected when the first set of biometric data and the second set of biometric data were captured and transmitted from locations outside a predefined proximity to each other. 
     
     
         28 . The method of  claim 25 , further comprising:
 encrypting the first biometric data with a first encoding site prior to transmitting to the remote authentication server; and   encrypting the second biometric data with a second encoding site prior to transmitting to the remote authentication server;   wherein the first encoding site and the second encoding site are independent of each other.   
     
     
         29 . A system for establishing a secure data communications link with a user device and a site resource, comprising:
 a secured transmission gateway to which the user device connects and with which the secure data communications link is established;   a central verification clearinghouse system storing a first biometric data of a user;   a first independent encoding site linked to the user device over a first data transmission link, biometric data provided by a user on the user device being encoded by the first independent encoding site upon transmission to the central verification clearinghouse system on the first data transmission link;   a second independent encoding site linked to site resource over a second data transmission link independent of the first data transmission link, biometric data provided by the user on the site resource upon request responsive to an authentication instruction from the user device being encoded by the second independent encoding site upon transmission to the central verification clearinghouse system on the second data transmission link;   a first independent security site linked to the user device over the first data transmission link to monitor transmissions from the user device to the central verification clearinghouse system for security breaches;   a second independent security site linked to the site resource over the second data transmission link to monitor transmissions from the site resource to the central verification clearinghouse system for security breaches;   wherein the secured transmission gateway authorizes the secure data communications link with the user device upon a contemporaneous and independent verification of the biometric data by the central verification clearinghouse as encoded by the first independent encoding site and by the second independent encoding site and confirmations from each of the first and second independent security sites and the first and second encoding sites that no security breaches were encountered;   wherein the first independent security site, the first independent encoding site, the second independent security site, and the second independent encoding site communicate with the secured transmission gateway over respective independent data communications links.

Join the waitlist — get patent alerts

Track US2015113616A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.