Access Control Through Multifactor Authentication with Multimodal Biometrics
First Claim
1. A method of authenticating a user of a computing device as an enrolled user of the computing device during a transaction, the method comprising:
- i. determining whether the computing device is associated with the enrolled user;
ii. determining whether the user exhibits knowledge of a predetermined fact;
iii. determining the identity of the user based on at least one biometric challenge; and
iv. determining whether the user is a live person based on at least one liveness challenge.
0 Assignments
0 Petitions
Accused Products
Abstract
A system is provided in which a person may use a Cellular (Mobile) Telephone, a PDA or any other handheld computer to make a purchase. This is an example only. The process may entail any type of transaction which requires authentication, such as any financial transaction, any access control (to account information, etc.), and any physical access scenario such as doubling for a passport or an access key to a restricted area (office, vault, etc.). It may also be used to conduct remote transactions such as those conducted on the Internet (E-Commerce, account access, etc.). In the process, a multifactor authentication is used.
-
Citations
44 Claims
-
1. A method of authenticating a user of a computing device as an enrolled user of the computing device during a transaction, the method comprising:
-
i. determining whether the computing device is associated with the enrolled user; ii. determining whether the user exhibits knowledge of a predetermined fact; iii. determining the identity of the user based on at least one biometric challenge; and iv. determining whether the user is a live person based on at least one liveness challenge. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26)
-
-
27. A transaction processing method comprising:
-
i) registering authentication software that executes on a computing device of an enrolled user with a certificate authority, thereby generating software certificate reference data; ii) registering the software certificate reference data in association with the enrolled user with a transaction authority; and iiii) communicating with the transaction authority to validate that the software certificate reference data associated with the authentication software that executes on the computing device matches the software certificate reference data stored by the transaction authority in order to authenticate a user of the computing device as the enrolled user and selectively process a transaction via operation of the computing device of the enrolled user. - View Dependent Claims (28, 29, 30, 31, 32, 33, 34, 35)
-
-
36. A method of controlling access to a physical location by operation of a computing device whose execution provides a physical access control interface, the method comprising:
configuring the physical access control interface to selectively grant access to the physical location based a number of operations, including i. determining whether a user of the physical access control interface exhibits knowledge of a predetermined fact, ii. determining the identity of the user of the physical access control interface based on at least one biometric challenge, and iii. determining whether the user of the physical access control interface is a live person based on at least one liveness challenge. - View Dependent Claims (37, 38, 39, 40)
-
41. A method of controlling access to personal health data of an enrolled user stored on a computing device, the method comprising:
-
i. determining whether the computing device is associated with the enrolled user; ii. determining whether a user of the computing device exhibits knowledge of a predetermined fact; iii. determining the identity of the user of the computing device based on at least one biometric challenge; and iv. determining whether the user of the computing device is a live person based on at least one liveness challenge. - View Dependent Claims (42, 43, 44)
-
Specification