System and method for authorizing access to access-controlled environments
Abstract
Systems and methods are provided for authorizing a user to access an access-controlled environment. The system includes a system server platform that communicates with fixed PC's, servers and mobile devices (e.g., smartphones) operated by users. The systems and methods described herein enable a series of operations whereby a user attempting to access an access-controlled environment is prompted to biometrically authenticate using the user's preregistered mobile device. Biometric authentication can include capturing images of the user's biometric features, encoding the features as a biometric identifier, comparing the biometric identifier to a previously generated biometric identifier and determining liveness. In addition, the authentication system can further authorize the user and electronically grant access to the access-controlled environment. In this manner the secure authentication system can, based on biometric authentication, authorize a user's access to devices, online services, physical locations or any networked environment that require user authorization.
Claims
exact text as granted — not AI-modified1 - 27 . (canceled)
28 . An authorization system for securely coordinating access to an access-controlled environment for a user using a mobile computing device executing a biometric authentication application to biometrically confirm the user's identity a function of a biometric of the user, the system comprising:
a non-transitory computer readable storage medium having instructions in the form of one or more modules stored therein; keys stored in the storage medium and associated with respective user accounts, wherein each respective user account is associated with a respective key generated based on confirmation of a respective user's identity by a respective mobile device executing the biometric authentication application and using identification information concerning the respective user and a component of the of the respective mobile device; a processor configured by executing the modules therein; a network connection configured to communicatively connect the processor to one or more mobile devices over a network connection, and wherein the processor, using the network connection, is configured to receive: i) access-control information that identifies an access-controlled environment, and ii) one or more transmissions from a mobile device including a key and an indicator indicating that the user's identity has been biometrically confirmed by the mobile device; an authorization module that, when executed by the processor, configures the processor to:
verify that the received key corresponds to at least one of the respective keys,
determine, based on the indicator and the key, that the mobile device has biometrically confirmed the identity of the user using the biometric authentication application,
confirm that at least one of the one or more transmissions is not a replay of a previously received transmission from the mobile device, and
facilitate, over the network with a remote computing device based on the information that identifies an access-controlled environment, the user access to the access-controlled environment as a function of the verification, determination and confirmation.
29 . The system of claim 28 , wherein the processor is configured to confirm that the at least one transmission is not a replay by verifying that the at least one transmission differs from one or more previous received transmissions.
30 . The system of claim 28 , wherein a prescribed manner in which each transmission received from the mobile device is unique is provided in the storage, and wherein the processor is configured to confirm that the at least one transmission is not a replay by:
verifying that the at least one transmission conforms to the prescribed manner.
31 . The system of claim 28 , wherein the authentication module further configures the processor to:
prompt the mobile device to: i) capture biometric information of the user, ii) biometrically confirm the user's identity, and iii) transmit the indicator.
32 . The system of claim 31 , wherein the access-control information includes information identifying the user, and wherein the authentication module further configures the processor to:
identify a user account, among the respective user accounts, that is associated with the user, and identity the mobile device that is associated with the user account in the storage.
33 . The system of claim 32 , further comprising:
wherein, in response to the biometric authentication request, the biometric authentication application executed by the mobile device, configures the mobile device to:
capture biometric information of the user;
confirm the identity of the user as a function of the captured biometric information and biometric information previously stored on the mobile device, and determine that the biometric information is representative of a live subject; and
transmit the one or more transmissions including the indicator and the key.
34 . The system of claim 28 , wherein the processor is configured to verify that the key corresponds to at least one of the respective keys by:
testing the key against one or more of the respective keys to identify a match; and identifying a user account associated with the respective key matched to the key.
35 . The system of claim 34 , wherein the one or more transmissions include one or more additional keys, and wherein the processor is configured to verify that the one or more additional keys correspond to the user account.
36 . The system of claim 34 , wherein the storage includes an access rule associated with the user account, wherein the access rule defines the user's access to the access-controlled environment; and wherein the processor is configured to:
retrieve the access rule from the storage; facilitate the user access to the access-controlled environment based on the access rule.
37 . The system of claim 28 , wherein the at least one remote computing device includes a first remote computing device that is associated with the access-controlled environment and grants access to the access-controlled environment, and a second remote computing device that is associated with the user, and wherein the processor is configured to facilitate the user access by:
establishing a secure communication session between the first remote computing device and the second remote computing device.
38 . The system of claim 37 , wherein the processor is configured to establish the secure communication session based on the received key.
39 . The system of claim 37 , wherein the processor is configured to establish the secure communication session by:
transmitting one or more notifications to the first remote computing device and the second remote computing device, wherein the one or more notifications causes the first remote computing device and the second remote computing devices to establish the secure communication session there-between;
40 . The system of claim 39 , wherein at least one of the one or more notifications transmitted to the first remote computing device includes a representation of one or more of: information identifying the user, information identifying a user account associated with the user, a unique identifier for the secure communication session.
41 . The system of claim 40 , wherein at least one of the one or more notifications transmitted to the second remote computing device causes the second remote computing device to:
retrieve, from a memory in accordance with the at least one notification, account details associated with the access-controlled environment, and transmit at least the account details to the first remote computing device.
42 . The system of claim 37 , wherein the second remote computing device is the mobile device.
43 . A method for securely coordinating access to an access-controlled environment for a user that is using a mobile computing device executing a biometric authentication application to biometrically confirm the user's identity a function of a biometric of the user, the method comprising:
receiving, at a computing device over a network connection, one or more transmissions from a mobile device including: i) access-control information that identifies an access-controlled environment, and ii) one or more transmissions from a mobile device including a key and an indicator indicating that the user's identity has been biometrically confirmed by the mobile device, wherein the computing device has access to a non-transitory computer readable storage medium having keys stored therein including respective keys stored in association with respective user accounts, wherein each respective key is generated based on confirmation of a respective user's identity by a respective mobile device and using identification information concerning the respective user and a component of the of the respective mobile device; verifying, using the code executing in the processor, that the received key corresponds to at least one of the respective keys; determining, using the code executing in the processor based on the indicator and the key, that the mobile device has biometrically confirmed the identity of the user using the biometric authentication application; confirming, using the code executing in the processor, that at least one of the one or more transmissions is not a replay of a previously received transmission from the mobile device; based on the verifying, determining and confirming steps and the received access-control information, facilitating the user access to the access-controlled environment, using the code executing in the processor in conjunction with one or more remote computing devices.
44 . The method of claim 43 , wherein the step of facilitating the user access comprises:
establishing, using the code executing in the processor, a secure communication session between a first remote computing device associated with the access controlled environment and a second remote computing devices associated with the user.
45 . The method of claim 44 , further comprising:
identifying, using the code executing in the processor based on the information that identifies an access-controlled environment, the first remote computing device; and identifying, using the code executing in the processor based on the information that identifies an access-controlled environment and the received key, the second remote computing device associated with the user.
46 . The method of claim 44 , wherein the step of establishing the secure communication comprises:
transmitting one or more notifications to the first remote computing device and the second remote computing device, wherein the one or more notifications causes the first remote computing device and the second remote computing devices to establish the secure communication session there-between.
47 . The method of claim 46 , wherein the one or more notifications transmitted includes one or more of: information identifying the user, information identifying a user account associated with the user, a unique identifier for the secure communication session.Join the waitlist — get patent alerts
Track US2015195288A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.