SYSTEM AND METHOD FOR PERFORMING AUTHENTICATION FOR A LOCAL TRANSACTION
A system, apparatus, method, and machine readable medium are described for strong authentication for a local transaction. For example, one embodiment of a system comprises: a local transaction device; a client device performing one or more authentication transactions including receiving biometric input from the user to generate an authentication result; a secure transaction service communicatively coupled to the local transaction device over a network, the secure transaction service receiving the authentication result from the client device; and the remote secure transaction service transmitting a signal to the local transaction device to perform one or more operations if the authentication result is sufficient to complete a transaction.
1 . A method comprising:
receiving a request from a client device to perform a transaction at a local transaction device; and
performing one or more authentication transactions including receiving biometric input from the user on the client device to generate an authentication result;
transmitting the authentication result to a remote secure transaction service; and
the remote secure transaction service transmitting a signal to the local transaction device to perform one or more operations if the authentication result is sufficient to complete the transaction.
2 . The method as in claim 1 wherein performing one or more authentication transactions comprises determining an assurance level that a current user of the client is a legitimate user for the transaction.
3 . The method as in claim 2 further comprising:
establishing a local communication channel between the client device and the local transaction device; and
utilizing the local communication channel for one of the one or more authentication transactions.
4 . The method as in claim 3 wherein the local communication channel comprises a near field communication (NFC) channel, a Bluetooth communication channel and/or a Wifi communication channel.
5 . The method as in claim 3 wherein the client device receives first authentication data from the remote secure transaction service and passes the authentication data to the local transaction device over the local communication channel.
6 . The method as in claim 5 wherein the first authentication data comprises a code transmitted to the local transaction device over the local communication channel.
7 . The method as in claim 1 wherein the local transaction device comprises a automatic teller machine (ATM) and wherein the one or more operations includes dispensing a user-specified amount of cash.
8 . The method as in claim 1 wherein the assurance level is determined based, at least in part, on one or more explicit user authentication operations in which the biometric data provided by the user is compared against biometric reference data.
9 . The method as in claim 8 wherein the biometric data comprises fingerprint data, facial image data, and/or voice data.
10 . The method as in claim 8 wherein the assurance level is determined based, at least in part, on results of one or more non-intrusive authentication techniques in which the user is not required to enter biometric or other user data.
11 . The method as in claim 9 wherein the non-intrusive authentication techniques include determining a period of time since a last explicit user authentication.
12 . The method as in claim 9 wherein the non-intrusive authentication techniques include collecting and analyzing sensor data from one or more sensors on the client device.
13 . The method as in claim 12 wherein at least one of the sensors comprises a location sensor indicating a current location of the client device.
14 . A system comprising:
a local transaction device;
a client device performing one or more authentication transactions including receiving biometric input from the user to generate an authentication result;
a secure transaction service communicatively coupled to the local transaction device over a network, the secure transaction service receiving the authentication result from the client device; and
the remote secure transaction service transmitting a signal to the local transaction device to perform one or more operations if the authentication result is sufficient to complete a transaction.
15 . The system as in claim 14 wherein performing one or more authentication transactions comprises determining an assurance level that a current user of the client is a legitimate user for the transaction.
16 . The system as in claim 15 further comprising:
a first communication interface on the local transaction device;
a second communication interface on the client device;
wherein the client device and the local transaction device establish a local communication channel through the network interfaces and utilize the local communication channel for one of the one or more authentication transactions.
17 . The system as in claim 16 wherein the local communication channel comprises a near field communication (NFC) channel, a Bluetooth communication channel and/or a Wifi communication channel.
18 . The system as in claim 16 wherein the client device receives first authentication data from the remote secure transaction service and passes the authentication data to the local transaction device over the local communication channel.
19 . The system as in claim 18 wherein the first authentication data comprises a code transmitted to the local transaction device over the local communication channel.
20 . The system as in claim 14 wherein the local transaction device comprises a automatic teller machine (ATM) and wherein the one or more operations includes dispensing a user-specified amount of cash.
21 . The system as in claim 14 wherein the assurance level is determined based, at least in part, on one or more explicit user authentication operations in which the biometric data provided by the user is compared against biometric reference data.
22 . The system as in claim 21 wherein the biometric data comprises fingerprint data, facial image data, and/or voice data.
23 . The system as in claim 21 wherein the assurance level is determined based, at least in part, on results of one or more non-intrusive authentication techniques in which the user is not required to enter biometric or other user data.
24 . The system as in claim 22 wherein the non-intrusive authentication techniques include determining a period of time since a last explicit user authentication.
25 . The system as in claim 22 further comprising one or more sensors on the client device, wherein the non-intrusive authentication techniques include collecting and analyzing sensor data collected from the one or more sensors.
26 . The system as in claim 25 wherein at least one of the sensors comprises a location sensor indicating a current location of the client device.