IP Library Granted Patent US 11,842,803
Granted Patent B2
US 11,842,803 · App. 17/712,379 · Granted Dec 12, 2023

Strong authentication via distributed stations

Inventor: Meinhard Dieter Ullrich (Lexington, MA)
Assignee: Imprivata, Inc.
G16H10/60G06F3/0482G16H40/20G16H40/67G16Z99/00H04L63/08H04L67/12H04L67/52H04L67/535H04W4/023H04W4/029H04W4/33H04W64/00H04W12/06H04W12/63H04W60/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,842,803
App. No.
17/712,379
Granted
Dec 12, 2023
Kind
B2
Abstract

In various embodiments, authentication stations are distributed within a facility, particularly in spaces where mobile devices are predominantly used—e.g., a hospital's emergency department. Each such station includes a series of authentication devices. Mobile device may run applications for locating the nearest such station and, in some embodiments, pair wirelessly with the station so that authentication thereon will accord a user access to the desired resource via a mobile device.

Claims (29)

1. A system for facilitating user authentication and enabling access to secure resources via a computer network using an authentication modality, the system comprising:

a computer network;

a plurality of computational devices each configured to provide user access to one or more secure resources via the computer network but lacking the authentication modality;

an authentication server; and

a plurality of authentication stations each being different from the authentication server and each being configured to (i) receive, using the authentication modality, authentication credentials from a user located at the authentication station, (ii) transmit the authentication credentials to the authentication server, and (iii) receive an authentication confirmation from the authentication server;

wherein user access to the one or more secure resources at one or more of the computational devices is enabled by the authentication confirmation.

2. The system of claim 1 , wherein at least one of the authentication stations comprises one or more of a fingerprint reader, a proximity-card reader, a smart-card reader, a vein reader, an iris scanner, or a soft token application.

3. The system of claim 1 , wherein at least one of the authentication stations comprises two or more of a fingerprint reader, a proximity-card reader, a smart-card reader, a vein reader, an iris scanner, or a soft token application.

4. The system of claim 1 , wherein at least some of the computational devices are mobile devices of users.

5. The system of claim 1 , wherein the authentication stations are not configured to provide user access to one or more secure resources via the computer network.

6. The system of claim 1 , further comprising one or more second computational devices each configured to provide user access to one or more secure resources via the computer network and each comprising the authentication modality, each second computational device being configured to function as an authentication station when not being otherwise utilized by a user.

7. The system of claim 6 , further comprising a location server maintaining a database relating the second computational devices to their physical locations.

8. The system of claim 7 , wherein the database relates the second computational devices to their use statuses.

9. The system of claim 7 , wherein the database relates the authentication stations to their physical locations.

10. The system of claim 1 , wherein one or more of the authentication stations is configured for wireless communication with mobile devices of users.

11. The system of claim 1 , further comprising a location server maintaining a database relating the authentication stations to their physical locations.

12. A system enabling access to secure resources, on a mobile device of a user via a computer network using an authentication modality, wherein the mobile device lacks the authentication modality, the system comprising:

a computer network;

an authentication server; and

a plurality of authentication stations each being different from the authentication server and each being configured to (i) receive, using the authentication modality, authentication credentials from a user located at the authentication station, and (ii) transmit the authentication credentials to the authentication server and/or to the mobile device of the user;

wherein the authentication server is configured to issue an authentication confirmation based on the authentication credentials, the authentication confirmation enabling access to the secure resources to the user on the mobile device.

13. The system of claim 12 , wherein the authentication server is configured to receive the authentication credentials from an authentication station and transmit the authentication confirmation to said authentication station.

14. The system of claim 12 , wherein the authentication server is configured to receive the authentication credentials from an authentication station and transmit the authentication confirmation to the mobile device.

15. The system of claim 12 , wherein the authentication server is configured to receive the authentication credentials from the mobile device and transmit the authentication confirmation to the mobile device.

16. The system of claim 12 , wherein the mobile device comprises a display and a mapping application configured to cause a map showing a current location of the mobile device and a location of at least one said authentication station to appear on the display.

17. The system of claim 12 , wherein the mobile device is configured to wirelessly claim an identified authentication station until the authentication credentials have been received by the authentication station.

18. The system of claim 12 , wherein at least one authentication station is configured to be claimed, via wireless communication with the mobile device, until the authentication credentials have been received by the authentication station or until a predetermined time period has elapsed.

19. The system of claim 12 , wherein at least one of the authentication stations comprises one or more of a fingerprint reader, a proximity-card reader, a smart-card reader, a vein reader, an iris scanner, or a soft token application.

20. The system of claim 12 , wherein at least one of the authentication stations comprises two or more of a fingerprint reader, a proximity-card reader, a smart-card reader, a vein reader, an iris scanner, or a soft token application.

Assignments (4)
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY COLLATERAL AT REEL/FRAME NO. 68553/0806 Recorded Sep 18, 2024
From: BLUE OWL CAPITAL CORPORATION (FORMERLY KNOWN AS OWL ROCK CAPITAL CORPORATION), AS COLLATERAL AGENT
To: IMPRIVATA, INC.
Reel/Frame 068981/0790 →
INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT (1L) Recorded Aug 12, 2024
From: IMPRIVATA, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 068551/0623 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT (2L) Recorded Aug 12, 2024
From: IMPRIVATA, INC.
To: BLUE OWL CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 068553/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2023
From: ULLRICH, MEINHARD DIETER
To: IMPRIVATA, INC.
Reel/Frame 064505/0599 →
Continuity (6)
Continuation 16834117 · Mar 30, 2020
Continuation 16108736 · Aug 22, 2018
Continuation 14945671 · Nov 19, 2015
Provisional Application 62183793 · Jun 24, 2015
Provisional Application 62081820 · Nov 19, 2014
Related Publication 20220230717A1 · Jul 21, 2022