Strong authentication via distributed stations
In various embodiments, authentication stations are distributed within a facility, particularly in spaces where mobile devices are predominantly used—e.g., a hospital's emergency department. Each such station includes a series of authentication devices. Mobile device may run applications for locating the nearest such station and, in some embodiments, pair wirelessly with the station so that authentication thereon will accord a user access to the desired resource via a mobile device.
1. A system for facilitating user authentication and enabling access to secure resources via a computer network using an authentication modality, the system comprising:
a computer network;
a plurality of computational devices each configured to provide user access to one or more secure resources via the computer network but lacking the authentication modality;
an authentication server; and
a plurality of authentication stations each being different from the authentication server and each being configured to (i) receive, using the authentication modality, authentication credentials from a user located at the authentication station, (ii) transmit the authentication credentials to the authentication server, and (iii) receive an authentication confirmation from the authentication server;
wherein user access to the one or more secure resources at one or more of the computational devices is enabled by the authentication confirmation.
2. The system of claim 1 , wherein at least one of the authentication stations comprises one or more of a fingerprint reader, a proximity-card reader, a smart-card reader, a vein reader, an iris scanner, or a soft token application.
3. The system of claim 1 , wherein at least one of the authentication stations comprises two or more of a fingerprint reader, a proximity-card reader, a smart-card reader, a vein reader, an iris scanner, or a soft token application.
4. The system of claim 1 , wherein at least some of the computational devices are mobile devices of users.
5. The system of claim 1 , wherein the authentication stations are not configured to provide user access to one or more secure resources via the computer network.
6. The system of claim 1 , further comprising one or more second computational devices each configured to provide user access to one or more secure resources via the computer network and each comprising the authentication modality, each second computational device being configured to function as an authentication station when not being otherwise utilized by a user.
7. The system of claim 6 , further comprising a location server maintaining a database relating the second computational devices to their physical locations.
8. The system of claim 7 , wherein the database relates the second computational devices to their use statuses.
9. The system of claim 7 , wherein the database relates the authentication stations to their physical locations.
10. The system of claim 1 , wherein one or more of the authentication stations is configured for wireless communication with mobile devices of users.
11. The system of claim 1 , further comprising a location server maintaining a database relating the authentication stations to their physical locations.
12. A system enabling access to secure resources, on a mobile device of a user via a computer network using an authentication modality, wherein the mobile device lacks the authentication modality, the system comprising:
a computer network;
an authentication server; and
a plurality of authentication stations each being different from the authentication server and each being configured to (i) receive, using the authentication modality, authentication credentials from a user located at the authentication station, and (ii) transmit the authentication credentials to the authentication server and/or to the mobile device of the user;
wherein the authentication server is configured to issue an authentication confirmation based on the authentication credentials, the authentication confirmation enabling access to the secure resources to the user on the mobile device.
13. The system of claim 12 , wherein the authentication server is configured to receive the authentication credentials from an authentication station and transmit the authentication confirmation to said authentication station.
14. The system of claim 12 , wherein the authentication server is configured to receive the authentication credentials from an authentication station and transmit the authentication confirmation to the mobile device.
15. The system of claim 12 , wherein the authentication server is configured to receive the authentication credentials from the mobile device and transmit the authentication confirmation to the mobile device.
16. The system of claim 12 , wherein the mobile device comprises a display and a mapping application configured to cause a map showing a current location of the mobile device and a location of at least one said authentication station to appear on the display.
17. The system of claim 12 , wherein the mobile device is configured to wirelessly claim an identified authentication station until the authentication credentials have been received by the authentication station.
18. The system of claim 12 , wherein at least one authentication station is configured to be claimed, via wireless communication with the mobile device, until the authentication credentials have been received by the authentication station or until a predetermined time period has elapsed.
19. The system of claim 12 , wherein at least one of the authentication stations comprises one or more of a fingerprint reader, a proximity-card reader, a smart-card reader, a vein reader, an iris scanner, or a soft token application.
20. The system of claim 12 , wherein at least one of the authentication stations comprises two or more of a fingerprint reader, a proximity-card reader, a smart-card reader, a vein reader, an iris scanner, or a soft token application.