Multifactor authentication for secure management of data center assets from a mobile device
US-2020236116-A1 · Jul 23, 2020 · US
US11711699B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11711699-B2 |
| Application number | US-202217584223-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jan 25, 2022 |
| Priority date | Apr 13, 2020 |
| Publication date | Jul 25, 2023 |
| Grant date | Jul 25, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A provider system is connected to readers disposed at distances from the provider system. A secure local connection is established between the client device and the provider system via one of the readers. Before the client reaches an access touchpoint, the provider system receives from the client device a request for client access, the provider system sends to the client device a request for identification information of the client, and the client device sends client information associated with a first mobile identification credential (MIC) which the client device received from an authorizing party system (APS), the client having consented to release the client information to the provider system, and the client information having been verified. The provider system uses the verified client information associated with the first MIC to verify or not verify the identity of the client before granting or denying the request to the client.
Opening claim text (preview).
What is claimed is: 1. A method for a client having a client device to request client access from a provider having a provider system, the method comprising: connecting the provider system to a plurality of readers disposed at distances from an access touchpoint and from each other; establishing a secure local connection between the client device and the provider system via a reader of the plurality of readers, before the client and the client device reach the access touchpoint; receiving, by the provider system from the client device, a request for client access before the client and the client device reach the access touchpoint; sending, by the provider system to the client device, a request for identification information of the client before the client and the client device reach the access touchpoint; receiving, by the provider system before the client and the client device reach the access touchpoint, part or all of client information included in a first mobile identification credential (MIC) which the client device received from a first authorizing party system (APS), the part or all of user information including the identification information of the client, the client having consented to release the part or all of client information to the provider system, and the part or all of client information having been verified by the first APS; using, by the provider system, the verified part or all of client information included in the first MIC to verify or not verify an identity of the client; and verifying the identity of the client, by the provider system, before granting the client the request for client access. 2. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from the client device before the client and the client device reach the access touchpoint, a token specifying the part or all of client information which the client has consented to release to the provider system; sending, by the provider system to the first APS, the received token, which is to be verified by the first APS with another token sent from the client device to the first APS; when the tokens are received by the first APS within a preset timeframe and are verified by the first APS, receiving, by the provider system from the first APS, the verified part or all of client information; and when the tokens are not received by the first APS within the preset timeframe or are not verified by the first APS, receiving, by the provider system from the first APS, a notification to resubmit the request for identification information of the client. 3. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from the client device before the client and the client device reach the access touchpoint, an electronic document specifying the part or all of client information which the client has consented to release to the provider system; sending, by the provider system to the first APS, the received electronic document; when the received electronic document is verified by the first APS, receiving, by the provider system from the first APS, the verified part or all of client information; and when the received electronic document is not verified by the first APS, receiving, from the provider system from the first APS, a notification to resubmit the request for identification information of the client. 4. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from client device before the client and the client device reach the access touchpoint, an electronic document and the part or all of client information which the client has consented to release to the provider system; sending, by the provider system to the first APS, the received electronic document; when the received electronic document is verified by the first APS, receiving, by the provider system from the first APS, an authentication key to verify the part or all of client information received from the client device; and when the received electronic document is not verified by the first APS, receiving, by the provider system from the first APS, a notification to resubmit the request for identification information of the client. 5. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from the client device before the client and the client device reach the access touchpoint, the part or all of client information which the client has consented to release to the provider system; and receiving, by the provider system from the first APS, an authentication key to verify the part or all of client information received from the client device, based on a request sent from the client device to the first APS. 6. The method of claim 1 , further comprising: performing a liveness check of the client using live-captured client information at the access touchpoint and determining whether the liveness check is valid or invalid; granting the request from the client, by the provider system, to provide the client access when the identity of the client is verified and when the liveness check is valid; and denying the request from the client, by the provider system, to provide the client access when the identity of the client is not verified or when the liveness check is invalid. 7. The method of claim 1 , further comprising: sending, by the provider system to the client device, a request for client eligibility information of the client; receiving, by the provider system, part or all of client eligibility information associated with the first MIC which the client device received from the first APS or a second MIC which the client device received from a second APS, wherein the client has consented to release the part or all of client eligibility information to the provider system, and wherein the part or all of client eligibility information has been verified by the first APS or the second APS as verified part or all of client eligibility information; using, by the provider system, the verified part or all of client eligibility information to verify or not verify client eligibility of the client; granting the client the request for client access, by the provider system, when the identity and the client eligibility of the client are verified; and denying the client the request for client access, by the provider system, when the identity or the client eligibility of the client is not verified. 8. The method of claim 1 , further comprising: sending, by the provider system to an escrow provider system, a request for information showing that the client has met escrow obligations to receive the client access; receiving, by the provider system, part or all of client escrow fulfillment information associated with an escrow MIC which the client device received from an escrow APS, which is the first MIC issued by the first APS or another MIC issued by another APS, wherein the client has consented to release the part or all of client escrow fulfillment information to the provider system, and wherein the part or all of client escrow fulfillment information has been verified by the escrow APS; using, by the provider system, the verified part or all of client escrow fulfillment information to verify or not verify escrow fulfillment of the client; granting the request for client access, by the provider system to the escrow provider system, to provide to the client the client access when the identity of the client is verified and the escrow fulfillment of the client is verified; and denying the request for client access, by the p
Hardware identity · CPC title
Authentication · CPC title
Access security · CPC title
using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title
using certificates or pre-shared keys · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.