IP Library Granted Patent US 11,693,941
Granted Patent B2
US 11,693,941 · App. 17/120,002 · Granted Jul 4, 2023

Multi-factor authentication for access control using a wearable device

Inventor: Joshua Perry (Sandy, UT)
G06F21/34G06F21/31G06F21/35G07C9/00904H04L9/3234H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,693,941
App. No.
17/120,002
Granted
Jul 4, 2023
Kind
B2
Abstract

A system and method for providing multi-factor authentication for access through a door, but without the user having to repeat a physical act of providing authentication every time that the door is opened, wherein the first time through the door, multi-factor authentication is provided to the access control system, and wherein each subsequent access through the door, multi-factor authentication is performed automatically and without intervention of the user as long as the user has a wearable device providing at least one factor of the multi-factor authentication, and the user has not removed the wearable device since the multi-factor authentication was last provided to the access control system.

Claims (24)

1. A method for multi-factor authentication of a user to an access control system using manual authentication of credentials, and never having to repeat manual authentication as long as the user does not invalidate the credentials, said method comprising:

pairing a first electronic device and a second electronic device to each other so they may communicate, wherein the first and the second electronic devices are running an authentication program that enables authentication of a user by proving knowledge, possession or inherence of the user and wherein the second electronic device only communicates with the first electronic device;

authenticating the identity of the user on the first electronic device;

placing the second electronic device on the user such that the second electronic device remains in physical contact with the user;

authenticating the identity of the user on the second electronic device;

transmitting a signal from the second electronic device to the first electronic device that the user is authenticated;

waiting for the user to come within range of an access control system of a door, and when the user comes within range, verifying that the second electronic device still has valid credentials for the user by not losing physical contact with the user;

receiving challenge data at the first electronic device from the access control system, sending the challenge data to a secure element in the first electronic device, encrypting the challenge data with a private key in the secure element to create an encrypted private key, and transmitting the encrypted private key from the first electronic device to the access control system;

receiving the encrypted private key by the access control system and verifying that the user has valid multi-factor authentication credentials by verifying the encrypted private key;

re-transmitting challenge data to the first electronic device whenever the first electronic device comes within range of the access control system; and

automatically sending the challenge data to the secure element, encrypting the challenge data with the private key in the secure element, and transmitting the encrypted private key to the access control system without having to re-authenticate the identity of the user.

2. A system for multi-factor authentication of a user to an access control system using manual authentication of credentials, and never having to repeat manual authentication as long as the user does not invalidate the credentials, the system comprising:

one or more processors; and

one or more memories coupled to the processor, wherein the memory comprises instructions which, when executed by the processor, cause the processor to:

pair a first electronic device and a second electronic device to each other so they may communicate, wherein the first and the second electronic devices are running an authentication program that enables authentication of a user by proving knowledge, possession or inherence of the user and wherein the second electronic device only communicates with the first electronic device;

authenticate the identity of the user on the first electronic device;

place the second electronic device on the user such that the second electronic device remains in physical contact with the user;

authenticate the identity of the user on the second electronic device;

transmit a signal from the second electronic device to the first electronic device that the user is authenticated;

wait for the user to come within range of an access control system of a door, and when the user comes within range, verify that the second electronic device still has valid credentials for the user by not losing physical contact with the user;

receive challenge data at the first electronic device from the access control system, send the challenge data to a secure element in the first electronic device, encrypt the challenge data with a private key in the secure element to create an encrypted private key, and transmit the encrypted private key from the first electronic device to the access control system;

receive the encrypted private key by the access control system and verify that the user has valid multi-factor authentication credentials by verifying the encrypted private key;

re-transmit challenge data to the first electronic device whenever the first electronic device comes within range of the access control system; and

automatically send the challenge data to the secure element, encrypt the challenge data with the private key in the secure element, and transmit the encrypted private key to the access control system without having to re-authenticate the identity of the user.

Assignments (2)
SECURITY INTEREST Recorded Aug 8, 2024
From: PRODATAKEY, INC.
To: ZIONS BANCORPORATION, N.A.
Reel/Frame 068225/0687 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2022
From: PERRY, JOSHUA
To: PRODATA KEY, LLC
Reel/Frame 061534/0319 →
Continuity (2)
Provisional Application 62946835 · Dec 11, 2019
Related Publication 20210184858A1 · Jun 17, 2021
Cited By (1)
US 12,387,191