IP Library Granted Patent US 9,614,845
Granted Patent B2
US 9,614,845 · App. 14/687,327 · Granted Apr 4, 2017

Anonymous authentication and remote wireless token access

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,614,845
App. No.
14/687,327
Granted
Apr 4, 2017
Kind
B2
Abstract

Provided is a method for operating an authentication server for authenticating a user who is communicating with an enterprise via a network. The method include receiving, via the network, a first authenticator including first information from a low energy wireless device received via a user device wirelessly, and storing the first authenticator. When the authentication service later receives, from the enterprise, a request to authenticate the user, the authentication server transmits an authentication request to the user device via the network requesting that the user read information from the low energy wireless device using the user device. The information received from the low energy wireless device in response to the authentication request is then used authenticate the user by comparing the information received from the low energy wireless device due to the authentication request with the stored first authenticator.

Claims (94)

1. A method of operating an authentication server for authenticating a user who is communicating with an enterprise via a network, comprising:

establishing, via the network, an enterprise account with the enterprise by generating and storing an enterprise account identifier;

establishing, via the network, a user device account with the user device by storing authentifiers received using the user device and storing the authentifiers in association with a device identifier associated with the user device;

generating, after establishing the user device account with the user device, a first asymmetric key pair and storing one key of the first asymmetric key pair and transmitting the other key of the first asymmetric key pair to the user device;

generating, after establishing the user device account and the enterprise account, a relationship account that associates the user device identifier and the enterprise account identifier using a relationship identifier;

transmitting the relationship identifier to the user device;

receiving, after transmitting the relationship identifier to the user device, one key of a second asymmetric key pair from the user device and transmitting the one key of the second asymmetric key pair to the enterprise with the relationship identifier;

receiving, via the network, a first authenticator including first information from a low energy wireless device received via a user device wirelessly, and storing the first authenticator;

receiving, from the enterprise, a request to authenticate he user;

transmitting an authentication request to the user device via the network requesting that the user read information from the low energy wireless device using the user device;

receiving, from the user device via the network, the information received from the low energy wireless device in response to the authentication request; and

authenticating the user by comparing the information received from the low energy wireless device due to the authentication request with the stored first authenticator,

wherein the information received from the low energy wireless device is encrypted by the user device using the other key of the second asymmetric key pair.

2. The method of claim 1 , wherein the first information from the low energy wireless device is hashed and the hashed output is stored as the authenticator as the stored authenticator; and

wherein the information received from the low energy wireless device due to the authentication request is hashed and the hashed output is compared to the hashed output stored as the authenticator to authenticate the user.

3. The method of claim 1 , further comprising:

receiving, via the network, a second authenticator from the user device, and storing the second authenticator;

transmitting an authentication request to the user device via the network requesting the second authenticator; and

receiving, from the first user device via the network, an authenticator in response to the authentication request requesting the second authenticator,

authenticating the user by comparing the received second authenticator with the stored second authenticator,

wherein the authentication request transmitted to the user device via the network requesting that the user read information from the low energy wireless device using the user device is transmitted in response to the user being authenticated using the second authenticator.

4. The method of claim 3 , wherein the first information from the low energy wireless device is hashed and the hashed output is stored as the authenticator as the stored authenticator; and

wherein the information received from the low energy wireless device due to the authentication request is hashed and the hashed output is compared to the hashed output stored as the authenticator to authenticate the user.

5. A method of operating an authentication server for securely exchanging information between a user device and an enterprise via a network, comprising:

receiving, via the network, a request from the enterprise to obtain information from a low energy wireless device associated with a user;

sending the request to obtain information from the low energy wireless device to the user device associated with the user;

receiving information from the low energy wireless device read using the user device, the information encrypted by the user device;

transmitting the encrypted information to the enterprise;

receiving, via the network, second information from the enterprise with a request to transmit the second information from the user device to the low energy wireless device to be encrypted using the low energy wireless device;

transmitting, via the network, the second information and the request to encrypt the second information to the user device; and

receiving the second information encrypted by the low energy wireless device; and

transmitting the encrypted second information to the enterprise.

6. The method of claim 5 , further comprising:

receiving, via the network, an authenticator from the user device, and storing the authenticator;

transmitting an authentication request to the user device via the network requesting the authenticator;

receiving, from the user device via the network, an authenticator in response to the authentication request requesting the authenticator; and

authenticating the user by comparing the received authenticator with the stored authenticator,

wherein the request to obtain information from the low energy wireless device is sent in response to the user being authenticated using the authenticator received from the user device.

7. The method of claim 5 , further comprising: receiving, via the network, an authenticator from the user device, and storing the authenticator; transmitting an authentication request to the user device via the network requesting the authenticator; receiving, from the user device via the network, an authenticator in response to the authentication request requesting the authenticator; and authenticating the user by comparing the received authenticator with the stored authenticator, wherein the second information and the request are transmitted to the user device in response to the user being authenticated using the authenticator received from the user device.

8. The method of claim 5 , further comprising:

receiving one key of an asymmetric key pair from the user device and transmitting the one key to the enterprise without storing the one key,

wherein the second information received from the enterprise is encrypted using an other key of the asymmetric key pair and is transmitted as encrypted second information to the user device with the request.

9. The method of claim 5 , further comprising: receiving one key of an asymmetric key pair from the user device and transmitting the one key to the enterprise without storing the one key, wherein the information received from the low energy wireless device read using the user device is encrypted by the user device using an other key of the asymmetric key pair.

10. The method of claim 5 , further comprising:

establishing, via the network, an enterprise account with the enterprise by generating and storing an enterprise account identifier;

establishing, via the network, a user device account with the user device by storing authenticators received using the user device and storing the authenticators in association with a device identifier associated with the user device;

generating, after establishing the user device account with the user device, a first asymmetric key pair and storing one key of the first asymmetric key pair and transmitting the other key of the first asymmetric key pair to the user device;

generating, after establishing the user device account and the enterprise account, a relationship account that associates the user device identifier and the enterprise account identifier using a relationship identifier;

transmitting the relationship identifier to the user device; and

receiving, after transmitting the relationship identifier to the user device, one key of a second asymmetric key pair from the user device and transmitting the one key of the second asymmetric key pair to the enterprise with the relationship identifier,

wherein the information received from the low energy wireless device is encrypted by the user device using the other key of the second asymmetric key pair.

11. The method of claim 1 , wherein the user device is a mobile device and the low energy wireless device is configured to communicate using Bluetooth, near field communication or Bluetooth low energy.

12. An article of manufacture for authenticating a user who is communicating with an enterprise via a network, comprising:

a non-transitory storage medium; and

logic stored on the storage medium, wherein the stored logic is configured to be readable by a processor and thereby causes the processor to operation so as to:

establish, via the network, an enterprise account with the enterprise by generating and storing an enterprise account identifier;

establish, via the network, a user device account with the user device by storing authentifiers received using the user device and storing the authentifiers in association with a device identifier associated with the user device;

generate, after establishing the user device account with the user device, a first asymmetric key pair and storing one key of the first asymmetric key pair and transmitting the other key of the first asymmetric key pair to the user device;

generate, after establishing the user device account and the enterprise account, a relationship account that associates the user device identifier and the enterprise account identifier using a relationship identifier;

transmit the relationship identifier to the user device;

receive, after transmitting the relationship identifier to the user device, one key of a second asymmetric key pair from the user device and transmitting the one key of the second asymmetric key pair to the enterprise with the relationship identifier;

receive, via the network, a first authenticator including first information from a low energy wireless device received via a user device wirelessly, and store the first authenticator;

receive, from the enterprise, a request to authenticate the user;

transmit an authentication request to the user device via the network requesting that the user read information from the low energy wireless device using the user device;

receive, from the user device via the network, the information received from the low energy wireless device in response to the authentication request; and

authenticate the user by comparing the information received from the low energy wireless device due to the authentication request with the stored first authenticator,

wherein the information received from the low energy wireless device is encrypted by the user device using the other key of the second asymmetric key pair.

13. The article of manufacture of claim 12 , wherein the first information from the low energy wireless device is hashed and the hashed output is stored as the authenticator as the stored authenticator; and

wherein the information received from the low energy wireless device due to the authentication request is hashed and the hashed output is compared to the hashed output stored as the authenticator to authenticate the user.

14. The article of manufacture of claim 12 , wherein the stored logic is further configured to cause the processor to operate so as to:

receive, via the network, a second authenticator from the user device, and store the second authenticator;

transmit an authentication request to the user device via the network requesting the second authenticator; and

receive, from the first user device via the network, an authenticator in response to the authentication request requesting the second authenticator,

authenticate the user by comparing the received second authenticator with the stored second authenticator,

wherein the authentication request transmitted to the user device via the network requesting that the user read information from the low energy wireless device using the user device is transmitted in response to the user being authenticated using the second authenticator.

15. The article of manufacture of claim 14 , wherein the first information from the low energy wireless device is hashed and the hashed output is stored as the authenticator as the stored authenticator; and

wherein the information received from the low energy wireless device due to the authentication request is hashed and the hashed output is compared to the hashed output stored as the authenticator to authenticate the user.

16. An article of manufacture for operating an authentication server for securely exchanging information between a user device and an enterprise via a network, comprising:

a non-transitory storage medium; and

logic stored on the storage medium, wherein the stored logic is configured to be readable by a processor and thereby causes the processor to operation so as to:

receive, via the network, a request from the enterprise to obtain information from a low energy wireless device associated with a user;

send the request to obtain information from the low energy wireless device to the user device associated with the user;

receive information from the low energy wireless device read using the user device, the information encrypted by the user device;

transmit the encrypted information to the enterprise;

receive, via the network, second information from the enterprise with a request to transmit the second information from the user device to the low energy wireless device to be encrypted using the low energy wireless device;

transmit, via the network, the second information and the request to encrypt the second information to the user device; and

receive the second information encrypted by the low energy wireless device; and

transmit the encrypted second information to the enterprise.

17. The method of claim 16 , wherein the stored logic is further configured to cause the processor to operate so as to:

receive, via the network, an authenticator from the user device, and storing the authenticator;

transmit an authentication request to the user device via the network requesting the authenticator;

receive, from the user device via the network, an authenticator in response to the authentication request requesting the authenticator; and

authenticate the user by comparing the received authenticator with the stored authenticator,

wherein the request to obtain information from the low energy wireless device is sent in response to the user being authenticated using the authenticator received from the user device.

Assignments (8)
CHANGE OF NAME Recorded Sep 17, 2024
From: PAYFONE, INC.
To: PROVE IDENTITY, INC.
Reel/Frame 068968/0708 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2020
From: EARLY WARNING SERVICES, LLC
To: PAYFONE, INC.
Reel/Frame 053148/0191 →
CONFIRMATORY GRANT OF SECURITY INTEREST IN PATENTS Recorded Jun 18, 2020
From: PAYFONE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 052984/0061 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR NAME PREVIOUSLY RECORDED AT REEL: 041610 FRAME: 0944. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Aug 23, 2017
From: AUTHENTIFY, LLC
To: EARLY WARNING SERVICES, LLC
Reel/Frame 043649/0549 →
MERGER AND CHANGE OF NAME Recorded Jul 25, 2017
From: AUTHENTIFY, INC.; AUTHENTIFY, LLC
To: AUTHENTIFY, LLC
Reel/Frame 043325/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2017
From: AUTHENTIFY, INC.
To: EARLY WARNING SERVICES, LLC
Reel/Frame 041610/0944 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2017
From: AUTHENTIFY, INC.
To: EARLY WARNING SERVICES, LLC
Reel/Frame 041341/0559 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2015
From: ROLFE, ANDREW ROBERT
To: AUTHENTIFY, INC.
Reel/Frame 035417/0884 →