IP Library Granted Patent US 10,997,302
Granted Patent B2
US 10,997,302 · App. 16/026,089 · Granted May 4, 2021

Private audio-visual feedback for user authentication

Inventors: Moshe Karako (Kiryat-Ono, IL); Yaacov Hoch (Ramat-Gan, IL)
Assignee: NEC Corporation Of America
G06F21/604G06K19/0723H04L63/083H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,997,302
App. No.
16/026,089
Granted
May 4, 2021
Kind
B2
Abstract

A computer implemented method of authenticating a user accessing a secure terminal, comprising obtaining identification information stored in a personal machine readable storage medium exclusively associated with an accessing user attempting to access a secure system, retrieving authentication information exclusively associated with the accessing user from a remote network resource using the identification information, operating one or more privately directed user interfaces to exclusively present to the accessing user a requested alteration to a challenge request generated based on the authentication information and presented via another user interface, receiving a response to the challenge request from the accessing user and granting the accessing user access to the secure terminal in case the response matches the altered challenge request and denying access in case of no match. The privately directed user interface(s) is adapted to make the presentation of the required alteration discernable only by the accessing user.

Claims (34)

1. A computer implemented method of authenticating a user accessing a secure terminal, comprising:

using at least one processor for:

obtaining identification information stored in a personal machine readable storage medium exclusively associated with an accessing user attempting to access a secure terminal which is a member of a group consisting of: an Automated Teller Machine (ATM), an automated kiosk, a vending machine, and a door digital lock;

retrieving authentication information exclusively associated with the accessing user from a remote network resource using the identification information, the authentication information is required to verify a response of the accessing user to a challenge request;

operating at least one user interface to present the challenge request to the accessing user, wherein the at least one user interface is prone to eavesdropping;

generating a random alteration to the challenge request and compute instructions for the random alteration;

operating at least one privately directed user interface to exclusively present the random alteration instructions to the accessing user, the at least one privately directed user interface is adapted to make the presentation of the random alteration instructions discernable only by the accessing user;

receiving a response to the altered challenge request from the accessing user;

restoring the response to remove the random alteration the accessing user was instructed to apply in order to produce a restored representation of the authentication information; and

instructing the secure terminal to grant access to the accessing user in case the restored representation matches the authentication information and deny access in case the restored representation does not match the authentication information;

wherein the at least one privately directed user interface is a member of a group comprising: a privately directed visual interface adapted to generate a visual presentation of the random alteration instructions visible only to the accessing user, a wearable audio aid adapted to generate an audible presentation of the random alteration instructions audible only to the accessing user, a directed speaker adapted to emit a narrow sound beam audible only to the accessing user and a client device associated with the accessing user adapted to generate a presentation discernable only by the accessing user;

wherein the at least one of the visual presentation, the audible presentation, and the presentation discernable only by the accessing user are generated to be conceived by the accessing user only when the accessing user is located in a designated location to ensure that only the accessing user is presented with the random alteration instructions;

wherein the authentication information comprising at least one member of a group consisting of: a private identification number (PIN), a password, a code and a security question.

2. The computer implemented method of claim 1 , wherein the personal machine readable storage medium is a magnetic card comprising a magnetic band for coding the authentication information.

3. The computer implemented method of claim 1 , wherein the personal machine readable storage medium is a smart card comprising an integrated card for storing the authentication information.

4. The computer implemented method of claim 1 , wherein the personal machine readable storage medium comprising a radio frequency identification (RFID) component for storing the authentication information.

5. The computer implemented method of claim 1 , wherein the required random alteration to the challenge request comprises a request to enter a representation of the authentication information after altered according to the required random alteration.

6. The computer implemented method of claim 1 , wherein the required random alteration to the challenge request comprises a request to enter alternative authentication information compared to the authentication information requested by the challenge request.

7. The computer implemented method of claim 1 , further comprising generating at least one additional required random alteration to at least one another challenge request presented to the accessing user to further authenticate the accessing user.

8. A system for authenticating a user accessing a secure terminal, comprising:

a tangible program store device storing a code; and

at least one processor of a secure terminal coupled to the program store for executing the stored code, the code comprising:

code instructions to obtain identification information stored in a personal machine readable storage medium exclusively associated with an accessing user attempting to access a secure terminal which is a member of a group consisting of: an Automated Teller Machine (ATM), an automated kiosk, a vending machine, and a door digital lock,

code instructions to retrieve authentication information exclusively associated with the accessing user from a remote network resource using the identification information, the authentication information is required to verify a response of the accessing user to a challenge request,

code instructions to operate at least one user interface to present the challenge request to the accessing user, wherein the at least one user interface is prone to eavesdropping,

code instructions to generate a random alteration to the challenge request and compute instructions for the random alteration,

code instructions to operate at least one privately directed user interface to exclusively present the random alteration instructions to the accessing user, the at least one privately directed user interface is adapted to make the presentation of the random alteration instructions discernable only by the accessing user,

code instructions to receive a response to the altered challenge request from the accessing user,

code instructions to restore the response to remove the random alteration the accessing user was instructed to apply in order to produce a restored representation of the authentication information, and

code instructions to instruct the secure terminal to grant access to the accessing user in case the restored representation matches the authentication information and deny access in case the restored representation does not match the authentication information,

wherein the at least one privately directed user interface is a member of a group comprising: a privately directed visual interface adapted to generate a visual presentation of the random alteration instructions visible only to the accessing user, a wearable audio aid adapted to generate an audible presentation of the random alteration instructions audible only to the accessing user, a directed speaker adapted to emit a narrow sound beam audible only to the accessing user and a client device associated with the accessing user adapted to generate a presentation discernable only by the accessing user;

wherein the at least one of the visual presentation, the audible presentation, and the presentation discernable only by the accessing user are generated to be conceived by the accessing user only when the accessing user is located in a designated location to ensure that only the accessing user is presented with the random alteration instructions;

wherein the authentication information comprising at least one member of a group consisting of: a private identification number (PIN), a password, a code and a security question.

9. The computer implemented method of claim 1 , wherein the privately directed user interface is integrated in the secure terminal.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2024
From: NEC CORPORATION OF AMERICA
To: NEC CORPORATION
Reel/Frame 068039/0047 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2018
From: KARAKO, MOSHE; HOCH, YAACOV
To: NEC CORPORATION OF AMERICA
Reel/Frame 046520/0726 →
Continuity (1)
Related Publication 20200012800A1 · Jan 9, 2020