Personal Portable Secured Network Access System
Abstract
A connection request is received from a network application for content provided by the content server. A determination is made that the network application is of a type associated with a secure terminal that biometrically authenticates a user prior to submitting the connection request. The secure terminal is authenticated. A secure personal storage device identifier is received from the secure terminal and identifies the secure personal storage device. Account credentials assigned for the secure personal storage device identifier are determined Account credentials are requested and received from the secure terminal. A determination is made that the received account credentials match the account credentials assigned for the secure personal storage device identifier. The network application is directed to connect to the requested content.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for allowing secure access to a content server, the method comprising:
receiving a first connection request from a first network application for content provided by the content server; determining that the first network application is of a type associated with a first secure terminal that biometrically authenticates a user prior to submitting the first connection request; authenticating the first secure terminal; receiving a first secure personal storage device identifier from the first secure terminal, wherein the first secure personal storage device identifier is stored within a first secure personal storage device that has been connected to the first secure terminal and identifies the first secure personal storage device; determining that account credentials are assigned for the first secure personal storage device identifier; requesting and receiving account credentials from the first secure terminal that are stored in the first secure personal storage device; determining that the received account credentials match the account credentials assigned for the first secure personal storage device identifier; and directing and allowing the first network application to connect to the content requested in the first connection request.
2 . The method of claim 1 , further comprising:
receiving a second connection request from a second network application for content provided by the content server; and responsive to determining that the second network application is not from a secure terminal, directing the second network application to unsecured content of the content server.
3 . The method of claim 1 , further comprising:
receiving a second connection request from a second network application for content provided by the content server; determining that the second network application is of a type that is associated with a second secure terminal that biometrically authenticates a user prior to submitting the second connection request; authenticating the second secure terminal; receiving a second secure personal storage device identifier from the second secure terminal, wherein the second secure personal storage device identifier is stored within a second secure personal storage device that has been connected to the second secure terminal and identifies the second secure personal storage device; determining that account credentials are not assigned for the second personal storage device identifier; verifying an identity of a user that originated the second connection request; determining that the user is authorized to access the content requested in the second connection request; creating account credentials for the user; associating the created account credentials with the second secure personal storage device identifier; and transmitting the created account credentials to the second secure terminal for writing to the second secure personal storage device.
4 . The method of claim 3 , wherein the step of verifying the identity of the user includes presenting one or more personal challenges and receiving one or more answers to the personal challenges respectively.
5 . The method of claim 1 , further comprising:
receiving a second connection request from a second network application for content provided by the content server; determining that the second network application is of a type that is associated with a second secure terminal that biometrically authenticates a user prior to submitting the second connection request; authenticating the second secure terminal; receiving a second secure personal storage device identifier from the second secure terminal, wherein the second secure personal storage device identifier is stored within a second secure personal storage device that has been connected to the second secure terminal and identifies the second secure personal storage device; determining that account credentials are assigned for the second secure personal storage device identifier; requesting and receiving account credentials from the second secure terminal that are stored in the second secure personal storage device; determining that the received account credentials do not match the account credentials assigned for the second secure personal storage device identifier; and instructing the second secure terminal to delete the account credentials stored on the second secure personal storage device identifier.
6 . The method of claim 1 , wherein the first network application is allowed to connect to the content requested in the first connection request without requiring input of one or more of a username, a password, and a personal identification number.
7 . The method of claim 1 , wherein the first network application is a browser.
8 . An apparatus, comprising:
a set of one or more processors; a set of one or more non-transitory computer-readable storage mediums storing instructions, that when executed by the set of processors, cause the set of processors to perform the following operations:
receive a first connection request from a first network application for content provided by a content server;
determine that the first network application is of a type associated with a first secure terminal that biometrically authenticates a user prior to submitting the first connection request;
authenticate the first secure terminal;
receive a first secure personal storage device identifier from the first secure terminal, wherein the first secure personal storage device identifier is stored within a first secure personal storage device that has been connected to the first secure terminal and identifies the first secure personal storage device;
determine that account credentials are assigned for the first secure personal storage device identifier;
request and receive account credentials from the first secure terminal that are stored in the first secure personal storage device;
determine that the received account credentials match the account credentials assigned for the first secure personal storage device identifier; and
direct and allow the first network application to connect to the content requested in the first connection request.
9 . The apparatus of claim 8 , wherein the set of non-transitory computer-readable storage mediums further stores instructions, that when executed by the set of processors, cause the set of processors to perform the following operations:
receive a second connection request from a second network application for content provided by the content server; and responsive to a determination that the second network application is not from a secure terminal, direct the second network application to unsecured content of the content server.
10 . The apparatus of claim 8 , wherein the set of non-transitory computer-readable storage mediums further stores instructions, that when executed by the set of processors, cause the set of processors to perform the following operations:
receive a second connection request from a second network application for content provided by the content server; determine that the second network application is of a type that is associated with a second secure terminal that biometrically authenticates a user prior to submitting the second connection request; authenticate the second secure terminal; receive a second secure personal storage device identifier from the second secure terminal, wherein the second secure personal storage device identifier is stored within a second secure personal storage device that has been connected to the second secure terminal and identifies the second secure personal storage device; determine that account credentials are not assigned for the second personal storage device identifier; verify an identity of a user that originated the second connection request; determine that the user is authorized to access the content requested in the second connection request; create account credentials for the user; associate the created account credentials with the second secure personal storage device identifier; and transmit the created account credentials to the second secure terminal for writing to the second secure personal storage device.
11 . The apparatus of claim 10 , wherein to verify the identity of the user includes a presentation of one or more personal challenges and receipt of one or more answers to the personal challenges respectively.
12 . The apparatus of claim 8 , wherein the set of non-transitory computer-readable storage mediums further stores instructions, that when executed by the set of processors, cause the set of processors to perform the following operations:
receive a second connection request from a second network application for content provided by the content server; determine that the second network application is of a type that is associated with a second secure terminal that biometrically authenticates a user prior to submitting the second connection request; authenticate the second secure terminal; receive a second secure personal storage device identifier from the second secure terminal, wherein the second secure personal storage device identifier is stored within a second secure personal storage device that has been connected to the second secure terminal and identifies the second secure personal storage device; determine that account credentials are assigned for the second secure personal storage device identifier; request and receiving account credentials from the second secure terminal that are stored in the second secure personal storage device; determine that the received account credentials do not match the account credentials assigned for the second secure personal storage device identifier; and instruct the second secure terminal to delete the account credentials stored on the second secure personal storage device identifier.
13 . The apparatus of claim 8 , wherein the first network application is allowed to connect to the content requested in the first connection request without requiring input of one or more of a username, a password, and a personal identification number.
14 . The apparatus of claim 8 , wherein the first network application is a browser.
15 . A non-transitory machine-readable storage medium that provides instructions that, when executed by a processor, cause said processor to perform operations comprising:
receiving a first connection request from a first network application for content provided by a content server; determining that the first network application is of a type associated with a first secure terminal that biometrically authenticates a user prior to submitting the first connection request; authenticating the first secure terminal; receiving a first secure personal storage device identifier from the first secure terminal, wherein the first secure personal storage device identifier is stored within a first secure personal storage device that has been connected to the first secure terminal and identifies the first secure personal storage device; determining that account credentials are assigned for the first secure personal storage device identifier; requesting and receiving account credentials from the first secure terminal that are stored in the first secure personal storage device; determining that the received account credentials match the account credentials assigned for the first secure personal storage device identifier; and directing and allowing the first network application to connect to the content requested in the first connection request.
16 . The non-transitory machine-readable storage medium of claim 15 , further comprising instructions that, when executed by the processor, cause said processor to perform the following operations:
receiving a second connection request from a second network application for content provided by the content server; and responsive to determining that the second network application is not from a secure terminal, directing the second network application to unsecured content of the content server.
17 . The non-transitory machine-readable storage medium of claim 15 , further comprising instructions that, when executed by the processor, cause said processor to perform the following operations:
receiving a second connection request from a second network application for content provided by the content server; determining that the second network application is of a type that is associated with a second secure terminal that biometrically authenticates a user prior to submitting the second connection request; authenticating the second secure terminal; receiving a second secure personal storage device identifier from the second secure terminal, wherein the second secure personal storage device identifier is stored within a second secure personal storage device that has been connected to the second secure terminal and identifies the second secure personal storage device; determining that account credentials are not assigned for the second personal storage device identifier; verifying an identity of a user that originated the second connection request; determining that the user is authorized to access the content requested in the second connection request; creating account credentials for the user; associating the created account credentials with the second secure personal storage device identifier; and transmitting the created account credentials to the second secure terminal for writing to the second secure personal storage device.
18 . The non-transitory machine-readable storage medium of claim 17 , wherein the step of verifying the identity of the user includes presenting one or more personal challenges and receiving one or more answers to the personal challenges respectively.
19 . The non-transitory machine-readable storage medium of claim 15 , further comprising instructions that, when executed by the processor, cause said processor to perform the following operations:
receiving a second connection request from a second network application for content provided by the content server; determining that the second network application is of a type that is associated with a second secure terminal that biometrically authenticates a user prior to submitting the second connection request; authenticating the second secure terminal; receiving a second secure personal storage device identifier from the second secure terminal, wherein the second secure personal storage device identifier is stored within a second secure personal storage device that has been connected to the second secure terminal and identifies the second secure personal storage device; determining that account credentials are assigned for the second secure personal storage device identifier; requesting and receiving account credentials from the second secure terminal that are stored in the second secure personal storage device; determining that the received account credentials do not match the account credentials assigned for the second secure personal storage device identifier; and instructing the second secure terminal to delete the account credentials stored on the second secure personal storage device identifier.
20 . The non-transitory machine-readable storage medium of claim 15 , wherein the first network application is allowed to connect to the content requested in the first connection request without requiring input of one or more of a username, a password, and a personal identification number.
21 . The non-transitory machine-readable storage medium of claim 15 , wherein the first network application is a browser.Join the waitlist — get patent alerts
Track US2016006733A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.