Multi-factor authentication to achieve required authentication assurance level
US-2016087957-A1 · Mar 24, 2016 · US
US10032008B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10032008-B2 |
| Application number | US-201414523679-A |
| Country | US |
| Kind code | B2 |
| Filing date | Oct 24, 2014 |
| Priority date | Feb 23, 2014 |
| Publication date | Jul 24, 2018 |
| Grant date | Jul 24, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A mobile device may perform authentication with an authenticating entity. The mobile device may comprise a plurality of sensors and a processor. The processor may be configured to: receive an authentication request from the authenticating entity requesting authentication information; and determine if the authentication request satisfies predefined user privacy preferences. If so, the processor may be configured to: retrieve the authentication information from at least one sensor to form a trust vector in response to the authentication request and to command transmission of the trust vector to the authenticating entity for authentication.
Opening claim text (preview).
What is claimed is: 1. A mobile device comprising: a transceiver; a plurality of sensors; and a processor configured to: transmit a request for a transaction to an authenticating entity through the transceiver; receive an authentication request from an authenticating entity requesting authentication information through the transceiver; determine if the authentication request satisfies predefined user privacy preferences, wherein the user privacy preferences are predefined based on the authenticating entity and the transaction, and, if so: retrieve the authentication information from at least one sensor to form a trust vector in response to the authentication request; and transmit the trust vector to the authenticating entity for authentication, wherein if the authentication request does not satisfy the predefined user privacy preferences based upon types of user-approved device specific sensor data and types of 1) biometric sensor information, and/or 2) data input, a trust broker to negotiate with the authenticating entity to determine the trust vector that satisfies the predefined user privacy preferences and the authentication requirements for the authenticating entity, and the trust broker to transmit the negotiated trust vector to the authenticating entity through the transceiver. 2. The mobile device of claim 1 , wherein the trust broker determines at least one sensor data score, biometric sensor information score, or data input score for inclusion in the trust vector. 3. The mobile device of claim 1 , wherein the trust vector includes a multi-field data message including at least one of sensor data, biometric sensor information, data input, a sensor data score, a biometric sensor information score, a data input score, a trust coefficient, a trust score, a credential, an authentication coefficient, an authentication score, an authentication level, an authentication system output, or authentication information to satisfy the authentication request. 4. The mobile device of claim 1 , wherein one or more components of the trust vector are updated to provide continuous authentication. 5. A method to perform authentication with an authenticating entity comprising: transmitting a request for a transaction to the authenticating entity through a transceiver; receiving an authentication request from the authenticating entity requesting authentication information through the transceiver; determining if the authentication request satisfies predefined user privacy preferences, wherein the user privacy preferences are predefined based on the authenticating entity and the transaction, and, if so: retrieving the authentication information to form a trust vector in response to the authentication request; and transmitting the trust vector to the authenticating entity for authentication, wherein if the authentication request does not satisfy the predefined user privacy preferences based upon types of user-approved device specific sensor data and types of 1) biometric sensor information, and/or 2) data input, a trust broker to negotiate with the authenticating entity to determine the trust vector that satisfies the predefined user privacy preferences and the authentication requirements for the authenticating entity, and the trust broker to transmit the negotiated trust vector to the authenticating entity through the transceiver. 6. The method of claim 5 , further comprising determining at least one sensor data score, biometric sensor information score, or data input score for inclusion in the trust vector. 7. The method of claim 5 , wherein the trust vector includes a multi-field data message including at least one of sensor data, biometric sensor information, data input, a sensor data score, a biometric sensor information score, a data input score, a trust coefficient, a trust score, a credential, an authentication coefficient, an authentication score, an authentication level, an authentication system output, or authentication information to satisfy the authentication request. 8. The method of claim 5 , further comprising updating the trust vector to provide continuous authentication. 9. A non-transitory computer-readable medium including code that, when executed by a processor, causes the processor to: transmit a request for a transaction to an authenticating entity through a transceiver; receive an authentication request from an authenticating entity requesting authentication information through the transceiver; determine if the authentication request satisfies predefined user privacy preferences, wherein the user privacy preferences are predefined based on the authenticating entity and the transaction, and, if so: retrieve the authentication information to form a trust vector in response to the authentication request; and transmit the trust vector to the authenticating entity for authentication, wherein if the authentication request does not satisfy the predefined user privacy preferences based upon types of user-approved device specific sensor data and types of 1) biometric sensor information, and/or 2) data input, a trust broker to negotiate with the authenticating entity to determine the trust vector that satisfies the predefined user privacy preferences and the authentication requirements for the authenticating entity, and the trust broker to transmit the negotiated trust vector to the authenticating entity through the transceiver. 10. The computer-readable medium of claim 9 , further comprising code to determine at least one sensor data score, biometric sensor information score, or data input score for inclusion in the trust vector. 11. The computer-readable medium of claim 9 , wherein the trust vector includes a multi-field data message including at least one of sensor data, biometric sensor information, data input, a sensor data score, a biometric sensor information score, a data input score, a trust coefficient, a trust score, a credential, an authentication coefficient, an authentication score, an authentication level, an authentication system output, or authentication information to satisfy the authentication request. 12. The computer-readable medium of claim 9 , further comprising code to update the trust vector to provide continuous authentication. 13. A mobile device comprising: means for transmitting a request for a transaction to an authenticating entity; means for receiving an authentication request from an authenticating entity requesting authentication information; means for determining if the authentication request satisfies predefined user privacy preferences, wherein the user privacy preferences are predefined based on the authenticating entity and the transaction, and, if so: means for retrieving the authentication information to form a trust vector in response to the authentication request; and means for transmitting the trust vector to the authenticating entity for authentication, wherein, if the authentication request does not satisfy the predefined user privacy preferences based upon types of user-approved device specific sensor data and types of 1) biometric sensor information, and/or 2) data input, utilizing means for negotiating with the authenticating entity to determine the trust vector that satisfies the predefined user privacy preferences and the authentication requirements for the authenticating entity, and utilizing the means for transmitting the negotiated trust vector to the authenticating entity. 14. The mobile device of claim 13 , further comprising means for determining at least one sensor data score, biometric sensor information score, or data input score for inclusion in the trust vecto
using biometrical features, e.g. fingerprint, retina-scan (cryptographic mechanisms or cryptographic arrangements for entity authentication using biological data H04L9/3231) · CPC title
Recurrent verification · CPC title
User authentication · CPC title
applying multi-factor authentication · CPC title
by quorum, i.e. whereby two or more security principals are required · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.