IP Library › Granted Patent US 6,980,081
Granted Patent B2
US 6,980,081 · App. 10/143,661 · Granted Dec 27, 2005

System and method for user authentication

Assignee: Hewlett-Packard Development Company, L.P.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,980,081
App. No.
10/143,661
Granted
Dec 27, 2005
Kind
B2
Abstract

According to one embodiment of the present invention, a method for authenticating a user of a device comprises: generating at least one arrangement comprising a sub-set of a plurality of stored objects, the sub-set comprising at least one authenticating object that forms at least part of a user's authentication key and the sub-set further comprising at least one non-authenticating object, wherein such generating comprises randomly selecting a position within the at least one arrangement for the at least one authenticating object and randomly selecting the at least one non-authenticating object from the plurality of stored objects; presenting to a user the generated at least one arrangement; receiving input that comprises a selection of at least one of the objects from the at least one arrangement; and determining whether the selection identifies the authentication key.

Claims (69)

1. A method for authenticating a user of a device, said method comprising:

generating at least one arrangement comprising a sub-set of a plurality of stored objects, said sub-set comprising at least one authenticating object that forms at least part of a user's authentication key and said sub-set further comprising at least one non-authenticating object, wherein said generating comprises randomly selecting a position within said at least one arrangement for said at least one authenticating object and randomly selecting said at least one non-authenticating object from said plurality of stored objects;

presenting to a user said generated at least one arrangement;

receiving input that comprises a selection of at least one of said objects from said at least one arrangement; and

determining whether said selection identifies said authentication key.

2. The method of claim 1 further comprising:

denying access to at least a portion of said device if said input is determined not to identify said authentication key.

3. The method of claim 1 wherein said device controls access to a physical location, further comprising:

denying access to said physical location if said input is determined not to identify said authentication key.

4. The method of claim 1 wherein said plurality of stored objects comprises objects that are stored for use on said device for a purpose in addition to authenticating a user.

5. The method of claim 4 wherein said plurality of stored objects comprises objects that are stored for use by an application, other than a user authentication application, executable by said device.

6. The method of claim 1 further comprising:

storing said plurality of objects to a data store that is at least temporarily communicatively accessible by said device.

7. The method of claim 1 further comprising:

storing said plurality of objects to a data store that is at least temporarily communicatively accessible by a mobile device.

8. The method of claim 1 wherein said presenting further comprises:

presenting via a mobile device said generated at least one arrangement.

9. The method of claim 8 wherein said plurality of stored objects are stored to said mobile device.

10. The method of claim 1 wherein said generating, presenting, receiving, and determining are performed by a mobile device.

11. The method of claim 1 wherein said authenticating key comprises a plurality of objects, said generating further comprising:

randomly selecting the sequence in which the plurality of objects of said authenticating key are to be presented.

12. The method of claim 1 further comprising:

assigning each of said plurality of stored objects to at least one of a plurality of different categories.

13. The method of claim 12 wherein said plurality of different categories comprise at least one category selected from the group consisting of: alphabetic, numeric, punctuation marks, icons, and silhouettes.

14. The method of claim 12 wherein said randomly selecting said at least one non-authenticating object from said plurality of stored objects comprises:

randomly selecting said at least one non-authenticating object from a category that corresponds to the category of said at least one object that forms at least part of said authentication key.

15. The method of claim 12 wherein said randomly selecting said at least one non-authenticating object from said plurality of stored objects comprises:

randomly selecting said at least one non-authenticating object from a determined category of said plurality of stored objects.

16. The method of claim 1 further comprising:

assigning at least one of said plurality of stored objects as an authentication key for a user.

17. A system comprising:

means for generating at least one arrangement comprising a sub-set of a plurality of stored objects, said sub-set comprising at least one authenticating object that forms at least part of a user's authentication key and said sub-set further comprising at least one non-authenticating object, wherein said generating means randomly selects a position within said at least one arrangement for said at least one authenticating object and randomly selects said at least one non-authenticating object from said plurality of stored objects;

means for presenting to a user said at least one arrangement;

means for receiving input that comprises a selection of at least one of said objects from said at least one arrangement; and

means for determining whether received input is a selection of said authentication key, wherein a user is authenticated if said input is determined to be a selection of said authentication key.

18. The system of claim 17 wherein said system is a mobile system.

19. The system of claim 17 further comprising:

means for assigning each of said plurality of stored objects to at least one of a plurality of different categories, wherein said means for generating at least one arrangement randomly selects said at least one non-authenticating object from a category that corresponds to the category of said at least one authenticating object.

20. The system of claim 17 further comprising:

means for assigning each of said plurality of stored objects to at least one of a plurality of different categories, wherein said means for generating at least one arrangement randomly selects said at least one non-authenticating object from a determined category of said plurality of stored objects.

21. The system of claim 17 further comprising:

means for storing said plurality of objects.

22. A method for authenticating a user of a device, said method comprising:

for a user authentication session, presenting at least one arrangement comprising a sub-set of a plurality of stored objects, said sub-set comprising at least one authenticating object that forms at least part of a user's authentication key and said sub-set further comprising at least one non-authenticating object randomly selected from said plurality of stored objects, wherein said at least one authenticating object is randomly positioned within said at least one arrangement;

receiving input that comprises a selection of at least one of said objects from said at least one arrangement; and

determining whether said selection identifies said authentication key.

23. The method of claim 22 wherein said at least one arrangement comprises a matrix.

24. The method of claim 22 wherein said presenting comprises:

presenting a plurality of said arrangements of a sub-set of said plurality of stored objects in series.

25. The method of claim 24 wherein each of said plurality of arrangements comprises at least one authenticating object randomly positioned therein and at least one non-authenticating object randomly selected from said plurality of stored objects.

26. The method of claim 24 wherein said receiving comprises:

for each of said plurality of arrangements, receiving input that comprises a selection of at least one of said objects from such arrangement.

27. The method of claim 26 wherein said determining comprises:

determining whether said selections for said plurality of arrangements identify said authentication key.

28. The method of claim 24 wherein each of said plurality of arrangements comprises a matrix.

29. The method of claim 22 wherein said user's authentication key comprises a plurality of authenticating objects.

30. The method of claim 29 wherein said presenting comprises:

presenting a different one of said plurality of authenticating objects in series.

31. The method of claim 29 wherein said plurality of authenticating objects have a defined order.

32. The method of claim 31 wherein said at least one arrangement may randomly include an authenticating object that is presented out of its defined order and thereby comprise a non-authenticating object of said at least one arrangement.

33. The method of claim 29 wherein said plurality of authenticating objects do not have a defined order.

34. The method of claim 22 wherein said presenting comprises presenting said at least one arrangement on a display of said device.

35. The method of claim 22 wherein said presenting comprises presenting said at least one arrangement on a display of a mobile device.

36. The method of claim 22 further comprising:

presenting at least one arrangement comprising a plurality of objects that does not comprise an authenticating object therein.

37. The method of claim 36 further comprising:

receiving input that comprises a selection of at least one of said objects from said at least one arrangement that does not comprise an authenticating object therein.

38. The method of claim 37 further comprising:

disregarding said input that comprises a selection of at least one of said objects from said at least one arrangement that does not comprise an authenticating object therein.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2003
From: HEWLETT-PACKARD COMPANY
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 013776/0928 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2002
From: ANDERSON, JAMES
To: HEWLETT-PACKARD COMPANY
Reel/Frame 013273/0001 →
Continuity (1)
Related Publication 20030210127A1 · Nov 13, 2003