IP Library Granted Patent US 8,646,056
Granted Patent B2
US 8,646,056 · App. 11/750,263 · Granted Feb 4, 2014

User-friendly multifactor mobile authentication

Inventor: John Poplett (River Forest, IL)
Assignee: U.S. Cellular Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,646,056
App. No.
11/750,263
Granted
Feb 4, 2014
Kind
B2
Abstract

A system and method for performing multifactor mobile authentication are described whereby a mobile communications device includes a contactless reader for receiving and validating a unique identifier stored in an external authenticating module prior to granting access to locally stored electronic authenticating material required to access an external resource. In one embodiment, the mobile communications device is a mobile telephone having an RFID reader for receiving the unique identifier from an RFID tag incorporated into the external authenticating module. Preferably, the external authenticating module is associated with a user, such as by being part of the user's jewelry or clothing. The mobile authentication device includes an RFID authenticator module that detects external resource access requests and checks whether the requested resource is on a list of resources that require additional user authentication prior to granting access to locally stored authenticating material.

Claims (41)

1. A method for gaining authenticated access to an external resource from a mobile communications device (MCD):

detecting, by the MCD, a user request to obtain access to the external resource via the MCD;

detecting whether the external resource is listed on a multifactor authentication list (MAL) stored in the MCD, the MAL comprising a listing of external resources accessible via multifactor authentication, the MAL providing an indication, for each listed external resource, that access to the listed external resource may be obtained through multifactor authentication incorporating a plurality of authenticating factors including:

electronic authenticating material stored in the MCD, and

a unique identifier stored on an external authenticating module;

in response to detecting, using the MAL, that the external resource is accessible via multifactor authentication using the plurality of authenticating factors, performing, by the MCD, the following:

(a) detecting the external authenticating module in proximity to the MCD;

(b) allowing access to the electronic authenticating material stored in the MCD in response to validating the unique identifier received from the external authenticating module as one of the plurality of authenticating factors; and

(c) communicating information associated with the electronic authenticating material stored in the MCD to the external resource as another one of the plurality of authenticating factors,

wherein the MCD is one of the group consisting of: a mobile telephone, a personal digital assistant and a portable computer,

wherein the MCD further comprises a radio frequency identification (RFID) reader and an RFID authenticator module including instructions for validating the unique identifier received from the external authenticating module,

wherein the electronic authenticating material comprises at least one of the group consisting of: a digital certificate, a near field communication (NFC) identifier, a username and password, and a personal identification number, and

wherein the external resource comprises at least one of the group consisting of: a secure web application, a virtual private network (VPN) server, and an NFC device.

2. The method of claim 1 wherein the external authenticating module comprises an RFID tag associated with a user of the MCD.

3. The method of claim 1 further comprising communicating the information associated with the electronic authenticating material via a communications protocol selected from the group consisting of: a secure sockets layer (SSL) protocol, a transport layer security (TLS) protocol, a near field communication (NFC) protocol, a hypertext transfer protocol (HTTP) Digest protocol, and a transmission control protocol (TCP) protocol.

4. A mobile communications device (MCD) for providing access to an external resource via a plurality of authenticating factors in accordance with a user request, the MCD comprising:

a hardware processor;

memory configured to store electronic authenticating material associated with external resources listed on a multifactor authentication list (MAL);

an authenticator module including instructions for detecting whether the external resource is listed on the MAL, the MAL comprising a listing of external resources accessible via multifactor authentication, the MAL providing an indication, for each listed external resource, that access to the external resource may be obtained through multifactor authentication, the plurality of authenticating factors including:

the electronic authenticating material as one of the plurality of authenticating factors, and

a unique identifier stored on an external authenticating module hardware device as another one of the plurality of authenticating factors;

at least one contactless reader, the contactless reader including an interface to receive the unique identifier provided by the external authenticating module hardware device to enable access to the electronic authenticating material, wherein the unique identifier is received by the contactless reader in response to detecting that the external resource is listed on the MAL; and

a communications interface including instructions for sending information associated with the electronic authenticating material to the external resource in accordance with multifactor authentication of the user request for access to the external resource;

wherein the MCD is one of the group consisting of: a mobile telephone, a personal digital assistant and a portable computer,

wherein the MCD further comprises a radio frequency identification (RFID) reader and an RFID authenticator module including instructions for validating the unique identifier received from the external authenticating module,

wherein the electronic authenticating material comprises at least one of the group consisting of: a digital certificate, a near field communication (NFC) identifier, a username and password, and a personal identification number, and

wherein the external resource comprises at least one of the group consisting of: a secure web application, a virtual private network (VPN) server, and an NFC device.

5. The MCD of claim 4 wherein the communications interface connects to the external resource via a communications protocol selected from the group consisting of: a secure sockets layer (SSL) protocol, a transport layer security (TLS) protocol, a near field communication (NFC) protocol, a hypertext transfer protocol (HTTP) Digest protocol, and a transmission control protocol (TCP) protocol.

6. A system for providing access to an external resource from a mobile communications device (MCD) via a plurality of authenticating factors in accordance with a user request, the system comprising:

the MCD having a hardware processor and a non-transitory computer-readable medium;

the MCD having stored thereon electronic authenticating material associated with an external resource listed on a multifactor authentication list (MAL), the MAL comprising a listing of external resources accessible via multifactor authentication, the MAL providing, for each listed external resource, an indication that access to the external resource may be obtained through multifactor authentication including the plurality of authenticating factors;

an external authenticating module hardware device having stored thereon, as one of the plurality of authenticating factors, a unique identifier enabling access to the electronic authenticating material stored in the MCD; and

wherein the MCD comprises at least one contactless reader, the contactless reader including an interface to receive the unique identifier from the external authenticating module hardware device when:

(a) the MCD detects a request to access the external resource listed on the MAL, and

(b) the external authenticating module is in proximity to the MCD,

wherein the MCD communicates information associated with the electronic authenticating material stored in the MCD to the external resource as another one of the plurality of authenticating factors,

wherein the MCD is one of the group consisting of: a mobile telephone, a personal digital assistant and a portable computer,

wherein the MCD further comprises a radio frequency identification (RFID) reader and an RFID authenticator module including instructions for validating the unique identifier received from the external authenticating module,

wherein the electronic authenticating material comprises at least one of the group consisting of: a digital certificate, a near field communication (NFC) identifier, a username and password, and a personal identification number, and

wherein the external resource comprises at least one of the group consisting of: a secure web application, a virtual private network (VPN) server, and an NFC device.

7. The system of claim 6 wherein the MCD sends information associated with the electronic authenticating material to the external resource via a communications protocol selected from the group consisting of: a secure sockets layer (SSL) protocol, a transport layer security (TLS) protocol, a near field communication (NFC) protocol, a hypertext transfer protocol (HTTP) Digest protocol, and a transmission control protocol (TCP) protocol.

Assignments (4)
MERGER Recorded Oct 27, 2025
From: USCC WIRELESS HOLDINGS, LLC
To: ODYSSEY WEST, LLC
Reel/Frame 073362/0519 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2025
From: ODYSSEY WEST, LLC
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 073365/0391 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2025
From: UNITED STATES CELLULAR CORPORATION
To: USCC WIRELESS HOLDINGS, LLC
Reel/Frame 072315/0805 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2007
From: POPLETT, JOHN
To: UNITED STATES CELLULAR CORPORATION
Reel/Frame 019538/0391 →
Continuity (1)
Related Publication 20080289030A1 · Nov 20, 2008