US2022004616A1PendingUtilityA1

Anti-replay authentication systems and methods

Assignee: TRUSONA INCPriority: Jul 29, 2016Filed: Jun 11, 2021Published: Jan 6, 2022
Est. expiryJul 29, 2036(~10 yrs left)· nominal 20-yr term from priority
G06K 7/1443G06F 21/36G06F 21/34G06K 7/1456H04W 12/06H04W 12/77G06K 19/06037G06K 7/1417
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for authentication with resistance to replay attacks are provided. A device may be used to capture image data of a physical token to authenticate or identify a user. Authentication information may be obtained by processing and analyzing the captured image data. Data about a state of the imaging device and the captured image data may be used for fraud detection. The data may be collected when the image data is processed and analyzed. The state of the imaging device and captured image data are unlikely to be repeated. The detected repetition of a state of the imaging device and captured image data may be a cause for increasing the likelihood that a replay attack is taking place. The device may be used to perform a transaction.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method for authenticating a user or a transaction, the method comprising:
 capturing image data of a physical element using an imaging device of a user device, wherein the physical element is a form of credential possessed by the user and is issued by an authority entity;   extracting identification information about the user from the image data by processing the image data;   collecting, from the user device, multiple types of local data about a physical state of the user device or the imaging device;   generating nonce data by combining the multiple types of local data; and   authenticating, with aid of one or more processors, the user or the transaction based on (1) the identification information and (2) the nonce data, wherein the nonce data and identification data are compared with a previously collected nonce data and a previously collected identification data to determine a presence of a replay attack.   
     
     
         22 . The method of  claim 21 , wherein the physical element comprises a graphical code that encodes the identification information about the user. 
     
     
         23 . The method of  claim 21 , wherein the physical element is a driver license, a passport or a document issued by the authority entity. 
     
     
         24 . The method of  claim 21 , wherein at least a portion of the local data is collected using one or more sensors onboard the user device. 
     
     
         25 . The method of  claim 21 , wherein the multiple types of local data about the physical state of the user device comprises data indicative of a physical state of a component of the user device. 
     
     
         26 . The method of  claim 25 , wherein the component is selected from the group consisting of an imaging device, a power supply unit, a processor, and a memory. 
     
     
         27 . The method of  claim 21 , wherein the multiple types of local data about the imaging device comprises data relating to one or more operational parameters of the imaging device at the time the image data is captured. 
     
     
         28 . The method of  claim 21 , wherein the nonce data is encrypted such that the multiple types of local data are not accessible by the one or more processors. 
     
     
         29 . The method of  claim 21 , wherein the multiple types of local data are weighted to generate the nonce data. 
     
     
         30 . The method of  claim 29 , wherein a weight assigned to a given type of local data is determined based on a variation of the given type of local data between different authentication events. 
     
     
         31 . A system for performing authentication of a user or a transaction, the system comprising:
 a server in communication with a user device configured to permit a user to perform a transaction, wherein the server comprises: (i) a memory for storing a set of software instructions, and (ii) one or more processors configured to execute the set of software instructions to:   receive an image data of a physical element possessed by the user, wherein the image data is captured by an imaging device of the user device and wherein the physical element is issued by an authority entity;   extract identification information about the user from the image data by processing the image data;   receive multiple types of local data about a physical state of the user device or the imaging device;   generate nonce data by combining the multiple types of local data; and   authenticate the user or the transaction based on (1) the identification information and (2) the nonce data, wherein the nonce data and identification data are compared with a previously collected nonce data and a previously collected identification data to determine a presence of a replay attack.   
     
     
         32 . The system of  claim 31 , wherein the physical element comprises a graphical code that encodes the identification information about the user. 
     
     
         33 . The system of  claim 31 , wherein the physical element is a driver license, a passport or a document issued by the authority entity. 
     
     
         34 . The system of  claim 31 , wherein at least a portion of the local data is collected using one or more sensors onboard the user device. 
     
     
         35 . The system of  claim 31  wherein the multiple types of local data about the physical state of the user device comprises data indicative of a physical state of a component of the user device. 
     
     
         36 . The system of  claim 35 , wherein the component is selected from the group consisting of an imaging device, a power supply unit, a processor, and a memory. 
     
     
         37 . The system of  claim 31 , wherein the multiple types of local data about the imaging device comprises data relating to one or more operational parameters of the imaging device at the time the image data is captured. 
     
     
         38 . The system of  claim 31 , wherein the nonce data is encrypted such that the multiple types of local data are not accessible by the one or more processors. 
     
     
         39 . The system of  claim 31 , wherein the multiple types of local data are weighted to generate the nonce data. 
     
     
         40 . The system of  claim 39 , wherein a weight assigned to a given type of local data is determined based on a variation of the given type of local data between different authentication events.

Join the waitlist — get patent alerts

Track US2022004616A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.