Multiple user authentications on a communications device
Abstract
A communications device provides a biometric reader to authenticate users onto the communications device based on a single biometric input. The communications device maintains a local copy of the strong authentication credentials, such as a user identification and password, and the biometrics which were previously input by users of the communications device. Then, rather than requiring re-entry of the strong authentication credentials to authenticate (or re-authenticate) these users onto the communications device, the communications device is able to authenticate the users based on the input of the appropriate biometric. When a biometric input is received, the communications device identifies the locally stored strong authentication credentials that is associated with the input biometric, and uses the locally stored strong authentication credentials to authenticate the user.
Claims
exact text as granted — not AI-modified1 .- 20 . (canceled)
21 . A computer-implemented method for authenticating a first user of a communications device having a biometric reader, the method comprising:
receiving authentication credentials for authenticating the first user to a service; storing on the communications device the authentication credentials; receiving a first instance of a biometric characteristic of the first user; storing on the communications device the first instance of the received biometric characteristic in association with the received authentication credentials; after storing the first instance of the biometric characteristic and the authentication credentials,
receiving via the biometric reader a second instance of the biometric characteristic of a user;
determining whether the second instance of the biometric characteristic matches the first instance of the biometric characteristic; and
in response to determining that the second instance of the biometric characteristic matches the first instance of the biometric characteristic, providing to the service the authentication credentials that is stored in association with the first instance of the biometric characteristic so that the service can authenticate the first user based on the authentication credentials.
22 . The method of claim 21 wherein the biometric characteristic is a fingerprint scan.
23 . The method of claim 21 wherein the biometric characteristic is a retina scan.
24 . The method of claim 21 wherein the providing to the service includes:
requesting log on to a server using the authentication credentials;
upon successfully logging on, allowing use of the communications device; and
upon unsuccessfully logging on, denying use of the communications device.
25 . The method of claim 21 further comprising upon receiving a third instance of the biometric characteristic that matches the first instance of the biometric characteristic, authenticating the user using the authentication credentials.
26 . The method of claim 21 wherein the first instance of the biometric characteristic is received from the user via the biometric reader and the authentication credentials is received from the user.
27 . A device for authenticating a user of the device, the device comprising:
a biometric reader; one or more memories storing computer-executable instructions that control the device to:
access an association between a first biometric characteristic of a first user and authentication credentials for the first user; and
receive via the biometric reader a second biometric characteristic for a user;
determine whether the second biometric characteristic matches the first biometric characteristic; and
in response to determining that the second biometric characteristic matches the first biometric characteristic, provide the authentication credentials to authenticate the first user; and
a processor for executing the computer-executable instructions stored in the one or more memories.
28 . The device of claim 27 wherein the one or more memories further include computer-executable instructions that control the device to:
receive from the first user the authentication credentials;
upon determining that the authentication credentials are not associated with a biometric characteristic, receive from the first user via the biometric reader the first biometric characteristic; and
store the association between the first biometric characteristic and authentication credentials.
29 . The device of claim 27 wherein the one or more memories further include computer-executable instructions that control the device to:
receive from the first user the authentication credentials;
receive from the first user via the biometric reader the first biometric characteristic; and
store the association between the first biometric characteristic and authentication credentials.
30 . The device of claim 27 wherein the instructions that provide further provide the authentication credentials to a server so that the server can authenticate the first user.
31 . The device of claim 27 wherein the instructions that provide further provide the authentication credentials to an application so that the application can authenticate the first user.
32 . The device of claim 27 wherein the instructions further comprise instructions that encrypt the authentication credentials.
33 . The device of claim 27 wherein the instructions further comprise instructions that receive additional authentication credentials of the first user and store an association between the first biometric characteristic and the additional authentication credentials.
34 . The device of claim 27 wherein the instructions that provide further provide the authentication credentials for locally authenticating the first user to use a feature of the device.
35 . A method performed by a device to provide authentication credentials for authenticating a user of the device, the device having a biometric reader, the method comprising:
accessing an association between a first representation of a first biometric characteristic of a first user and authentication credentials of the first user, the first representation of the first biometric characteristic and authentication credentials being stored locally in memory of the device; receiving via the biometric reader a second biometric characteristic of a user; creating a second representation of the second biometric characteristic; determining whether the second representation matches the first representation; and in response to determining that the second representation matches the first representation,
retrieving the authentication credentials stored locally in memory of the device; and
providing the authentication credentials for authenticating the first user.
36 . The method of claim 35 further comprising:
receiving from the first user the authentication credentials;
upon determining that the authentication credentials are not associated with a biometric characteristic, receiving from the first user via the biometric reader the first biometric characteristic; and
storing the association between the first biometric characteristic and authentication credentials.
37 . The method of claim 35 further comprising:
receiving from the first user the authentication credentials;
receiving from the first user via the biometric reader the first biometric characteristic; and
storing the association between the first biometric characteristic and authentication credentials.
38 . The method of claim 35 further comprising sending the authentication credentials to a server so that the first user can be logged on to the server.
39 . The method of claim 35 further comprising providing the authentication credentials to an application so that the first user can use the application.
40 . The method of claim 35 further comprising wherein the authentication credentials are provided for locally authenticating the first user to use a feature of the device.Join the waitlist — get patent alerts
Track US2017339136A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.