×

Method for adaptive authentication using a mobile device

DC
  • US 8,646,060 B1
  • Filed: 07/30/2013
  • Issued: 02/04/2014
  • Est. Priority Date: 07/30/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method for adaptive authentication comprising:

  • initiating a transaction onboard a first terminal,whereby the first terminal obtains a user identifier using a method selected from the group consisting of;

    wireless scan of a user'"'"'s device,scan a bar code,obtain an identifier from a user,obtain an identifier from memory,obtain an identifier from a database, anduser profiling,wherein the first terminal posts an authentication request to a remote server,wherein the authentication request corresponds to a user identifier,wherein the authentication request comprises at least one transaction information item,wherein the first terminal can obtain policy information from a remote server,wherein the first terminal is selected from the group consisting of;

    a mobile device, a computing device, a television set, a point of sale terminal, and a physical access terminal;

    running an authentication program onboard a first mobile device,wherein the authentication program corresponds to the user identifier,wherein the authentication program can login to the remote server,wherein the authentication program stores at least one first digital key selected from the group consisting of;

    a password, a random key, a one-time-password generator, a certificate, a Private Key Infrastructure (PKI) key, a symmetric key, an asymmetric key, payment information, access information, and physical access code,wherein the at least one first digital key can be stored in a secure memory location or on a secure element onboard the first mobile device,wherein the first mobile device is distinct from the first terminal,wherein upon detecting a user action onboard the first mobile device,wherein the user action is selected from the group consisting of;

    a button push, a display touch, a motion, a spoken word, and an application brought to the foreground,if the authentication program obtains a pending authentication request wirelessly from the remote server,wherein the pending authentication request corresponds to the user identifier,the authentication program can display the at least one transaction information,the authentication program initiates a user authentication action onboard the first mobile device and uses a user authentication method selected from the group consisting of;

    verify a button is activated or a menu is selected or a display is touched or an application is brought to the foreground,authenticate a pass code,authenticate a response to a challenge question,and authenticate biometric information,wherein the user authentication method is different from a previously used user authentication method,wherein upon or after a successful user authentication,the authentication program posts an authentication information update to the remote server, 

    wherein the authentication information update corresponds to the pending authentication request, 

    wherein the authentication information update comprises the at least one first digital key or at least one second digital key corresponding to the at least one first digital key;

    whereby after a pre-determined period of time,if the first terminal retrieves an authentication information update corresponding to the authentication request,the first terminal uses the authentication information update to perform an action selected from the group consisting of;

    unlock, uncloak, decrypt data, login to an application, authenticate to a remote server, authorize a second transaction, transmit user information wirelessly to a separate terminal, login automatically to an application interface, and call a script.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×