IP Library Granted Patent US 9,305,298
Granted Patent B2
US 9,305,298 · App. 14/145,533 · Granted Apr 5, 2016

System and method for location-based authentication

Inventor: Brendon J. Wilson (San Jose, CA)
Assignee: NOK NOK LABS, INC.
G06Q20/40145G06F21/32G06F21/577G06Q20/204G06Q20/3224G06Q20/3274G06Q20/3278G06Q20/4012G06Q20/42G06Q20/425G07F19/20H04L9/0819H04L9/0822H04L9/0841H04L9/3231H04L9/3247H04L9/3297H04L63/0492H04L63/08H04L63/083H04L63/0861H04L63/20G06F2221/2115H04L2209/805H04L2463/102H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,305,298
App. No.
14/145,533
Granted
Apr 5, 2016
Kind
B2
Abstract

A system, apparatus, method, and machine readable medium are described for location-aware authentication. For example, one embodiment of a location-aware method for user authentication comprises: determining a current location of a mobile device; identifying a location class corresponding to the current location; selecting a set of one or more authentication techniques to provide a sufficient level of user authentication for a current transaction based on the identified location class.

Claims (36)

1. A location-aware method for user authentication comprising:

determining a current location of a mobile device, wherein determining a current location of a mobile device comprises:

detecting, by a device proximity detection module, the presence of one or more peer or network infrastructure devices; and

performing, by the device proximity detection module, a correlation against historical presence data for the peer or network infrastructure devices, wherein a relatively higher correlation indicates that the mobile device is at a known location and a relatively lower correlation indicates that the mobile device is not at a known location;

identifying, by a location class determination module, a location class corresponding to the current location;

receiving, by an authentication policy engine, an authentication policy associated with a particular relying party, the authentication policy defining a set of one or more authentication techniques to provide a sufficient level of user authentication for a current transaction based on the identified location class; and

selecting, by the authentication policy engine, from the set of one or more authentication techniques to authenticate the user for the current transaction based on the identified location class.

2. The method as in claim 1 wherein determining a current location further comprises using a global positioning system (GPS) device.

3. The method as in claim 1 wherein determining a current location further comprises performing a reverse lookup of the mobile device's IP address.

4. The method as in claim 1 wherein determining a current location further comprises performing cell tower triangulation and/or Wifi access point triangulation.

5. The method as in claim 1 wherein determining a current location further comprises performing an approximation by noting a change in the mobile device's position relative to a starting point with a known location.

6. The method as in claim 1 wherein at least one location class is defined as the mobile device being within a given radius of a known specified location.

7. The method as in claim 1 wherein at least one location class is defined as the mobile device being within a specified boundary region or outside of a specified boundary region.

8. The method as in claim 1 wherein the authentication techniques include explicit authentication techniques and non-intrusive authentication techniques.

9. The method as in claim 8 wherein the explicit authentication techniques include one or more of fingerprint authentication, voice or facial recognition, retinal scanning, and PIN entry by the end user.

10. The method as in claim 8 wherein the non-intrusive authentication techniques include authentication based on data collected from one or more user behavior sensors.

11. The method as in claim 10 wherein the user behavior sensors measure a gait of the user, wherein the user is non-intrusively authenticated based on the user's gait being detected.

12. The method as in claim 8 wherein the non-intrusive authentication techniques include detecting presence of one or more peer or network infrastructure devices known to be present at a particular location.

13. A location-aware system for user authentication comprising:

a memory device for storing program code comprising a plurality of instructions;

at least one processor to execute the instructions to implement a plurality of different functional modules including:

a location detection module to determine a current location of a mobile device,

wherein determining a current location of the mobile device comprises a device proximity detection module to detect the presence of one or more peer or network infrastructure devices and to perform a correlation against historical presence data for the peer or network infrastructure devices, wherein a relatively higher correlation indicates that the mobile device is at a known location and a relatively lower correlation indicates that the mobile device is not at a known location;

a location class determination module to identify a location class corresponding to the current location;

an authentication policy engine to receive an authentication policy associated with a particular relying party, the authentication policy defining a set of one or more authentication techniques to provide a sufficient level of user authentication for a current transaction based on the identified location class, the authentication policy engine to select from the set of one or more authentication techniques to authenticate the user for the current transaction based on the identified location class.

14. The system as in claim 13 wherein the location detection module further comprises a global positioning system (GPS) device.

15. The system as in claim 13 wherein determining a current location further comprises performing a reverse lookup of the mobile device's IP address.

16. The system as in claim 13 wherein determining a current location further comprises performing cell tower triangulation and/or Wifi access point triangulation.

17. The system as in claim 13 wherein determining a current location further comprises performing an approximation by noting a change in the mobile device's position relative to a starting point with a known location.

18. The system as in claim 13 wherein at least one location class is defined as the mobile device being within a given radius of a known specified location.

19. The system as in claim 13 wherein at least one location class is defined as the mobile device being within a specified boundary region or outside of a specified boundary region.

20. The system as in claim 13 wherein the authentication techniques include explicit authentication techniques and non-intrusive authentication techniques.

21. The system as in claim 20 wherein the explicit authentication techniques include one or more of fingerprint authentication, voice or facial recognition, retinal scanning, and PIN entry by the end user.

22. The system as in claim 20 wherein the non-intrusive authentication techniques include authentication based on data collected from one or more user behavior sensors.

23. The system as in claim 22 wherein the user behavior sensors measure a gait of the user, wherein the user is non-intrusively authenticated based on the user's gait being detected.

24. The system as in claim 20 wherein the non-intrusive authentication techniques include detecting presence of one or more peer or network infrastructure devices known to be present at a particular location.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 71257 FRAME: 566. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2025
From: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 073057/0274 →
SECURITY INTEREST Recorded Jul 1, 2025
From: NOK NOK LABS, INC.
To: MUFG BANK, LTD.
Reel/Frame 071773/0493 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY RECORDED PATENT APPLICATION NUMBER 14488747 PREVIOUSLY RECORDED ON REEL 71273 FRAME 25. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Jun 18, 2025
From: VENTURE LENDING & LEASING IX, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071773/0352 →
RELEASE OF SECURITY INTEREST Recorded May 30, 2025
From: VENTURE LENDING & LEASING VIII, INC.; VENTURE LENDING & LEASING IX, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071273/0025 →
RELEASE OF SECURITY INTEREST Recorded May 29, 2025
From: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071257/0566 →
SECURITY INTEREST Recorded Jul 5, 2018
From: NOK NOK LABS, INC.
To: VENTURE LENDING & LEASING IX, INC.; VENTURE LENDING & LEASING VIII, INC.
Reel/Frame 046492/0870 →
SECURITY INTEREST Recorded Jan 12, 2017
From: NOK NOK LABS, INC.
To: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
Reel/Frame 041352/0867 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2014
From: WILSON, BRENDON J.
To: NOK NOK LABS, INC.
Reel/Frame 032234/0427 →
Continuity (2)
Provisional Application 61804568 · Mar 22, 2013
Related Publication 20140289821A1 · Sep 25, 2014