Multifactor authentication for secure management of data center assets from a mobile device
US-2020236116-A1 · Jul 23, 2020 · US
US11716630B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11716630-B2 |
| Application number | US-202217961091-A |
| Country | US |
| Kind code | B2 |
| Filing date | Oct 6, 2022 |
| Priority date | Apr 13, 2020 |
| Publication date | Aug 1, 2023 |
| Grant date | Aug 1, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A provider system is connected to readers disposed at distances from the provider system. A secure local connection is established between the client device and the provider system via one of the readers. Before the client reaches an access touchpoint, the provider system receives from the client device a request for client access, the provider system sends to the client device a request for identification information of the client, and the client device sends client information associated with a first mobile identification credential (MIC) which the client device received from an authorizing party system (APS), the client having consented to release the client information to the provider system, and the client information having been verified. The provider system performs a liveness check of the client using live-captured biometric information at the access touchpoint, determines whether the liveness check is valid, and grants the request if the liveness check is valid.
Opening claim text (preview).
What is claimed is: 1. A method for a client having a client device to request client access from a provider having a provider system, the method comprising: establishing a secure connection between the client device and the provider system via a reader, before the client reaches an access touchpoint; receiving, by the provider system from the client device, a request for client access before the client reaches the access touchpoint; sending, by the provider system to the client device, a request for identification information of the client before the client reaches the access touchpoint; receiving, by the provider system before the client reaches the access touchpoint, part or all of client information associated with a first mobile identification credential (MIC) which the client device received from a first authorizing party system (APS), the client having consented to release the part or all of client information to the provider system, and the part or all of client information having been verified by the first APS, the client information including biometric information of the client; performing a liveness check of the client using live-captured biometric information of the client at the access touchpoint; using, by the provider system, the verified part or all of client information associated with the first MIC to determine whether the liveness check is valid or invalid; and determining that the liveness check is valid, by the provider system, before granting the client the request for client access. 2. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from the client device before the client reaches the access touchpoint, a token specifying the part or all of client information which the client has consented to release to the provider system; sending, by the provider system to the first APS, the received token, which is to be verified by the first APS with another token sent from the client device to the first APS; when the tokens are received by the first APS within a preset timeframe and are verified by the first APS, receiving, by the provider system from the first APS, the verified part or all of client information; and when the tokens are not received by the first APS within the preset timeframe or are not verified by the first APS, receiving, by the provider system from the first APS, a notification to resubmit the request for identification information of the client. 3. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from the client device before the client reaches the access touchpoint, an electronic document specifying the part or all of client information which the client has consented to release to the provider system; sending, by the provider system to the first APS, the received electronic document; when the received electronic document is verified by the first APS, receiving, by the provider system from the first APS, the verified part or all of client information; and when the received electronic document is not verified by the first APS, receiving, from the provider system from the first APS, a notification to resubmit the request for identification information of the client. 4. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from client device before the client reaches the access touchpoint, an electronic document and the part or all of client information which the client has consented to release to the provider system; sending, by the provider system to the first APS, the received electronic document; when the received electronic document is verified by the first APS, receiving, by the provider system from the first APS, an authentication key to verify the part or all of client information received from the client device; and when the received electronic document is not verified by the first APS, receiving, by the provider system from the first APS, a notification to resubmit the request for identification information of the client. 5. The method of claim 1 , wherein receiving the verified part or all of client information comprises: receiving, by the provider system from the client device before the client reaches the access touchpoint, the part or all of client information which the client has consented to release to the provider system; and receiving, by the provider system from the first APS, an authentication key to verify the part or all of client information received from the client device, based on a request sent from the client device to the first APS. 6. The method of claim 1 , further comprising: granting the request from the client, by the provider system, to provide the client access when the liveness check is valid; and denying the request from the client, by the provider system, to provide the client access when the liveness check is invalid. 7. The method of claim 1 , further comprising: sending, by the provider system to the client device, a request for client eligibility information of the client; receiving, by the provider system, part or all of client eligibility information associated with the first MIC which the client device received from the first APS or a second MIC which the client device received from a second APS, wherein the client has consented to release the part or all of client eligibility information to the provider system, and wherein the part or all of client eligibility information has been verified by the first APS or the second APS as verified part or all of client eligibility information; using, by the provider system, the verified part or all of client eligibility information to verify or not verify client eligibility of the client; granting the client the request for client access, by the provider system, when the identity and the client eligibility of the client are verified; and denying the client the request for client access, by the provider system, when the identity or the client eligibility of the client is not verified. 8. The method of claim 1 , further comprising: sending, by the provider system to an escrow provider system, a request for information showing that the client has met escrow obligations to receive the client access; receiving, by the provider system, part or all of client escrow fulfillment information associated with an escrow MIC which the client device received from an escrow APS, which is the first MIC issued by the first APS or another MIC issued by another APS, wherein the client has consented to release the part or all of client escrow fulfillment information to the provider system, and wherein the part or all of client escrow fulfillment information has been verified by the escrow APS; using, by the provider system, the verified part or all of client escrow fulfillment information to verify or not verify escrow fulfillment of the client; granting the request for client access, by the provider system to the escrow provider system, to provide to the client the client access when the liveness check is valid and the escrow fulfillment of the client is verified; and denying the request for client access, by the provider system to the escrow provider system, to provide to the client the client access when at least one of the liveness check is invalid or the escrow fulfillment of the client is not verified. 9. The method of claim 1 , wherein the client access is subject to a quantity limit, the method further comprising: granting the client the request for client access, by the provider system, when the liveness check is valid and when an accumulated quanti
Hardware identity · CPC title
Authentication · CPC title
Access security · CPC title
using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title
using certificates or pre-shared keys · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.