IP Library Granted Patent US 11,936,646
Granted Patent B2
US 11,936,646 · App. 16/273,830 · Granted Mar 19, 2024

Online authentication systems and methods

Inventors: Ron M. Pitters (Fallbrook, CA); Janakiramana Rao Yandapalli (San Diego, CA)
Assignee: AXOS BANK
H04L63/0861G06F9/452G06F21/33G06F21/53H04L63/0838
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,936,646
App. No.
16/273,830
Granted
Mar 19, 2024
Kind
B2
Abstract

A server may include at least one server processor configured to execute an application. A desktop virtualization system may include at least one desktop virtualization processor. The desktop virtualization processor may be configured to instantiate a virtual desktop; authenticate a user of a client device; in response to authenticating the user of the client device, place the client device in communication with the virtual desktop through at least one network; launch a secure browser in the virtual desktop; and using the secure browser, place the client device in communication with the server through the at least one network. The application may be configured to perform processing in response to at least one command from the client device sent through the secure browser of the virtual desktop.

Claims (81)

1. An authentication system comprising:

a server including at least one server processing device configured to execute an application; and

a desktop virtualization system including at least one virtualization system processing device configured to:

instantiate connection functionality at an access point accessible from outside a first firewall controlling access to the desktop virtualization system;

instantiate a virtual desktop behind the first firewall within the desktop virtualization system, the virtual desktop providing a secure computing environment;

receive an indication that a user of a client device outside the first firewall is authenticated for access through the first firewall to the secure computing environment by the access point at a first time before the client device is in communication with the virtual desktop;

in response to receiving the indication that the user of the client device is authenticated, authenticate the user of the client device for access through a second firewall within the secure computing environment controlling access to the server at a second time after receiving the indication that the user of the client device is authenticated at the first time;

in response to authenticating the user of the client device at the second time, place the client device in communication with the virtual desktop through the at least one network;

launch a secure browser in the virtual desktop; and

using the secure browser, place the client device in communication with the server through the at least one network;

wherein the application is configured to perform processing in response to at least one command from the client device sent through the secure browser of the virtual desktop.

2. The authentication system of claim 1 , further comprising the client device including at least one client processing device.

3. The authentication system of claim 2 , wherein the at least one client processing device is configured to:

perform processing associated with authenticating the user and sending the at least one command; and

prevent processing associated with tasks unrelated to the processing associated with authenticating the user and sending the at least one command.

4. The authentication system of claim 2 , wherein the client device comprises at least one biometric sensor.

5. The authentication system of claim 4 , wherein the at least one virtualization system processing device is configured to authenticate the user by:

receiving biometric data from the at least one biometric sensor; and

determining that the biometric data matches known biometric data of the user.

6. The authentication system of claim 5 , wherein the at least one virtualization system processing device is further configured to authenticate the user by:

receiving additional credentials from the client device; and

determining that the additional credentials match known credentials of the user.

7. The authentication system of claim 1 , wherein the at least one virtualization system processing device is configured to authenticate the user by:

causing an authentication service to issue a one-time passcode for the user;

receiving the one-time passcode from the client device; and

determining that the one-time passcode from the client device matches the one-time passcode issued by the authentication service.

8. The authentication system of claim 7 , wherein the at least one virtualization system processing device is further configured to authenticate the user by:

receiving additional credentials from the client device; and

determining that the additional credentials match known credentials of the user.

9. The authentication system of claim 1 , wherein the at least one virtualization system processing device is configured to authenticate the user by:

receiving biometric data from the client device; and

determining that the biometric data matches known biometric data of the user.

10. The authentication system of claim 9 , wherein the at least one virtualization system processing device is further configured to authenticate the user by:

receiving additional credentials from the client device; and

determining that the additional credentials match known credentials of the user.

11. The authentication system of claim 1 , wherein the at least one server processing device is configured to:

receive user authentication information from the secure browser; and

prior to performing the processing in response to the at least one command, validating the user authentication information.

12. The authentication system of claim 1 , wherein:

the application is a banking application; and

the processing includes performing at least one banking task.

13. An authentication method comprising:

instantiating, by at least one system processing device, connection functionality at an access point accessible from outside a first firewall controlling access to a desktop virtualization system;

instantiating, by the at least one system processing device, a virtual desktop behind the first firewall within the desktop virtualization system, the virtual desktop providing a secure computing environment;

receiving an indication, at the at least one system processing device, a user of a client device outside the first firewall is authenticated for access through the first firewall to the secure computing environment by the access point at a first time before the client device is in communication with the virtual desktop;

in response to receiving the indication that the user of the client device is authenticated, authenticating, by the at least one system processing device, a user of a client device for access through a second firewall within the secure computing environment controlling access to the server at a second time after receiving the indication that the user of the client device is authenticated at the first time;

in response to authenticating the user of the client device, placing, by the at least one system processing device, the client device in communication with the virtual desktop through at least one network;

launching, by the at least one system processing device, a secure browser in the virtual desktop;

using the secure browser, placing, by the at least one system processing device, the client device in communication with a server through the at least one network; and

performing, by at least one server processing device, processing in response to at least one command from the client device sent through the secure browser of the virtual desktop.

14. The authentication method of claim 13 , further comprising:

performing, by at least one client processing device, processing associated with authenticating the user and sending the at least one command; and

preventing, by the at least one client processing device, processing associated with tasks unrelated to the processing associated with authenticating the user and sending the at least one command.

15. The authentication method of claim 13 , wherein the authenticating comprises:

receiving biometric data from the client device; and

determining that the biometric data matches known biometric data of the user.

16. The authentication system of claim 15 , wherein the authenticating further comprises:

receiving additional credentials from the client device; and

determining that the additional credentials match known credentials of the user.

17. The authentication method of claim 15 , further comprising collecting, by at least one biometric sensor of the client device, the biometric data.

18. The authentication method of claim 13 , wherein the authenticating comprises:

causing an authentication service to issue a one-time passcode for the user;

receiving the one-time passcode from the client device; and

determining that the one-time passcode from the client device matches the one-time passcode issued by the authentication service.

19. The authentication method of claim 18 , wherein the authenticating further comprises:

receiving additional credentials from the client device; and

determining that the additional credentials match known credentials of the user.

20. The authentication method of claim 13 , further comprising:

receiving, by the at least one server processing device, user authentication information from the secure browser; and

prior to performing the processing in response to the at least one command, validating, by the at least one server processing device, the user authentication information.

21. An authentication system comprising:

a server including at least one server processing device configured to execute an application; and

a desktop virtualization system including at least one virtualization system processing device configured to:

instantiate connection functionality at an access point accessible from outside a first firewall controlling access to the desktop virtualization system;

instantiate a virtual desktop behind the first firewall within the desktop virtualization system, the virtual desktop providing a secure computing environment;

receive an indication a user of a client device outside the first firewall is authenticated for access through the first firewall to the secure computing environment by the access point at a first time before the client device is in communication with the virtual desktop;

in response to receiving the indication that the user of the client device is authenticated, authenticate the user of the client device for access through a second firewall within the secure computing environment controlling access to the server at a second time after receiving the indication that the user of the client device is authenticated at the first time;

in response to authenticating the user of the client device at the second time, place the client device in communication with the virtual desktop through at least one network;

in response to placing the client device in communication with the virtual desktop through the at least one network, launch a secure browser in the virtual desktop; and

using the secure browser, place the client device in communication with the server through the at least one network;

wherein the application is configured to perform processing in response to at least one command from the client device sent through the secure browser of the virtual desktop.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2020
From: PITTERS, RON M.; YANDAPALLI, JANAKIRAMANA RAO
To: AXOS BANK
Reel/Frame 052355/0732 →
CHANGE OF NAME Recorded Feb 14, 2019
From: BOFI FEDERAL BANK
To: AXOS BANK
Reel/Frame 048335/0932 →
Continuity (2)
Provisional Application 62629928 · Feb 13, 2018
Related Publication 20190253415A1 · Aug 15, 2019
Cited By (1)
US 12,292,984