US2013185775A1PendingUtilityA1

Multi factor authentication

Assignee: PHONEFACTOR INCPriority: Nov 16, 2006Filed: Jan 28, 2013Published: Jul 18, 2013
Est. expiryNov 16, 2026(~0.3 yrs left)· nominal 20-yr term from priority
H04L 63/0869H04L 63/08H04L 63/168H04L 63/18H04L 63/166
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In one embodiment, a network element comprises one or more processors, and a memory module communicatively coupled to the processor. The memory module comprises logic instructions which, when executed by the processor, configure the processor to receive, via a first communication channel, a primary authentication request transmitted from a user from a first device, process the primary authentication request to determine whether the user is authorized to access one or more resources, in response to a determination that the user is authorized to access one or more resources, initiate, a secondary authentication request, and transmit the secondary authentication request from the network element to the user via a second communication channel, different from the first communication channel.

Claims

exact text as granted — not AI-modified
1 . A method of authenticating a user for accessing a resource, said method relying on multi-factor authentication of the user, the method comprising the steps of:
 associating the user with a first factor authentication information;   associating the user with a second factor authentication information;   receiving information of a first instance of a first factor authentication step, said first factor authentication step comprising the user inputting a first user authentication information across a first communications network and matching the first user authentication information to the first factor authentication information;   upon receipt of the information of the first instance of the first factor authentication step, performing a first instance of a second factor authentication step, said second factor authentication step comprising—
 placing a telephone call or sending a text message to the user across a second communications network at a pre-registered number associated with a telecommunications device of the user, 
 in response to placing said telephone call or sending said text message to the user, receiving a second user authentication information inputted by the user at the user's telecommunications device, 
 confirming that said second user authentication information provided by the user via the user's telecommunications device matches the second factor authentication information, and 
 upon confirming that the second user authentication information matches the second factor authentication information, identifying the user as being authorized to access the resource; 
   receiving information of the user performing a second instance of said first factor authentication step;   determining if the second instance of said first factor authentication step is within a predetermined period of time since the first instance of said second factor authentication step;   if the second instance of said first factor authentication step is outside the predetermined period of time, performing a second instance of said second factor authentication step for the user; and   if the second instance of said first factor authentication step is within the predetermined period of time, not performing the second instance of said second factor authentication step for the user.   
     
     
         2 . The method as set forth in  claim 1 , wherein the first communications network is selected from the group consisting of a private data network, a local area network, a wide area network, or a public network. 
     
     
         3 . The method as set forth in  claim 1 , wherein the first communications network is the Internet. 
     
     
         4 . The method as set forth in  claim 1 , wherein the input of said first user authentication information is immediately prior to the user accessing said resource. 
     
     
         5 . The method as set forth in  claim 1 , wherein the first factor authentication information comprises a username and password. 
     
     
         6 . The method as set forth in  claim 1 , wherein the second communications network is selected from the group consisting of a public switched telephone network and an Internet Protocol network. 
     
     
         7 . A non-transitory computer-readable storage medium with an executable program stored thereon for directing operation of at least one computer to authenticate a user for accessing a resource, wherein the program instructs the at least one computer to perform the following steps:
 associate the user with a first factor authentication information;   associate the user with a second factor authentication information;   receive information of a first instance of a first factor authentication step, said first factor authentication step comprising the user inputting a first user authentication information across a first communications network and match the first user authentication information to the first factor authentication information;   upon receipt of the information of the first instance of the first factor authentication step, perform a first instance of a second factor authentication step, said second factor authentication step comprising—
 place a telephone call or send a text message to the user across a second communications network at a pre-registered number associated with a telecommunications device of the user, 
 in response to placing said telephone call or sending said text message to the user, receive a second user authentication information inputted by the user at the user's telecommunications device, 
 confirm that said second user authentication information provided by the user via the user's telecommunications device matches the second factor authentication information, and 
 upon confirming that the second user authentication information matches the second factor authentication information, identify the user as being authorized to access the resource; 
   receive information of the user performing a second instance of said first factor authentication step;   determine if the second instance of said first factor authentication step is within a predetermined period of time since the first instance of said second factor authentication step;   if the second instance of said first factor authentication step is outside the predetermined period of time, perform a second instance of said second factor authentication step for the user; and   if the second instance of said first factor authentication step is within the predetermined period of time, not perform the second instance of said second factor authentication step for the user.   
     
     
         8 . The computer-readable storage medium as set forth in  claim 7 , wherein the first communications network is selected from the group consisting of a private data network, a local area network, a wide area network, or a public network. 
     
     
         9 . The computer-readable storage medium as set forth in  claim 7 , wherein the first communications network is the Internet. 
     
     
         10 . The computer-readable storage medium as set forth in  claim 7 , wherein the input of said first user authentication information is immediately prior to the user accessing said resource. 
     
     
         11 . The computer-readable storage medium as set forth in  claim 7 , wherein the first factor authentication information comprises a username and password. 
     
     
         12 . The computer-readable storage medium as set forth in  claim 7 , wherein the second communications network is selected from the group consisting of a public switched telephone network and an Internet Protocol network. 
     
     
         13 . A method of authenticating a user for accessing a resource, said method relying on multi-factor authentication of the user, the method comprising the steps of:
 associating the user with a first factor authentication information;   associating the user with a second factor authentication information;   receiving information of a first instance of a first factor authentication step, said first factor authentication step comprising the user inputting a first user authentication information across a first communications network and matching the first user authentication information to the first factor authentication information; and   upon receipt of the information of the first instance of the first factor authentication step, performing a first instance of a second factor authentication step, said second factor authentication step comprising—
 placing a first telephone call or sending a first text message to the user across a second communications network at a pre-registered number associated with a telecommunications device of the user, 
 in response to placing said first telephone call or sending said first text message to the user, receiving a second user authentication information inputted by the user at the user's telecommunications device, 
 confirming that said second user authentication information provided by the user via the user's telecommunications device matches the second factor authentication information, 
 if the second user authentication information matches the second factor authentication information, identifying the user as being authorized to access the resource, and 
 if the second user authentication information does not match the second factor authentication information, identifying the user as not being authorized to access the resource, and placing a second telephone call or sending a second text message to the user across the second communications network at the pre-registered number, wherein the second telephone call or the second text message includes information notifying the user that the second factor authentication step failed and that the user must initiate a second instance of said first factor and said second factor authentication steps. 
   
     
     
         14 . The method as set forth in  claim 13 , wherein the first communications network is selected from the group consisting of a private data network, a local area network, a wide area network, or a public network. 
     
     
         15 . The method as set forth in  claim 13 , wherein the first communications network is the Internet. 
     
     
         16 . The method as set forth in  claim 13 , wherein the input of said first user authentication information is immediately prior to the user accessing said resource. 
     
     
         17 . The method as set forth in  claim 13 , wherein the first factor authentication information comprises a username and password. 
     
     
         18 . The method as set forth in  claim 13 , wherein the second communications network is selected from the group consisting of a public switched telephone network and an Internet Protocol network.

Join the waitlist — get patent alerts

Track US2013185775A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.