US2020228335A1PendingUtilityA1

Authentication system for enhancing network security

Assignee: CEELOX PATENTS LLCPriority: Apr 13, 2006Filed: Mar 27, 2020Published: Jul 16, 2020
Est. expiryApr 13, 2026(expired)· nominal 20-yr term from priority
H04L 9/3213H04L 63/0428H04L 9/3231H04L 63/0861
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A network-based biometric authentication system includes a client computer ( 10 ), a third party server ( 24 ), and a biometric authentication server ( 26 ). A user requests access to a web site hosted by the third party server via the client computer, wherein the third party server communicates a deployable object to the client computer. The client computer executes the deployable object, wherein the object enables the client computer to receive a user name, password, and biometric data from the user and to communicate the user name, password, and biometric data to the biometric authentication server in a secure fashion. The biometric authentication server authenticates the user name, password, and biometric data, and communicates the user name and password to the third party server, which attempts to verify the user name and password in a conventional manner and grants access to the user if the user name and password are verified.

Claims

exact text as granted — not AI-modified
Having thus described a preferred embodiment of the invention, what is claimed as new and desired to be protected by Letters Patent includes the following: 
     
         1 . One or more non-transitory computer-readable storage medium storing computer-executable instructions that, when executed by one or more processor, perform a method of enabling authentication of a user at a third-party server, wherein the computer program instructs the one or more processors to perform the steps of:
 receive, by a client computer and from the user, user identification information;   receive, by the client computer, key information from an authentication server;   encrypt, by the client computer using the key information, the user identification information to obtain encrypted user identification information;   transmit, by the client computer and to the authentication server, the encrypted user identification information;   transmit, by the client computer and to the third-party server, at least one item of user authentication information;   decrypt, by the authentication server, the encrypted user identification information;   authenticate, by the authentication server, the user based on the stored identification information to obtain an authenticated user;   receive, by the authentication server and from the third-party server, the at least one item of user authentication information; and   based on the received at least one item of user authentication information and the authenticated user, grant access to the user to the third-party server.   
     
     
         2 . The computer-readable storage medium of  claim 1 , wherein the identification information comprises at least one of biometric information, a user password, and a username. 
     
     
         3 . The computer-readable storage medium of  claim 1 , wherein the biometric information is at least one of voice, retinal, iris, and facial characteristics data. 
     
     
         4 . The computer-readable storage medium of  claim 1 , wherein the client computer is a handheld device. 
     
     
         5 . The computer-readable storage medium of  claim 1 ,
 wherein the key used to encrypt the user identification information is a first key, and   wherein the user authentication information transmitted by the client computer to the third-party server is encrypted by or is a second key.   
     
     
         6 . The computer-readable storage medium of  claim 4 , wherein the second key is derived from information provided by the authentication server, and such information is the same as the information used to derive the first key. 
     
     
         7 . The computer-readable storage medium of  claim 1 , wherein the step of granting access to the user to the third-party server based on the received user authentication information and the authenticated user includes the step of confirming the user authentication information received by the authentication server and from the third-party server is derived from or includes the information provided by the authentication server and to the client computer. 
     
     
         8 . The computer-readable storage medium of  claim 1 , wherein the step of authenticating the user based on the stored identification information includes confirming the stored identification information matches the decrypted user identification information. 
     
     
         9 . The computer-readable storage medium of  claim 1 , wherein the step of granting access to the user to the third-party server comprises granting access to the user to a particular resource associated with the third-party server. 
     
     
         10 . A computerized method of enabling authentication of a user at a third-party server, wherein the computerized method comprises the steps of:
 receive, by a client computer and from the user, user identification information, wherein the user identification information comprises at least one of a username and a password;   receive, by the client computer, key information from an authentication server;   encrypt, by the client computer using the key information, the user identification information to obtain encrypted user identification information;   transmit, by the client computer and to the authentication server, the encrypted user identification information;   transmit, by the client computer and to the third-party server, at least one item of user authentication information;   decrypt, by the authentication server, the encrypted user identification information;   authenticate, by the authentication server, the user based on the stored identification information to obtain an authenticated user;   receive, by the authentication server and from the third-party server, the at least one item of user authentication information; and   based on the received at least one item of user authentication information and the authenticated user, grant access to the user to the third-party server.   
     
     
         11 . The method of  claim 10 , wherein the identification information further comprises biometric information. 
     
     
         12 . The method of  claim 11 , wherein the biometric information comprises at least one of fingerprint, voice, retinal, iris, and facial characteristics data. 
     
     
         13 . The method of  claim 12 , wherein biometric authentication is performed prior to transmitting to the authorization server. 
     
     
         14 . The method of  claim 13 , wherein the biometric authentication is performed on a handheld device. 
     
     
         15 . The method of  claim 12 , wherein the biometric information is sent by the authentication server to the third-party server and verified at the third-party server by comparing to stored biometric information. 
     
     
         16 . A computerized method of enabling authentication of a user at a third-party server, wherein the computerized method comprises the steps of:
 receive, by a client computer and from the user, user identification information,   wherein the client computer is a handheld device;   receive, by the client computer, key information from an authentication server;   encrypt, by the client computer using the key information, the user identification information to obtain encrypted user identification information;   transmit, by the client computer and to the authentication server, the encrypted user identification information;   transmit, by the client computer and to the third-party server, at least one item of user authentication information;   decrypt, by the authentication server, the encrypted user identification information;   authenticate, by the authentication server, the user based on the stored identification information to obtain an authenticated user;   receive, by the authentication server and from the third-party server, the at least one item of user authentication information; and   based on the received at least one item of user authentication information and the authenticated user, grant access to the user to the third-party server.   
     
     
         17 . The method of  claim 16 ,
 wherein the identification information comprises at least one of a username and a password, and is bundled with biometric identification information,   wherein the biometric identification information is at least one of fingerprint, voice, retinal, iris, and facial characteristics data.   
     
     
         18 . The method of  claim 17 , wherein the step of authenticating the user based on the stored biometric identification information includes confirming the stored biometric identification information matches the decrypted user biometric identification information. 
     
     
         19 . The method of  claim 17 , wherein the step of granting access to the user to the third-party server based on the received user authentication information and the authenticated user includes the step of confirming the user authentication information received by the authentication server and from the third-party server is derived from or includes the information provided by the authentication server and to the client computer. 
     
     
         20 . The method of  claim 19 ,
 wherein the key used to encrypt the user biometric identification information is a first key,   wherein the user authentication information transmitted by the client computer to the third-party server is encrypted by or is a second key and is bundled with the identification information and the biometric identification information.

Join the waitlist — get patent alerts

Track US2020228335A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.