Event driven second factor credential authentication
US-9769161-B2 · Sep 19, 2017 · US
US11089012B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11089012-B2 |
| Application number | US-201715706937-A |
| Country | US |
| Kind code | B2 |
| Filing date | Sep 18, 2017 |
| Priority date | Jul 12, 2011 |
| Publication date | Aug 10, 2021 |
| Grant date | Aug 10, 2021 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A reader configured to perform dual-factor authentication is provided. The reader is configured to analyze credential data as well as event-based user inputs. The event-based user inputs are received in response to the reader presenting one or more events to a user and monitoring the user's reaction thereto. Utilization of an event-based user input enables the reader to perform dual-factor authentication without necessarily being provided with a keyboard or other advanced user input device.
Opening claim text (preview).
What is claimed is: 1. A method comprising: detecting, at a reader, event-based user input responsive to a sequence of events controlled by the reader, the event-based user input comprising a plurality of user input events occurring during the sequence of events controlled by the reader, wherein for each of the plurality of user input events, a time during the sequence of events at which such user input event is detected identifies a value of a multi-digit PIN; analyzing the event-based user input; and based on the analysis of the event-based user input, determining whether a user that provided the user input is allowed access to an asset protected by the reader; wherein the plurality of user input events are detected by monitoring an amount of time that a credential is selectively presented and not presented to the reader during presentation of the sequence of events controlled by the reader. 2. The method of claim 1 , further comprising: receiving, at the reader, at least a portion of credential data from the credential; analyzing the credential data; and upon determining that the credential data and the event-based user input are both valid, permitting the user access to the asset protected by the reader. 3. The method of claim 2 , wherein the credential data is split across a plurality of credentials and wherein the credential data is determined to be valid when each of the plurality of credentials are presented. 4. The method of claim 1 , wherein the sequence of events controlled by the reader comprises at least one of flashing a light and beeping a buzzer a predetermined number of times. 5. The method of claim 1 , wherein the sequence of events controlled by the reader comprises sequentially displaying numbers in a random or pseudo random order. 6. A reader comprising: a user interface configured to present a sequence of events to a user; and an authentication module coupled to the user interface such that inputs received at the user interface are received at the authentication module thereby enabling the authentication module to monitor user reaction to the sequence of events and, based on the user reaction, determine whether the user has provided a valid event-based user input, wherein the event-based user input comprises a plurality of user input events occurring during the sequence of events controlled by the reader, wherein for each of the plurality of user input events, a time during the sequence of events at which such user input event is detected identifies a value of a multi-digit PIN; wherein the plurality of user input events are detected by monitoring an amount of time that a credential is selectively presented and not presented to the reader during presentation of the sequence of events controlled by the reader. 7. The reader of claim 6 , wherein the user interface does not include a user input device. 8. The reader of claim 6 , wherein the user interface comprises at least one Light Emitting Diode (LED). 9. The reader of claim 6 , wherein the user interface comprises at least one of a buzzer and speaker. 10. The reader of claim 6 , wherein the authentication module is configured to determine whether the credential is within a read range of the reader as a part of the monitoring. 11. The reader of claim 10 , wherein the reader is further configured to retrieve credential data from the credential presented by the user. 12. The reader of claim 11 , wherein the reader is configured to forward the credential data to a networked device for analysis only in response to the authentication module determining that the event-based user input is valid. 13. An access control system comprising: a reader comprising a user interface configured to present a sequence of events to a user and an authentication module coupled with the user interface such that inputs received at the user interface are provided to the authentication module and enable the authentication module to monitor user reaction to the sequence of events and, based on the user reaction, determine whether the user has provided a valid event-based user input, wherein the event-based user input comprises a plurality of user input events occurring during the sequence of events controlled by the reader, wherein for each of the plurality of user input events, a time during the sequence of events at which such user input event is detected identifies a value of a multi-digit PIN; and a plurality of credentials, each credential comprising credential data stored thereon and being configured to communicate its credential data to the reader; wherein the plurality of user input events are detected by monitoring an amount of time that a given one of the plurality of credentials is selectively presented and not presented to the reader during presentation of the sequence of events controlled by the reader. 14. The system of claim 13 , wherein each of the plurality of credentials has a different event-based user input associated therewith. 15. The system of claim 13 , wherein the valid event-based user input is encoded on the plurality of credentials. 16. The system of claim 13 , wherein a single event-based user input is valid for at least two different credentials. 17. The system of claim 13 , wherein the reader is configured to forward the credential data to a networked device for analysis only in response to the authentication module determining that the event-based user input is valid.
With time considerations, e.g. temporary activation, valid time window or time limitations · CPC title
in combination with an identity check of the pass holder · CPC title
using a predetermined code, e.g. password, passphrase or PIN (network architectures or network communication protocols for supporting authentication of entities using passwords in a packet data network H04L63/083) · CPC title
applying multi-factor authentication · CPC title
Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.