Cross-channel authentication
A method and a communication network are disclosed. A first computing device of a trusted computing system transmits an authentication request, for authenticating, in the trusted computing system, an identity of an individual, to a server of the trusted computing system. An authentication provider module, pre-registered with the trusted computing system and that is executing on a second computing device external to the trusted computing system determines that the authentication request has been transmitted to the server of the trusted computing system. The authentication provider module is configured to authenticate the identity of the individual independently of the trusted computing system, responsive to said determining. The authentication provider module authenticates the identity of the individual, and responsive to said authenticating, transmits a response to the authentication request to the server of the trusted computing system, thereby authenticating, in the trusted computing system, the identity of the individual.
1 . A computer-implemented method for authenticating, in a trusted computing system, an identity of an individual, comprising the steps of:
transmitting, by a first computing device of a trusted computing system to a server of the trusted computing system, an authentication request for authenticating, in the trusted computing system, the identity of an individual, the authentication request including a request identifier associated with an interaction at the first computing device;
determining, by an authentication provider software module that is pre-registered with the trusted computing system and that is executing on a second computing device external to the trusted computing system, that the authentication request has been transmitted to the server of the trusted computing system, by receiving, at the authentication provider software module, an indication of the authentication request including the request identifier;
responsive to said determining, authenticating, by the authentication provider software module, the identity of the individual using authentication factors or credentials obtained by the authentication provider software module and not accessible to the trusted computing system;
responsive to said authenticating, transmitting, bythe authentication provider software module, an authentication response to the authentication including the request identifier to the server of the trusted computing system, thereby authenticating, in the trusted computing system, the identity of the individual;
providing an authentication token, issued by a trusted identity provider software module of the trusted computing system, to the authentication provider software module;
pre-registering the authentication provider software module with the trusted computing system by providing the authentication token to the server when transmitting the response to the authentication request to the server, providing the authentication token; and
authenticating, by the server, the authentication token to authenticate the authentication provider software module.
2 . The method as claimed in claim 1 , further comprising: transmitting, by the server, said response to the authentication request to the first computing device.
3 . The method as claimed in claim 1 , further comprising:
detecting, by the first computing device, an input event indicating that the individual is to be authenticated via a cardless authentication process.
4 . The method as claimed in claim 3 , further comprising:
generating, by the first computing device, the authentication request responsive to detecting the input event.
5 . The method as claimed in claim 4 , further comprising:
generating the authentication request as a set of data comprising at least a request identifier for the request and a device identifier for the first computing device.
6 . The method as claimed in claim 1 , further comprising:
responsive to receiving the authentication request at the server, providing the authentication request to an authentication request queue on the server.
7 . The method as claimed in claim 6 , further comprising:
monitoring, by the authentication provider software module, the authentication request queue on the server for authentication requests that can be fulfilled by the authentication provider software module.
8 . The method as claimed in claim 1 , further comprising:
responsive to receiving the response to the authentication request at the server, providing the response to an authentication response queue on the server.
9 . The method as claimed in claim 8 , further comprising:
monitoring, by the first computing device, the authentication response queue for responses to authentication requests generated by the first computing device.
10 . The method as claimed in claim 1 , further comprising:
executing an application programming interface on the server, that is configured to communicate with the authentication provider software module.
11 . The method as claimed in claim 1 , further comprising:
executing an application programming interface on the server, that is configured to communicate with the first computing device.
12 . The method as claimed in claim 1 , further comprising:
storing, in a memory on the server, data indicating a list of available authentication provider software modules able to fulfil authentication requests.
13 . The method as claimed in claim 1 , further comprising:
providing an authentication token, issued by an identity provider software module external to the trusted computing system, to a computing device of the individual; and
when authenticating the identity of the individual via the authentication provider software module, transmitting the authentication token from the computing device of the individual to the authentication provider software module.
14 . The method as claimed in claim 1 , further comprising:
continuously transmitting, by the authentication provider software module, a ping to the server to indicate the authentication provider software module is available to fulfil authentication requests.
15 . A communication network, comprising:
a trusted computing system comprising a first computing device and a server;
a non-trusted computing system, external to the trusted computing system, comprising a second computing device executing a respective authentication provider software module that is pre-registered with the trusted computing system and that is configured to authenticate an identity of an individual independently of the trusted computing system;
wherein the first computing device is configured to:
transmit an authentication request to the server, for authenticating, in the trusted computing system, the identity of the individual, the authentication request including a request identifier associated with an interaction at the first computing device;
wherein the respective authentication provider software module is configured to:
receive an indication of the authentication request including the request identifier,
determine that the authentication request has been transmitted to the server;
authenticate the identity of the individual using authentication factors or credentials obtained by the authentication provider software module and not accessible to the trusted computing system; and
transmit an authentication response including the request identifier to the server to thereby authenticate, in the trusted computing system, the identity of the individual;
providing an authentication token, issued by a trusted identity provider software module of the trusted computing system, to the authentication provider software module;
pre-registering the authentication provider software module with the trusted computing system by providing the authentication token to the server;
when transmitting the response to the authentication request to the server, providing the authentication token; and
authenticating, by the server, the authentication token to authenticate the authentication provider software module.
16 . The communication network as claimed in claim 15 , wherein the first computing device is an Automated Teller Machine or Self-Service Terminal or kiosk.
17 . The communication network as claimed in claim 15 , wherein the first computing device is a desktop computer or a laptop or a mobile device of a bank teller.
18 . The communication network as claimed in claim 15 , wherein the second computing device is a server of the non-trusted computing system and the respective authentication provider software module is a mobile backend associated with a mobile banking application executing on a mobile device of the individual.