US2023283604A1PendingUtilityA1

Biometric knowledge extraction for mutual and multi-factor authentication and key exchange

Assignee: WELLS FARGO BANK NAPriority: May 31, 2016Filed: May 15, 2023Published: Sep 7, 2023
Est. expiryMay 31, 2036(~9.8 yrs left)· nominal 20-yr term from priority
H04L 63/0861H04L 63/06H04L 63/0428G06F 16/9535H04W 12/06H04L 9/3231H04L 9/0866H04L 9/0844H04L 9/0861H04W 12/68H04L 2209/56
74
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Various embodiments relate to a method performed by a processor of a computing system. An example method includes matching a possession object identifier with a stored user secret, generating a decryption key using the stored user secret as an input to a password authenticated key exchange protocol, decrypting an encrypted authentication data message using the decryption key, extracting a user secret from the biometric sample, authenticating the user by matching the extracted user secret with the stored user secret, and authenticating an identity of the user by matching the biometric sample with a biometric reference template associated with the possession object identifier.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 generating, by a computing system, a decryption key using a first user secret as an input to a password authenticated key exchange protocol, the first user secret is stored in a memory of the computing system;   decrypting, by the computing system, an encrypted authentication data message using the decryption key, the encrypted authentication data message comprising a second user secret;   authenticating, by the computing system, a user in response to matching the second user secret with the first user secret.   
     
     
         2 . The method of  claim 1 , wherein the encrypted authentication data message comprises data encrypted using an encryption key, the encryption key is generated using the second user secret. 
     
     
         3 . The method of  claim 2 , further comprising extracting the second user secret from the data. 
     
     
         4 . The method of  claim 3 , wherein the data comprises a biometric sample. 
     
     
         5 . The method of  claim 1 , authenticating the user further comprises matching the biometric sample with a biometric reference template associated with the user. 
     
     
         6 . The method of  claim 2 , wherein the encrypted authentication data message comprises an object identifier, and authenticating the user further comprises matching the object identifier with a stored object identifier associated with the user. 
     
     
         7 . The method of  claim 1 , wherein authenticating the user further comprises:
 transmitting, by the computing system to a biometric service provider computing system, a matching request, the matching request comprising a biometric sample of the encrypted authentication data message; and   receiving, by the computing system from the biometric service provider computing system, information indicative of comparison of the biometric sample to a biometric reference value.   
     
     
         8 . A system, comprising:
 a memory; and   a processor configured to:
 generate a decryption key using a first user secret as an input to a password authenticated key exchange protocol, the first user secret is stored in the memory; 
   decrypt an encrypted authentication data message using the decryption key, the encrypted authentication data message comprising a second user secret;   authenticate a user in response to matching the second user secret with the first user secret.   
     
     
         9 . The system of  claim 8 , wherein the encrypted authentication data message comprises data encrypted using an encryption key, the encryption key is generated using the second user secret. 
     
     
         10 . The system of  claim 9 , the processor is further configured to extract the second user secret from the data. 
     
     
         11 . The system of  claim 10 , wherein the data comprises a biometric sample. 
     
     
         12 . The system of  claim 8 , authenticating the user further comprises matching the biometric sample with a biometric reference template associated with the user. 
     
     
         13 . The system of  claim 9 , wherein the encrypted authentication data message comprises an object identifier, and authenticating the user further comprises matching the object identifier with a stored object identifier associated with the user. 
     
     
         14 . The system of  claim 8 , wherein authenticating the user further comprises:
 transmitting, to a biometric service provider computing system, a matching request, the matching request comprising a biometric sample of the encrypted authentication data message; and   receiving, from the biometric service provider computing system, information indicative of comparison of the biometric sample to a biometric reference value.   
     
     
         15 . A non-transitory computer readable medium having computer-executable instructions embodied therein that, when executed by a computing system, causes the computing system to perform operations for multi-factor authentication, the operations comprising:
 generating a decryption key using a first user secret as an input to a password authenticated key exchange protocol, the first user secret is stored in a memory of the computing system;   decrypting an encrypted authentication data message using the decryption key, the encrypted authentication data message comprising a second user secret;   authenticating a user in response to matching the second user secret with the first user secret.   
     
     
         16 . The non-transitory computer readable medium of  claim 15 , wherein the encrypted authentication data message comprises data encrypted using an encryption key, the encryption key is generated using the second user secret. 
     
     
         17 . The non-transitory computer readable medium of  claim 16 , the operations further comprising extracting the second user secret from the data. 
     
     
         18 . The non-transitory computer readable medium of  claim 15 , authenticating the user further comprises matching the biometric sample with a biometric reference template associated with the user. 
     
     
         19 . The non-transitory computer readable medium of  claim 16 , wherein the encrypted authentication data message comprises an object identifier, and authenticating the user further comprises matching the object identifier with a stored object identifier associated with the user. 
     
     
         20 . The non-transitory computer readable medium of  claim 15 , wherein authenticating the user further comprises:
 transmitting, to a biometric service provider computing system, a matching request, the matching request comprising a biometric sample of the encrypted authentication data message; and   receiving, from the biometric service provider computing system, information indicative of comparison of the biometric sample to a biometric reference value.

Join the waitlist — get patent alerts

Track US2023283604A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.