US2017366556A1PendingUtilityA1

Multichannel device utilizing a centralized out-of-band authentication system (cobas)

Assignee: STRIKEFORCE TECH INCPriority: Sep 5, 2000Filed: Jun 30, 2017Published: Dec 21, 2017
Est. expirySep 5, 2020(expired)· nominal 20-yr term from priority
Inventors:Ram Pemmaraju
H04L 63/18G06F 21/42H04L 63/102H04L 9/3231H04L 63/083H04L 9/3215H04L 63/08H04L 63/0861G06F 21/32
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A multichannel security system is disclosed, which system is for granting and denying access to a host computer in response to a demand from an access-seeking individual and computer. The access-seeker has a peripheral device operative within an authentication channel to communicate with the security system. The access-seeker initially presents identification and password data over an access channel which is intercepted and transmitted to the security computer. The security computer then communicates with the access-seeker. A biometric analyzer—a voice or fingerprint recognition device—operates upon instructions from the authentication program to analyze the monitored parameter of the individual. In the security computer, a comparator matches the biometric sample with stored data, and, upon obtaining a match, provides authentication. The security computer instructs the host computer to grant access and communicates the same to the access-seeker, whereupon access is initiated over the access channel.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method for controlling access to a host computer, the method comprising:
 receiving, at a security computer, through a first communication path, a user's request to access the host computer and the user's login identification,
 wherein the user's login identification was received by an accessor device from the user, and 
 wherein the user's request to access was diverted to the security computer; 
   verifying the login identification;   outputting, at the security computer, a prompt requesting transmission of data from the user through a second communication path, wherein the second communication path differs from the first communication path by at least one path resource;   receiving, at the security computer, the requested transmission of data from the user through a communication path other than the first communication path, wherein the communication path other than the first communication path differs from the first communication path by at least one path resource;   authenticating the user's identity, at the security computer, based on the received data transmission from the user; and   in response to said user being authenticated, sending a message from the security computer to the host computer that causes the user to be granted or denied access to the host computer.   
     
     
         22 . The method of  claim 21 , wherein the second communication path differs from the first communication path by at least one facility. 
     
     
         23 . The method of  claim 21 , wherein the second communication path differs from the first communication path by at least one time slot. 
     
     
         24 . The method of  claim 21 , wherein the second communication path differs from the first communication path by at least one frequency channel. 
     
     
         25 . The method of  claim 21 , wherein the communication path other than the first communication path differs from the first communication path by at least one facility. 
     
     
         26 . The method of  claim 21 , wherein the communication path other than the first communication path differs from the first communication path by at least one time slot. 
     
     
         27 . The method of  claim 21 , wherein the communication path other than the first communication path differs from the first communication path by at least one frequency channel. 
     
     
         28 . The method of  claim 21 , wherein the message is an instruction from the security computer to the host computer to grant access to the host computer or deny access thereto. 
     
     
         29 . The method of  claim 21 , wherein the first communication path comprises one of a wide area network and a local area network. 
     
     
         30 . A method for controlling access to a host computer, comprising the steps of:
 receiving at a security computer a user's request to access to the host computer, wherein the request to access was transmitted from an accessor device and diverted to the security computer;   receiving at the security computer a user identification and a first password from the accessor device, wherein the user identification and first password were received by the accessor device from the user;   verifying at the security computer that the first password matched a predetermined password associated with the user;   outputting a request for response to a peripheral device, wherein the outputting comprises initiating a communication to the peripheral device and receiving a response indicating a connection with the peripheral device;   outputting to the peripheral device a prompt to the user to provide a spoken password;   receiving from the peripheral device the user-provided spoken password;   verifying at the security computer that the received user-provided spoken password matches a predetermined spoken password; and   outputting a message to cause the host computer to grant access based on the user-provided spoken password.   
     
     
         31 . The method of  claim 30 , wherein the message is an instruction from the security computer to the host computer to grant access to the host computer. 
     
     
         32 . A security system for controlling access to a host computer using a mobile device, the system comprising a security computer configured to:
 receive a user identification from a first communication path, wherein the user identification was input by a user requesting access to an Internet-connected web server, wherein the web server is associated with a commercial institution;   receive predetermined data associated with the user identification, wherein the predetermined data comprises an address of a mobile device;   output to the mobile device an instruction through a second communication path, wherein the second communication path differs from the first communication path by at least one path resource and wherein the instruction requests a user input;   receive the requested user input through a path other than the first communication path;   authenticate the user's identity based on the received user input; and   based on the authentication of the user's identity, output an instruction that causes the user to be granted or denied access to the host computer.   
     
     
         33 . The method of  claim 32 , wherein the second communication path differs from the first communication path by at least one facility. 
     
     
         34 . The method of  claim 32 , wherein the second communication path differs from the first communication path by at least one time slot. 
     
     
         35 . The method of  claim 32 , wherein the second communication path differs from the first communication path by at least one frequency channel. 
     
     
         36 . The method of  claim 32 , wherein the communication path other than the first communication path differs from the first communication path by at least one facility. 
     
     
         37 . The method of  claim 32 , wherein the communication path other than the first communication path differs from the first communication path by at least one time slot. 
     
     
         38 . The method of  claim 32 , wherein the communication path other than the first communication path differs from the first communication path by at least one frequency channel. 
     
     
         39 . The method of  claim 32 , wherein the first communication path comprises one of a wide area network and a local area network. 
     
     
         40 . The system of  claim 32 , wherein the security computer is configured to receive biometric data associated with the user as the received user input, wherein the security computer is further configured to:
 compare predetermined biometric data with the received biometric data, wherein the user's identity is authenticated based on the comparison of said predetermined biometric data with the received biometric data associated with the user.   
     
     
         41 . The system of  claim 40 , wherein the authentication of the user's identity is based on fingerprint identification. 
     
     
         42 . The system of  claim 40 , wherein the authentication of the user's identity is based on palm recognition. 
     
     
         43 . The system of  claim 40 , wherein the authentication of the user's identity is based on iris recognition. 
     
     
         44 . The system of  claim 40 , wherein the authentication of the user's identity is based on retina recognition. 
     
     
         45 . The system of  claim 40 , wherein the authentication of the user's identity is based on facial recognition. 
     
     
         46 . A method for controlling access to a host computer, the method comprising:
 receiving, at a security computer, through a first communication path, a user's request to access the host computer and the user's login identification,
 wherein the user's login identification was received by an accessor device from the user, and 
 wherein the user's request to access was diverted to the security computer; 
   verifying the login identification;   outputting, at the security computer, a prompt requesting transmission of data from the user through a second communication path, wherein the second communication path differs from the first communication path by at least one path resource;   receiving, at the security computer, the requested transmission of data from the user;   authenticating the user's identity, at the security computer, based on the received data transmission from the user; and   in response to said user being authenticated, sending a message from the security computer to the host computer that causes the user to be granted or denied access to the host computer.   
     
     
         47 . The method of  claim 46 , wherein the second communication path differs from the first communication path by at least one facility. 
     
     
         48 . The method of  claim 46 , wherein the second communication path differs from the first communication path by at least one time slot. 
     
     
         49 . The method of  claim 46 , wherein the second communication path differs from the first communication path by at least one frequency channel. 
     
     
         50 . The method of  claim 46 , wherein the message is an instruction from the security computer to the host computer to grant access to the host computer or deny access thereto.

Join the waitlist — get patent alerts

Track US2017366556A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.