Biometric knowledge extraction for mutual and multi-factor authentication and key exchange
Abstract
Various embodiments relate to a method performed by a processor of a computing system. An example method includes matching a possession object identifier with a stored user secret, generating a decryption key using the stored user secret as an input to a password authenticated key exchange protocol, decrypting an encrypted authentication data message using the decryption key, extracting a user secret from the biometric sample, authenticating the user by matching the extracted user secret with the stored user secret, and authenticating an identity of the user by matching the biometric sample with a biometric reference template associated with the possession object identifier.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method, comprising:
generating, by a computing system, a decryption key using a first user secret as an input to a password authenticated key exchange protocol, the first user secret is stored in a memory of the computing system; decrypting, by the computing system, an encrypted authentication data message using the decryption key, the encrypted authentication data message comprising a second user secret; authenticating, by the computing system, a user in response to matching the second user secret with the first user secret.
2 . The method of claim 1 , wherein the encrypted authentication data message comprises data encrypted using an encryption key, the encryption key is generated using the second user secret.
3 . The method of claim 2 , further comprising extracting the second user secret from the data.
4 . The method of claim 3 , wherein the data comprises a biometric sample.
5 . The method of claim 1 , authenticating the user further comprises matching the biometric sample with a biometric reference template associated with the user.
6 . The method of claim 2 , wherein the encrypted authentication data message comprises an object identifier, and authenticating the user further comprises matching the object identifier with a stored object identifier associated with the user.
7 . The method of claim 1 , wherein authenticating the user further comprises:
transmitting, by the computing system to a biometric service provider computing system, a matching request, the matching request comprising a biometric sample of the encrypted authentication data message; and receiving, by the computing system from the biometric service provider computing system, information indicative of comparison of the biometric sample to a biometric reference value.
8 . A system, comprising:
a memory; and a processor configured to:
generate a decryption key using a first user secret as an input to a password authenticated key exchange protocol, the first user secret is stored in the memory;
decrypt an encrypted authentication data message using the decryption key, the encrypted authentication data message comprising a second user secret; authenticate a user in response to matching the second user secret with the first user secret.
9 . The system of claim 8 , wherein the encrypted authentication data message comprises data encrypted using an encryption key, the encryption key is generated using the second user secret.
10 . The system of claim 9 , the processor is further configured to extract the second user secret from the data.
11 . The system of claim 10 , wherein the data comprises a biometric sample.
12 . The system of claim 8 , authenticating the user further comprises matching the biometric sample with a biometric reference template associated with the user.
13 . The system of claim 9 , wherein the encrypted authentication data message comprises an object identifier, and authenticating the user further comprises matching the object identifier with a stored object identifier associated with the user.
14 . The system of claim 8 , wherein authenticating the user further comprises:
transmitting, to a biometric service provider computing system, a matching request, the matching request comprising a biometric sample of the encrypted authentication data message; and receiving, from the biometric service provider computing system, information indicative of comparison of the biometric sample to a biometric reference value.
15 . A non-transitory computer readable medium having computer-executable instructions embodied therein that, when executed by a computing system, causes the computing system to perform operations for multi-factor authentication, the operations comprising:
generating a decryption key using a first user secret as an input to a password authenticated key exchange protocol, the first user secret is stored in a memory of the computing system; decrypting an encrypted authentication data message using the decryption key, the encrypted authentication data message comprising a second user secret; authenticating a user in response to matching the second user secret with the first user secret.
16 . The non-transitory computer readable medium of claim 15 , wherein the encrypted authentication data message comprises data encrypted using an encryption key, the encryption key is generated using the second user secret.
17 . The non-transitory computer readable medium of claim 16 , the operations further comprising extracting the second user secret from the data.
18 . The non-transitory computer readable medium of claim 15 , authenticating the user further comprises matching the biometric sample with a biometric reference template associated with the user.
19 . The non-transitory computer readable medium of claim 16 , wherein the encrypted authentication data message comprises an object identifier, and authenticating the user further comprises matching the object identifier with a stored object identifier associated with the user.
20 . The non-transitory computer readable medium of claim 15 , wherein authenticating the user further comprises:
transmitting, to a biometric service provider computing system, a matching request, the matching request comprising a biometric sample of the encrypted authentication data message; and receiving, from the biometric service provider computing system, information indicative of comparison of the biometric sample to a biometric reference value.Join the waitlist — get patent alerts
Track US2023283604A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.