Anti-replay authentication systems and methods
Abstract
Systems and methods for authentication with resistance to replay attacks are provided. A device may be used to capture image data of a physical token to authenticate or identify a user. Authentication information may be obtained by processing and analyzing the captured image data. Data about a state of the imaging device and the captured image data may be used for fraud detection. The data may be collected when the image data is processed and analyzed. The state of the imaging device and captured image data are unlikely to be repeated. The detected repetition of a state of the imaging device and captured image data may be a cause for increasing the likelihood that a replay attack is taking place. The device may be used to perform a transaction.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method for authenticating a user or a transaction, the method comprising:
capturing image data of a physical element using an imaging device of a user device, wherein the physical element is a form of credential possessed by the user and is issued by an authority entity; extracting identification information about the user from the image data by processing the image data; collecting, from the user device, multiple types of local data about a physical state of the user device or the imaging device; generating nonce data by combining the multiple types of local data; and authenticating, with aid of one or more processors, the user or the transaction based on (1) the identification information and (2) the nonce data, wherein the nonce data and identification data are compared with a previously collected nonce data and a previously collected identification data to determine a presence of a replay attack.
22 . The method of claim 21 , wherein the physical element comprises a graphical code that encodes the identification information about the user.
23 . The method of claim 21 , wherein the physical element is a driver license, a passport or a document issued by the authority entity.
24 . The method of claim 21 , wherein at least a portion of the local data is collected using one or more sensors onboard the user device.
25 . The method of claim 21 , wherein the multiple types of local data about the physical state of the user device comprises data indicative of a physical state of a component of the user device.
26 . The method of claim 25 , wherein the component is selected from the group consisting of an imaging device, a power supply unit, a processor, and a memory.
27 . The method of claim 21 , wherein the multiple types of local data about the imaging device comprises data relating to one or more operational parameters of the imaging device at the time the image data is captured.
28 . The method of claim 21 , wherein the nonce data is encrypted such that the multiple types of local data are not accessible by the one or more processors.
29 . The method of claim 21 , wherein the multiple types of local data are weighted to generate the nonce data.
30 . The method of claim 29 , wherein a weight assigned to a given type of local data is determined based on a variation of the given type of local data between different authentication events.
31 . A system for performing authentication of a user or a transaction, the system comprising:
a server in communication with a user device configured to permit a user to perform a transaction, wherein the server comprises: (i) a memory for storing a set of software instructions, and (ii) one or more processors configured to execute the set of software instructions to: receive an image data of a physical element possessed by the user, wherein the image data is captured by an imaging device of the user device and wherein the physical element is issued by an authority entity; extract identification information about the user from the image data by processing the image data; receive multiple types of local data about a physical state of the user device or the imaging device; generate nonce data by combining the multiple types of local data; and authenticate the user or the transaction based on (1) the identification information and (2) the nonce data, wherein the nonce data and identification data are compared with a previously collected nonce data and a previously collected identification data to determine a presence of a replay attack.
32 . The system of claim 31 , wherein the physical element comprises a graphical code that encodes the identification information about the user.
33 . The system of claim 31 , wherein the physical element is a driver license, a passport or a document issued by the authority entity.
34 . The system of claim 31 , wherein at least a portion of the local data is collected using one or more sensors onboard the user device.
35 . The system of claim 31 wherein the multiple types of local data about the physical state of the user device comprises data indicative of a physical state of a component of the user device.
36 . The system of claim 35 , wherein the component is selected from the group consisting of an imaging device, a power supply unit, a processor, and a memory.
37 . The system of claim 31 , wherein the multiple types of local data about the imaging device comprises data relating to one or more operational parameters of the imaging device at the time the image data is captured.
38 . The system of claim 31 , wherein the nonce data is encrypted such that the multiple types of local data are not accessible by the one or more processors.
39 . The system of claim 31 , wherein the multiple types of local data are weighted to generate the nonce data.
40 . The system of claim 39 , wherein a weight assigned to a given type of local data is determined based on a variation of the given type of local data between different authentication events.Join the waitlist — get patent alerts
Track US2022004616A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.