Method and system for biometric identification and authentication having an exception mode
First Claim
Patent Images
1. A method of authenticating the identity of an enrolled user of a biometric authentication and/or identification system having a set of user modes including an exception mode, the method comprising:
- receiving a request from the enrolled user for switching a user mode of the enrolled user to the exception mode;
requesting identifying information from the enrolled user;
receiving the identifying information from the enrolled user;
verifying the enrolled user'"'"'s identity by determining if the identifying information received from the enrolled user matches identifying information of the enrolled user as stored in a user information database;
submitting to a template matching server a biometric template extracted from a biometric sample image of a biometric identifier of a person authorizing a switch in the enrolled user'"'"'s user mode to the exception mode;
if the template matching server finds a match between the biometric template of the person authorizing the switch in the enrolled user'"'"'s user mode to the exception mode and a pre-stored reference biometric template of the person authorizing the switch in the enrolled user'"'"'s user mode to the exception mode, switching the enrolled user'"'"'s user mode to the exception mode;
assigning to the user a temporary password having an expiration date;
storing the temporary password and said expiration date in the user information database;
setting a user exception mode authentication counter value stored in the user information database to a value corresponding to a number of allowed authentications with the temporary password;
transmitting the temporary password to the enrolled user by an out-of-band communication;
receiving a request from the enrolled user for access to a network application that requires biometric authentication;
sending a request for a user identification string previously assigned uniquely to the enrolled user and stored in the user information database and the temporary password;
receiving a user identification string from the enrolled user and a password from the enrolled user;
if the received user identification string matches the user identification string previously assigned uniquely to the enrolled user, the received password matches the temporary password, the temporary password has not expired, and the user exception mode authentication counter is greater than zero, authenticating the identity of the enrolled user;
decrementing the user exception mode authentication counter; and
if the template matching server finds a match between a biometric template extracted from a biometric image of a biometric identifier of the enrolled user in exception mode and a reference biometric template of the enrolled user, switching the enrolled user'"'"'s user mode.
1 Assignment
0 Petitions
Accused Products
Abstract
Embodiments of the invention provide methods and systems for authenticating an enrolled user of a biometric authentication and/or identification system having an exception mode, in which the enrolled user submits a temporary password during authentication. The temporary password is only generated if the enrolled user'"'"'s identity is verified and the person authorizing a change to the exception mode submits a valid biometric identifier.
-
Citations
10 Claims
-
1. A method of authenticating the identity of an enrolled user of a biometric authentication and/or identification system having a set of user modes including an exception mode, the method comprising:
-
receiving a request from the enrolled user for switching a user mode of the enrolled user to the exception mode; requesting identifying information from the enrolled user; receiving the identifying information from the enrolled user; verifying the enrolled user'"'"'s identity by determining if the identifying information received from the enrolled user matches identifying information of the enrolled user as stored in a user information database; submitting to a template matching server a biometric template extracted from a biometric sample image of a biometric identifier of a person authorizing a switch in the enrolled user'"'"'s user mode to the exception mode; if the template matching server finds a match between the biometric template of the person authorizing the switch in the enrolled user'"'"'s user mode to the exception mode and a pre-stored reference biometric template of the person authorizing the switch in the enrolled user'"'"'s user mode to the exception mode, switching the enrolled user'"'"'s user mode to the exception mode; assigning to the user a temporary password having an expiration date; storing the temporary password and said expiration date in the user information database; setting a user exception mode authentication counter value stored in the user information database to a value corresponding to a number of allowed authentications with the temporary password; transmitting the temporary password to the enrolled user by an out-of-band communication; receiving a request from the enrolled user for access to a network application that requires biometric authentication; sending a request for a user identification string previously assigned uniquely to the enrolled user and stored in the user information database and the temporary password; receiving a user identification string from the enrolled user and a password from the enrolled user; if the received user identification string matches the user identification string previously assigned uniquely to the enrolled user, the received password matches the temporary password, the temporary password has not expired, and the user exception mode authentication counter is greater than zero, authenticating the identity of the enrolled user; decrementing the user exception mode authentication counter; and if the template matching server finds a match between a biometric template extracted from a biometric image of a biometric identifier of the enrolled user in exception mode and a reference biometric template of the enrolled user, switching the enrolled user'"'"'s user mode. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A system for authenticating the identity of an enrolled user of a biometric authentication and/or identification system having a set of user modes including an exception mode, the system comprising:
-
one or more user information databases to store data records for all enrolled users, each data record including, but not limited to a uniquely assigned user identification string, a user mode indicator, a user exception mode authentication counter, reference biometric identifier templates for the enrolled user and a person authorizing a switch in a user mode of the enrolled user to the exception mode, information that identifies the enrolled user, and a temporary password having an expiration date and assigned exclusively to the enrolled user; a client device, operatively associated with the user information database, to receive a request for switching the enrolled user'"'"'s user mode to the exception mode sent from the enrolled user;
to request identifying information from the enrolled user;
to receive information sent by the enrolled user;
if the information sent by the enrolled user matches the information that identifies the enrolled user stored in the user information database, to verify the enrolled user'"'"'s identity;
to submit to a template matching server, a biometric template extracted from a biometric sample image of a biometric identifier of the person authorizing the switch in the enrolled user'"'"'s user mode to the exception mode;
if the template matching server finds a match between the submitted biometric template and the reference biometric template of the person authorizing the switch in the enrolled user'"'"'s authentication mode to the exception mode, to switch the enrolled user'"'"'s user mode to the exception mode;
to assign the temporary password to the user;
to store the temporary password and the expiration date in the user information database;
to set the user exception mode authentication counter value stored in the user information database to a value corresponding to the number of allowed authentications with the temporary password; and
to transmit the temporary password to the first client device by the out-of band communication; anda server, operatively associated with the user information database, to receive a request from the enrolled user for access to a network application that requires biometric authentication;
to receive, from the enrolled user, a user identification string and a password;
if the received user identification string matches the user identification string previously assigned uniquely to the enrolled user, the received password matches the temporary password, the temporary password has not expired, and the user exception mode authentication counter is greater than zero, to authenticate the identity of the enrolled user;
to decrement the user exception mode authentication counter by one; and
to, if the template matching server finds a match between a biometric template extracted from a biometric image of a biometric identifier of the enrolled user in exception mode and a reference biometric template of the enrolled user, switch the enrolled user'"'"'s user mode. - View Dependent Claims (8, 9, 10)
-
Specification