Systems and methods for anonymous authentication using multiple devices

US2016182500A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016182500-A1
Application numberUS-201514788152-A
CountryUS
Kind codeA1
Filing dateJun 30, 2015
Priority dateDec 22, 2014
Publication dateJun 23, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system and method of anonymous authentication is described. In operation, the authenticator receives a request to access a resource from one of the user devices of an associated set of user devices, wherein each of the user devices is registered to at least one user requesting access to the resource registered to at least two users. The authenticator generates and transmits an authentication challenge in response to the request to a subset of the user devices. A user device subsequently generates and transmits a response to the authentication challenge to the authenticator. The authenticator determines whether the responses received from the one or more user devices constitutes a valid response and grants any one or more of the user devices of the associated set of user devices access to the resource if the responses received from the user devices constitutes a valid response to the authentication challenge.

First claim

Opening claim text (preview).

1 . A method of authentication using at least two user devices of an associated set of user devices; the method comprising: registering each user device of an associated set of user devices with an authenticator computing device, wherein each of the user devices of the associated set of user devices are registered to at least one user; receiving, at the authenticator computing device, a request to access a resource from one user device of the associated set of user devices, wherein the one user device requesting access to the resource is registered to more than one user; generating an authentication challenge at the authenticator computing device in response to the request; transmitting the authentication challenge to a subset of user devices of the associated set of user devices registered with the authenticator computing device, wherein the subset of user devices comprises at least one user device other than the one user device requesting access to the resource; generating at least one response to the authentication challenge at one or more user devices of the subset of user devices; transmitting the at least one response to the authenticator computing device; determining, at the authenticator computing device, if the at least one response constitutes a valid response to the authentication challenge; and granting any one or more of the user devices of the associated set of user devices registered with authenticator computing device access to the resource if the at least one response received at the authenticator computing device constitutes a valid response to the authentication challenge. 2 . The method of claim 1 , wherein registering each of the user devices of the associated set of user devices with an authenticator computing device, wherein each of the user devices of the associated set of user devices are registered to at least one user further comprises storing at least one user credential and storing at least one verified device identifier from each of the user devices of the associated set of user devices at the authenticator computing device. 3 . The method of claim 1 , wherein transmitting the authentication challenge to a subset of user devices of the associated set of user devices further comprises, transmitting the authentication challenge from the authenticator computing device to the subset of user devices according to a forwarding policy of the authenticator computing device. 4 . The method of claim 1 , wherein transmitting the authentication challenge to a subset of user devices of the associated set of user devices further comprises, transmitting the authentication challenge from the authenticator computing device to the user device requesting access to the resource and the user device requesting access to the resource subsequently transmitting the authentication challenge to the other user devices of the subset of user devices according to a forwarding policy of the user device requesting access to the resource. 5 . The method of claim 1 , wherein generating at least one response to the authentication challenge at one or more user devices of the subset of user devices further comprises, generating a response to the authentication challenge at each of the user devices of the subset of user devices according to a response policy of each of the user devices of the subset of user devices. 6 . The method of claim 5 further comprising, transmitting the response to the authentication challenge generated at each of the user devices of the subset of user devices to the authenticator computing device. 7 . The method of claim 6 , wherein determining, at the authenticator computing device, if the at least one response constitutes a valid response to the authentication challenge further comprises, determining if each response to the authentication challenge generated at each of the users devices of the subset of user devices constitutes a valid response. 8 . The method of claim 6 , wherein determining, at the authenticator computing device, if the at least one response constitutes a valid response to the authentication challenge further comprises, determining if each response to the authentication challenge generated at each of user devices of the subset of user devices constitutes a valid response according to a validation policy of the authenticator computing device. 9 . The method of claim 1 , wherein the authentication challenge is an encrypted or cryptographically signed authentication challenge. 10 . The method of claim 1 , wherein the authentication challenge comprises a Message Authentication Code (MAC). 11 . The method of claim 1 , wherein the authentication challenge comprises a timestamp. 12 . The method of claim 1 , wherein a transmission technique for authentication challenge is selected from the group consisting of a QR code, a sound wave, a light wave, an infrared signal, an NFC, a Bluetooth signal, a radio signal, an image, a state of a memory device and a vibration. 13 . The method of claim 1 , wherein the resource is selected from the group consisting of an application, a file, a process, a port, a service, a network bandwidth, a device, a memory and a processor time. 14 . One or more non-transitory computer-readable media having computer-executable instructions for performing a method of running a software program on a computing device, the method including issuing instructions from the software program, the instructions comprising: registering each user device of an associated set of user devices with an authenticator computing device, wherein each of the user devices of the associated set of user devices are registered to at least one user; receiving, at the authenticator computing device, a request to access a resource from one user device of the associated set of user devices, wherein the one user device requesting access to the resource is registered to more than one user; generating an authentication challenge at the authenticator computing device in response to the request; transmitting the authentication challenge to a subset of user devices of the associated set of user devices registered with the authenticator computing device, wherein the subset of user devices comprises at least one user device other than the one user device requesting access to the resource; generating at least one response to the authentication challenge at one or more user devices of the subset of user devices; transmitting the at least one response to the authenticator computing device; determining, at the authenticator computing device, if the at least one response constitutes a valid response to the authentication challenge; and granting any one or more of the user devices of the associated set of user devices registered with the authenticator computing device access to the resource if the at least one response received at the authenticator computing device constitutes a valid response to the authentication challenge. 15 . The media of claim 14 , further comprising instructions for registering each of the user devices of the associated set of user devices to a user with an authenticator computing device, wherein each of the user devices of the associated set of user devices are registered to at least one user, by storing at least one user credential and storing at least one verified device identifier from each of the user devices of the associated set of user devices at the authenticator computing device. 16 . The media of claim 14 , further comprising instructions for transmitting the authentication challenge from the authenticator computing device to the subset o

Assignees

Inventors

Classifications

  • wherein the identity of one or more communicating identities is hidden (cryptographic mechanisms or cryptographic arrangements for anonymous credentials or for identity based cryptographic systems H04L9/00) · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • H04L9/3271Primary

    using challenge-response · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016182500A1 cover?
A system and method of anonymous authentication is described. In operation, the authenticator receives a request to access a resource from one of the user devices of an associated set of user devices, wherein each of the user devices is registered to at least one user requesting access to the resource registered to at least two users. The authenticator generates and transmits an authentication …
Who is the assignee on this patent?
Ligatti Jarred Adam, Goldgof Dmitry, Cetin Cagri, and 2 more
What technology area does this patent fall under?
Primary CPC classification H04L63/0853. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jun 23 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).