EP3122017B1

Systems and methods of authenticating and controlling access over customer data

Abstract

This record has no abstract on file.

EP3122017B1, drawing sheet 1
Sheet 1 of 7

Term

9.4 yearsleft in the term

Expires 26 February 2036.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

18 claims: 18 independent, 0 dependent

  1. 1
    A computer implemented method executed at least in part on a system (100), for authenticating and controlling access by a mobile agent to customer data stored on the system (100) comprising:receiving by a mobile application management module (211), a mobile agent login request from an agent device (105) and a customer authentication request from a customer device (103) using a pre-installed mobile application wherein unique identification data of the agent device (105) and the customer device (103) is pre-stored;receiving by a location match module (216), geo-spatial location of the agent device (105) and the customer device (103) and performing geo-spatial location match for the agent device (105) and the customer device (103);generating by a session key generator module (214), a session key which is valid for pre-determined duration of a meeting session and dividing the session key into two parts wherein one part is sent to the agent device (105) and other part to the customer device (103) wherein the session key is generated and sent only if location match is found between the agent device (105) and the customer device (103);entering the received parts of the session key into the agent device and the customer device (103) by the mobile agent and a customer respectively;retrieving, by a session key verification module, the entered session key by the customer and the mobile agent;comparing by the session key verification module (215), the entered session key with the generated session key by the session key generator module (214);comparing by an ID match module (217), the unique identification data of the agent device (105) and the customer device (103) stored with identification data of the agent device (105) and the customer device (103) used for entering the session key;and granting access by an access module (213) to mobile agent through agent device only if the location match, session key match and identification data match for the agent device (105) and the customer device (103) is found.
  2. 2
    The method of claim-1, wherein the session key is valid for the meeting session scheduled for a pre-determined duration between the mobile agent and the customer.
  3. 3
    The method of claim-1, wherein the generated session key is alphanumeric or alphabetical string.
  4. 4
    The method of claim-1, wherein the generated session key is an even numbered string or an odd numbered string.
  5. 5
    The method of claim-1, wherein the generated session key is divided into two equal halves.
  6. 6
    The method of claim-1, wherein the generated session key is divided into two unequal halves.
  7. 7
    The method of claim-1, wherein the identification data registered on remote server includes IMEI, international mobile equipment identity number, SIM number and IMSI number for the agent device (105) and the customer device (103).
  8. 8
    The method of claim-1, wherein failure of location match between the agent device (105) and the customer device (103) leads to denial of access of mobile agent to customer data.
  9. 9
    The method of claim-1, wherein failure of identification data match of the agent device (105) stored on remote server with the agent device (105) used for entering part of session key leads to denial of access of mobile agent to customer data.
  10. 10
    The method of claim-1, wherein failure of identification data match of customer device (103) stored on remote server with the customer device (103) used for entering part of session key leads to denial of access of mobile agent to customer data.
  11. 11
    The method of claim-1, additional comprising:receiving by the location match module (216), geo-spatial location of the agent device (105) and the customer device (103) during pendency of meeting session;in response to receiving, conducting geo-spatial location match of the agent device (105) and the customer device (103) by a location match module (216) during pendency of meeting session;and continuing the access of mobile agent to customer data by the access module (213) only if the location match is found.
  12. 12
    The method of claim-11, wherein the location match during pendency of meeting session is conducted over pre-determined intervals of time.
  13. 13
    The method of claim-11, wherein the access of mobile agent to customer data is revoked if the location match is not found.
  14. 14
    The method of claim-1, additionally comprising:receiving, a prompt on the customer device (103), an indication of meeting session nearing expiration of duration;receiving an extension request by the access module (213) sent through the customer device (103);receiving in response an acceptance of extension request on the access module (213) by the mobile agent through the agent device (105);receiving over a location match module (216), geospatial location of the agent device (105) and the customer device (103) and conducting a geo-spatial location match for the agent device and the customer device (103);and granting continued access during extended meeting session by access module (213) to the mobile agent only if the location match is found.
  15. 15
    The method of claim-14, wherein the access of mobile agent to customer data is revoked after expiration of meeting session.
  16. 16
    The method of claim-14, wherein the access of mobile agent to customer data is revoked if location match is not found during extended meeting session.
  17. 17
    A system for authenticating and controlling access by a mobile agent to customer data stored on the system 100 comprising:a memory storing instructions;a processor coupled to the memory to;receive by a mobile application management module (211), a mobile agent login request from an agent device and a customer authentication request from a customer device (103) using a pre-installed mobile application wherein unique identification data of the agent device and the customer device (103) is pre-stored;receive by a location match module (216), geo-spatial location of the agent device and the customer device (103) and performing geo-spatial location match for the agent device and the customer device (103);generating by a session key generator module (214), a session key which is valid for pre-determined duration of a meeting session and dividing the session key into two parts wherein one part is sent to the agent device (105) and other part to the customer device (103) wherein the session key is generated and sent only if location match is found between the agent device and the customer device (103);entering the received parts of the session key into the agent device and the customer device by the mobile agent and a customer respectively;retrieving, by a session key verification module (215), the entered session key by the customer and the mobile agent;and comparing by the session key verification module (215), the entered session key with the generated session key by the session key generator module (214);comparing by an ID match module (217), the unique identification data of agent device and customer device stored with identification data of agent device and customer device used for entering the session key;and granting access by an access module (213) to mobile agent through agent device only if the location match, session key match and identification data match for the agent device and customer device is found.
  18. 18
    A computer program product, when executed on a computer, for authenticating and controlling access by a mobile agent to customer data stored on a system (100), the computer program product comprising a non-transitory computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions comprising:a first executable portion for receiving a mobile agent login request and a customer authentication request from a customer device using a pre-installed mobile application wherein a unique identification data of an agent device and a customer device is pre-stored;a second executable portion for receiving geo-spatial location of the agent device and the customer device and performing a geo-spatial location match between the agent device and the customer device;a third executable portion for generating a session key which is valid for pre-determined duration of a meeting session and dividing the session key into two parts, wherein one part is sent to the agent device (105) and another part is sent to the customer device (103) wherein the session key is generated and sent only if location match is found between the agent device (105) and customer device (103) ;a fourth executable portion for entering the received parts of the session key into the agent device (105) and the customer device (103) by the mobile agent and a customer respectively;a fifth executable portion for retrieving by a session key verification module (215), the entered session key by the customer and the mobile agent;;a sixth executable portion for comparing, by the session key verification module (215), the entered session key with the generated session key by the session key generator module (214) ;. a seventh executable portion for comparing, by an ID match module (217), the unique identification data of agent device (105) and the customer device (103) stored with identification data of the agent device (105) and the customer device (103) used for entering the session key;and an eight executable portion for granting access by an access module (213) to the mobile agent through the agent device (105) if location match, session key match, identification data match for the agent device (105) and the customer device (103) is found.