CA2935807C

Systems and methods for multi-factor remote user authentication

Abstract

This invention discloses a multi-factor remote user authentication card-device 12 in the form factor of a prior art one-factor of "what you have" security card. The multi-factor card-device has innovative features that enable this one card- device itself to function and accomplish a multi-factor remote user authentication of "what you know", "what you have", "where you are" and "what you are", to a network. This invention discloses four embodiments of the card-device 12. In one embodiment 10A, one card-device of this invention enables two-factor authentication of "what you have" and "what you are". In another embodiment 10B, one card-device 12 of this invention enables two-factor authentication of "what you know" and "what you have". In another embodiment 10C, one card-device 12 of this invention enables three-factor authentication of "what you know", "what you have", and "what you are". In yet another embodiment 10D, one card-device 12 of this invention enables four-factor authentication of "what you know", "what you have", "where you are", and "what you are". The authentication logic 51 dynamically facilitates the use of multi-factor authentication so that it dynamically adjusts what factors are applicable for specific security application enabling a universal remote authentication device. The authentication system provides additional means of security assurance that aid in authentication based on time and location.

CA2935807C, drawing sheet 1
Sheet 1 of 17

Term

Term ended

Expired 15 September 2026, 0 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

20 claims: 3 independent, 17 dependent

  1. 1
    CLAIMS:1. A remote user authentication system, comprising: a. an authentication server and an authentication database, the authentication database has fields that correspond to four separate factors of remote user authentication of, (i) what you have (ii) what you know, (iii) what you are, and (iv) where you are, identifying a plurality of GPS geographic locations of a remote user;b. an authentication logic operable in the server and the database, the logic receives and processes an authentication record transmitted from a card device of the remote user, wherein the authentication record has separate, four factors of authentication of what you know, what you have, what you are, and where you are, identifying a current GPS geographic location of the remote user, thereby, the remote user authentication system provides multiple factors of remote user authentication.
  2. 10
    An authentication database system, the system comprising:a. a database server with a CPU and a data storage and resident in the data storage and operating in the CPU an authentication database for use in a remote user authentication system;CA 2935807 2017-08-14 b. the database has fields for four separate factors of remote user authentication of, (i) what you have (ii) what you know, (iii) what you are, and (iv) where you are, identifying a plurality of GPS geographic locations of a remote user to authenticate an authentication record transmitted from a card device of the remote user including at least a current GPS geographic location of the remote user;c. the database has additional fields from a group of (i) a serial number as the authentication record identifier, (ii) remote user identification data, (iii) an account status, and (iv) a history of remote user accesses.
  3. 14
    A method for a remote user authentication system, comprising the steps of:a. maintaining an authentication server, an authentication database, and an authentication logic operable in the server and the database, wherein providing by the authentication database fields that correspond to four separate factors of remote user authentication of, (i) what you have (ii) what you know, (iii) what you are, and (iv) where you are, identifying a plurality of GPS geographic locations of a remote user;b. receiving and processing by the authentication logic an authentication record from a remote user, wherein having in the authentication record transmitted from a card device of the remote user separate, four factors of authentication of what you know, what you have, what you are, and where you are, identifying a current GPS geographic location of the remote user, thereby, providing by the remote user authentication system multiple factors of remote user authentication. CA 2935807 2017-08-14