EP1925113A2

Systems and methods for multi-factor remote user authentication

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 15 September 2026, 0 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

26 claims: 26 independent, 0 dependent

  1. 1
    Claims of equivalent WO 2007035469 A2 CLAIMS What is claimed is:1. A remote user authentication device comprising: a. a hand-held card-device with an interface means and an embedded computer logic, wherein the logic and the interface means are used to interface the device to a network for a "what you have" factor of authentication;b. the device adapted with a thumbprint sensor on a part of the device for when the device is held, the thumb is naturally placed on the sensor, enabling capture of a thumbprint of a cardholder.
  2. 2
    The claim as in 1 , further comprising:the device is in the form of a flat card, with a topside, a bottom side a left edge and a right edge, wherein the interface is on the left edge, and the sensor is on the topside and near the right edge.
  3. 3
    The claim as in 1 , further comprising:the logic and the interface means transfer a card identification and the captured thumbprint to a network, wherein the thumbprint is for use as a "what you are" factor of authentication.
  4. 4
    The claim as in 3, further comprising:the logic adapted to begin thumbprint capture when card is interfaced with the network and not before and hold in the temporary memory of logic until the transfer to the network , whereby the device does not hold the thumbprint except for a brief moment in time.
  5. 5
    The claim as in 1 , further comprising:the device adapted with a radio clock sensor and mechanism chip that computes the time of device use and transfers such time as part of an authentication record via interface, to a network device, as a means of security assurance.
  6. 6
    A remote user authentication device comprising:a. a hand-held card-device with an interface means and an embedded computer logic, wherein the logic and the interface means are used to interface the device to a network for a "what you have" factor of authentication;b. the device adapted with an entry and display means and a logic that enable entry and display of a pin into a temporary memory of the logic, wherein the PIN is a "what you know" factor authentication.
  7. 7
    The claim as in 6, comprising:the logic and the interface means transfer a card identification and the PIN to the network, wherein the PIN is for use as a "what you know" factor of authentication.
  8. 8
    The claim as in 6, the entry means comprising:a plurality of electronic rotary switches that enable alphanumeric entry of the PIN without a keypad.
  9. 9
    The claim as in 6, further comprising:the logic embedded with a heuristic card-specific algorithm that transforms the temporary stored PIN to a temporary stored encryption key.
  10. 10
    The claim as in 9, the logic comprising:the logic uses this encryption key to encrypt the card identification and transfers the data anchored by a card serial number via the interface means to the network.
  11. 11
    A remote user authentication device comprising:a computer logic that (i) receives a PIN into a temporary memory, (ii) converts the PIN into an encryption key in temporary storage and deletes the PIN, (iii) using the key encrypts an authentication record and deletes the key, and (iv) transfers the encrypted record to a network device for authentication.
  12. 12
    The claim as in 11 , comprising:the logic uses a card specific algorithm to convert the PIN into a card-specific encryption key.
  13. 13
    A method of remote user authentication comprising the steps of:a. entering a PIN in a remote user authentication device;b. converting the PIN into an encryption key using a card-specific algorithm and then deleting the PIN;c. encrypting an authentication record using the key and then deleting the key;and d. transferring the encrypted record to a network device for forwarding the record by the network device to an authentication server.
  14. 14
    The claim as in 13, comprising the steps of:a. receiving the authentication record;b. recreating the encryption key from the PIN and the card specific algorithm pre-stored in an authentication database;c. decrypting the authentication record using the key;d. verifying the authentication record with pre-stored data.
  15. 15
    A remote user authentication device comprising:a. a hand-held card-device with an interface means and an embedded computer logic that provides a card serial number and encrypted card identification;b. the device adapted with an entry and display means and a logic that enables entry and display of a pin into a temporary memory of the logic for a limited time;c. the device adapted with a thumbprint sensor on a part of the device for when the device is held, the thumb is naturally placed on the sensor, enabling capture of a thumbprint of a cardholder in the temporary memory, wherein the logic and the interface means are used to interface the device to a network to provide it (i) a card identification for a "what you have" factor of authentication, (ii) the PIN for a "what you know" factor of authentication, and (iii) the thumbprint, for a "what you are" factor of authentication.
  16. 16
    The claim as in 15, further comprising:the device adapted with an embedded GPS chip enabling the location of the device to be used as an additional "where you are" factor of authentication.
  17. 17
    The claim as in 15, further comprising:the device adapted with a radio clock sensor and mechanism chip that computes the time of device use and transfers such time via the interface to a network, as an additional means of security assurance.
  18. 18
    The claim as in 15, further comprising:the device adapted with an RFID mechanism chip that identifies the device by a serial number, wherein the device may be tracked for location when entering and leaving controlled areas such as an airport.
  19. 19
    The claim as in 15, comprising:the interface means are from a group of, wired, optical, and short distance wireless.
  20. 20
    An authentication system comprising:a. an authentication server and an authentication database;b. an authentication logic that receives multiple factors of authentication on a network interface from a remote user and applies a weighted priority logic to the authentication factors, that enable dynamic multiple factors of authentication to be used for granting authentication to the remote user.
  21. 21
    The claim as in 20, the authentication database comprising:a. fields from a group that correspond to multiple factors of authentication of, (i) encrypted card id, (ii) PIN, (iii) thumbprint, (iv) a plurality of geographic locations in lat/long boundaries;b. fields from a group of (i) device serial number as a record identifier, (ii) remote user data, (iii) card status, and (iv) device-use log information.
  22. 22
    The claim as in 21 , the authentication database comprising:a field for heuristic card-specific algorithm for converting the PIN into an encryption key for decrypting the factors of authentication.
  23. 23
    The claim as in 20, the authentication database comprising:fields from a group that correspond to others aspects of authentication of, (i) calendar window, (ii) time window, (iii) weights for each of the factors;
  24. 24
    The claim as in 20, the system further comprising:an interface to the authentication system that enables an authorized person such as a field supervisor, to expand a calendar, or a time window, for field workers on a temporary basis.
  25. 25
    The claim as in 20, the system further comprising:an interface to the authentication system that enables an authorized person such as a field supervisor, to expand a geographic location for field workers on a temporary basis.
  26. 26
    The claim as in 20, the logic comprising:the logic is customized to a security application enabling different degrees of remote user authentication from multiple factors may be applied, wherein the authentication may be based on any two, or any three, or all four factors of authentication in a specific application.
Independent claims26