Data access control using multi-device multifactor authentication

US10853467B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10853467-B2
Application numberUS-201815938516-A
CountryUS
Kind codeB2
Filing dateMar 28, 2018
Priority dateMar 28, 2018
Publication dateDec 1, 2020
Grant dateDec 1, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An authentication device that includes an authentication engine configured to detect devices proximate to a terminal and to identify a user profile based on the detected one or more devices. The user profile identifies at least one of the detected devices in a device registry. The authentication engine is further configured to receive a data access request for a data resource and to identify authentication requirements for a multifactor authentication process for the user based on the detected devices. Identifying the authentication requirements includes setting types of authentication and a number of authentication levels that are used for performing multifactor authentication with the user. The authentication engine is further configured to execute the multifactor authentication process for the user, to determine whether the user has satisfied the authentication requirements, and to provide access to the data resource in response to determining the user has satisfied the authentication requirements.

First claim

Opening claim text (preview).

The invention claimed is: 1. An authentication device, comprising: a memory configured to store a plurality of user profiles, wherein each user profile comprises: a device registry identifying registered devices linked with a user; authentication requirements for the user, wherein the authentication requirements vary based on detected devices from the device registry; an input/output (I/O) interface configured to detect devices using a wireless communication protocol; an authentication engine implemented by one or more processors operably coupled to the memory and the I/O interface, configured to: detect one or more devices; identify a user profile based on the detected one or more devices, wherein identifying the user profile comprises determining at least one of the one or more devices is listed in a device registry of the user profile; receive a data access request for a data resource, wherein the data access request identifies a user linked with the user profile; identify authentication requirements for a multifactor authentication process for the user based on the detected one or more devices, wherein identifying the authentication requirements comprises: setting types of authentication that are used for performing multifactor authentication with the user, wherein setting the types of authentication identifies types of information that will be used for authentication; and setting a number of authentication levels that are used for performing multifactor authentication with the user, wherein setting the number of authentication levels identifies how many types of information that will be used for authentication; execute the multifactor authentication process for the user; determine whether the user has satisfied the authentication requirements; provide access to the data resource in response to determining the user has satisfied the authentication requirements. 2. The device of claim 1 , wherein the data access request is sent by a device listed in the device registry. 3. The device of claim 1 , further comprising a user interface, wherein the data access request is generated in response to the user interacting with the user interface. 4. The device of claim 1 , wherein detecting the one or more devices comprises detecting at least one wearable device. 5. The device of claim 1 , wherein detecting the one or more devices comprises detecting: a mobile user device; and at least one wearable device. 6. The device of claim 1 , wherein: the user profile comprises a stored behavioral profile comprising a first biometric signal for the user; and determining whether the user has satisfied the authentication requirements comprises: receiving a new behavioral profile from one of the detected devices, wherein the new behavior profile comprises a second biometric signal for the user; comparing first biometric signal for the user to the second biometric signal for the user; determining the first biometric signal matches the second biometric signal based on the comparison; and determining the user satisfies the authentication requirements in response to determining the first biometric signal matches the second biometric signal. 7. The device of claim 1 , wherein: the user profile comprises a behavioral profile identifying locations associated with the user; and determining the user has satisfied the authentication requirements comprises: determining the current location of the user; comparing the current location of the user to the locations associated with the user; determining whether the current location matches one of the locations associated with the user; and determining the user satisfies the authentication requirements in response to determining the current location matches one of the locations associated with the user. 8. A multifactor authentication method, comprising: detecting, by an authentication engine, one or more devices proximate to a terminal; identifying, by the authentication engine, a user profile based on the detected one or more devices, wherein: the user profile comprises: a device registry identifying registered devices linked with a user; authentication requirements for the user, wherein the authentication requirements vary based on detected devices from the device registry; and identifying the user profile comprises determining at least one of the detected one or more devices is listed in the device registry of the user profile; receiving, by the authentication engine, a data access request for a data resource, wherein the data access request identifies the user linked with the user profile; identifying, by the authentication engine, authentication requirements for a multifactor authentication process for the user based on the detected one or more devices, wherein identifying the authentication requirements comprises: setting types of authentication that are used for performing multifactor authentication with the user, wherein setting the types of authentication identifies types of information that will be used for authentication; and setting a number of authentication levels that are used for performing multifactor authentication with the user, wherein setting the number of authentication levels identifies how many types of information that will be used for authentication; executing, by the authentication engine, the multifactor authentication process for the user; determining, by the authentication engine, whether the user has satisfied the authentication requirements; providing, by the authentication engine, access to the data resource in response to determining the user has satisfied the authentication requirements. 9. The method of claim 8 , wherein the data access request is sent by a device listed in the device registry. 10. The method of claim 8 , wherein the data access request is generated in response to the user interacting with a user interface of the terminal. 11. The method of claim 8 , wherein detecting the one or more devices proximate to the terminal comprises detecting at least one wearable device. 12. The method of claim 8 , wherein detecting the one or more devices proximate to the terminal comprises detecting: a mobile user device; and at least one wearable device. 13. The method of claim 8 , wherein: the user profile comprises a behavioral profile identifying locations associated with the user; and determining whether the user has satisfied the authentication requirements comprises: determining the current location of the user; comparing the current location of the user to the locations associated with the user; determining the current location matches one of the locations associated with the user; and determining the user satisfies the authentication requirements in response to determining the current location matches one of the locations associated with the user. 14. The method of claim 8 , wherein: the user profile comprises a stored behavioral profile comprising a first biometric signal for the user; and determining whether the user has satisfied the authentication requirements comprises: receiving a new behavioral profile from one of the detected devices, wherein the new behavior profile comprises a second biometric signal for the user; comparing first biometric signal for the user to the second biometric signal for the user; determining the first biometric signal matches the second biometric signal based on the comparison; and determining the user satisfies the authentication requirements in response to determining the first biometric signal matches the second biometric signal.

Assignees

Inventors

Classifications

  • G06F21/32Primary

    using biometric data, e.g. fingerprints, iris scans or voiceprints · CPC title

  • Wearable computers, e.g. on a belt · CPC title

  • G06F21/34Primary

    involving the use of external additional devices, e.g. dongles or smart cards · CPC title

  • where the program performs an interfacing function, e.g. device driver (G06F13/105 takes precedence; contention policies within device drivers G06F9/4881; scheduling within device drivers G06F9/52) · CPC title

  • communicating wirelessly · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10853467B2 cover?
An authentication device that includes an authentication engine configured to detect devices proximate to a terminal and to identify a user profile based on the detected one or more devices. The user profile identifies at least one of the detected devices in a device registry. The authentication engine is further configured to receive a data access request for a data resource and to identify au…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification G06F21/32. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 01 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).