EP3365827B1

End user initiated access server authenticity check

Abstract

This record has no abstract on file.

EP3365827B1, drawing sheet 1
Sheet 1 of 12

Term

9.5 yearsleft in the term

Expires 31 March 2036.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

15 claims: 8 independent, 7 dependent

  1. 1
    A method comprising:receiving (506), by a computing system of an access management system, from a computing device operated by a user, a validation request to authenticate the access management system, the validation request including user identification information associated with the user;sending (510), by the computing system, to a destination associated with the user based on the user identification information, first temporary access information for the user to authenticate the access management system;receiving (512), by the computing system, from the computing device, a first response including second temporary access information;upon determining (514) that the second temporary access information received in the first response matches the first temporary access information, sending (516), by the computing system, personal information about the user to the computing device;receiving (518), from the computing device, a second response, wherein the second response indicates a confirmation by the user of the personal information sent to the computing device, wherein the second response includes credential data of the user, wherein the second response is separate from the first response, and wherein the first response does not comprise the credential data;and determining (510), by the computing system, authentication of the user to access a resource from the computing device, wherein the authentication of the user is determined based on the credential data and the confirmation of the personal information received in the second response.
  2. 5
    The method of claim any one of claims 1 to 4, further comprising:determining that the user identification information is associated with the user;and identifying the destination based on the user identification information.
  3. 6
    The method of any one of claims 1 to 5, wherein the first temporary access information and the second temporary access information are associated with a time period, wherein determining that the second temporary access information matches the first temporary access information includes determining a response time is within the time period, and wherein the response time is based on a time for receiving the first response after the first temporary access information is sent to the computing device.
  4. 7
    The method of claim any one of claims 1 to 6, further comprising:upon determining that the second temporary access information received in the first response matches the first temporary access information, generating the personal information before sending the personal information.
  5. 9
    An access management system comprising:one or more processors;and a memory coupled with and readable by the one or more processors, the memory storing a set of instructions that, when executed by the one or more processors, causes the one or more processors to: receive (506), from a computing device operated by a user, a validation request to authenticate the access management system, the validation request including user identification information associated with the user;send (510), to a destination associated with the user based on the user identification information, first temporary access information for the user to authenticate the access management system;receive (512), from the computing device, a first response including second temporary access information;upon determining (514) that the second temporary access information received in the first response matches the first temporary access information, send (516) personal information about the user to the computing device;receive (518), from the computing device, a second response, wherein the second response indicates a confirmation by the user of the personal information sent to the computing device, wherein the second response includes credential data of the user, wherein the second response is separate from the first response, and wherein the first response does not comprise the credential data;and determine (520) authentication of the user to access a resource from the computing device, wherein the authentication of the user is determined based on the credential data and the confirmation of the personal information received in the second response.
  6. 12
    The access management system of any one of claims 9 to 11, wherein the set of instructions, when executed by the one or more processors, further causes the one or more processors to:determine that the user identification information is associated with the user;and identify the destination based on the user identification information.
  7. 13
    The access management system of any one of claims 9 to 12, wherein the first temporary access information and the second temporary access information are associated with a time period, wherein determining that the second temporary access information matches the first temporary access information includes determining a response time is within the time period, and wherein the response time is based on a time for receiving the first response after the first temporary access information is sent to the computing device.
  8. 14
    The access management system of any one of claims 9 to 13, wherein the set of instructions, when executed by the one or more processors, further causes the one or more processors to:upon determining that the second temporary access information received in the first response matches the first temporary access information, generate the personal information before sending the personal information, wherein the personal information includes financial information about the user determined after the second temporary access information is determined to match the first temporary access information.
  9. 15
    A non-transitory computer-readable medium storing a set of instructions that, when executed by one or more processors, causes the one or more processors to carry out the method of any of claims 1 to 8.