IP Library › Granted Patent US 8,732,795
Granted Patent B2
US 8,732,795 · App. 13/111,290 · Granted May 20, 2014

System and method for user authentication

Inventors: Trent N. Skeel (Madison, WI); Eric W. Cooper (Madison, WI); Travis Keshav (Verona, WI)
Assignee: Epic Systems Corporation
H04L9/32H04L63/083H04L67/146H04L2463/082H04L9/00H04L9/006H04L63/08H04L63/0807
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,732,795
App. No.
13/111,290
Granted
May 20, 2014
Kind
B2
Abstract

A computer-implemented authentication method is described. The method includes the steps of (a) receiving an authentication request at an authentication computing system, the request including a resource identifier, (b) identifying one or more authentication pools associated with the resource identifier, each authentication pool including at least one authentication method implementation, (c) executing a pool authentication process for the one or more identified authentication pools, and (d) transmitting a response to the identification authentication request based on the execution of the pool authentication process for the one or more identified authentication pools.

Claims (45)

1. A computer-implemented authentication method, comprising:

(a) receiving an authentication request at an authentication computing system, the request including a resource identifier;

(b) identifying one or more authentication pools associated with the resource identifier, each authentication pool including at least one authentication method selected from the group including a password, passphrase, personal identification number, challenge response, identification card, wristband, security token, software token, cell phone, biometric information, fingerprint, retinal pattern, signature, face, and voice;

(c) executing a pool authentication process for the one or more identified authentication pools, the pool authentication process including a two stage authentication process, including at least one first stage that includes performing an authentication method implementation included in the authentication pool and a second stage dependent on the first stage; and

(d) transmitting a response to the identification authentication request based on the execution of the pool authentication process for the one or more identified authentication pools.

2. The method of claim 1 , wherein executing a pool authentication process includes identifying the one or more authentication method implementations that are to be performed.

3. The method of claim 2 , wherein executing a pool authentication process further includes generating an authentication method response, including

transmitting information to one or more of the identified authentication method implementations;

generating a device authentication response based on the transmitted information.

4. The method of claim 2 , further including determining whether an authentication method implementation has been used in the current authentication process in any authentication pool.

5. The method of claim 4 , further including selecting an alternate method implementation from an authentication pool based on a determination that an authentication method implementation has been used in the current authentication process.

6. The method of claim 1 , wherein identifying one or more authentication pools associated with the resource identifier includes accessing an authentication database including a table of resource identifiers and a table of authentication pools, each resource identifier including an association with one or more authentication pools, each authentication pool including an association with one or more authentication method implementations.

7. The method of claim 6 , wherein the table includes at least one authentication method implementation associated with more than one authentication pool.

8. The method of claim 1 , wherein the authentication request includes a request to identify a patient seeking medical care using a biometric reader as at least one authentication method implementation in the authentication process.

9. The method of claim 1 , wherein the authentication request includes a request to identify a medicine to be administered to a patient using a barcode reader as at least one authentication method implementation in the authentication process.

10. A computer-implemented authentication system, comprising:

an authentication data table, the table including

one or more resource identifiers, and

at least one authentication pool associated with each resource identifier, the pool including at least one authentication method selected from the group including a password, passphrase, personal identification number, challenge response, identification card, wristband, security token, software token, cell phone, biometric information, fingerprint, retinal pattern, signature, face, and voice;

an authentication engine configured to

receive an authentication request at an authentication computing system, the request including a resource identifier,

identify one or more authentication pools associated with the resource identifier, and

execute a pool authentication process for the one or more identified authentication pools, the pool authentication process including a two stage authentication process, including at least one first stage that includes performing an authentication method implementation included in the authentication pool and a second stage dependent on the first stage; and

an authentication reporting engine configured to provide a response to the identification authentication request based on the execution of the pool authentication process for the one or more identified authentication pools.

11. The system of claim 10 , wherein executing a pool authentication process includes identifying the one or more authentication method implementations that are to be performed.

12. The system of claim 11 , wherein executing a pool authentication process further includes generating an authentication method response, including

transmitting information to one or more of the identified authentication method implementations;

generating a device authentication response based on the transmitted information.

13. The system of claim 11 , wherein the authentication engine is configured to determine whether an authentication method implementation has been used in the current authentication process in any authentication pool.

14. The system of claim 13 , wherein the authentication engine is configured to select an alternate method implementation from an authentication pool based on a determination that an authentication method implementation has been used in the current authentication process.

15. The system of claim 10 , wherein the data table includes at least one authentication method implementation associated with more than one authentication pool.

16. The system of claim 10 , wherein the authentication request includes a request to identify a patient seeking medical care using a biometric reader as at least one authentication method implementation in the authentication process.

17. The system of claim 10 , wherein the authentication request includes a request to identify a medicine to be administered to a patient using a barcode reader as at least one authentication method implementation in the authentication process.

18. A computer-implemented authentication system for use in administering a controlled substance, comprising:

an authentication data table, the table including

one or more resource identifiers associated with the controlled substance, and

at least two authentication pools associated with the one or more resource identifiers, each pool including at least one authentication method selected from the group including a password, passphrase, personal identification number, challenge response, identification card, wristband, security token, software token, cell phone, biometric information, fingerprint, retinal pattern, signature, face, and voice;

an authentication engine configured to

receive an authentication request at an authentication computing system, the request including a resource identifier,

identify at least first and second authentication pools associated with the resource identifier,

execute a pool authentication process for the first identified authentication pool, including executing a first authentication method implementation, and

execute a pool authentication process for the second identified authentication pool, including executing a second authentication method implementation that is different than the first authentication method; and

an authentication reporting engine configured to provide a response to the identification authentication request based on a determination indicating successful execution of the first and second pool authentication processes for the at least first and second identified authentication pools.

19. The system of claim 18 , wherein the authentication engine is configured to determine whether an authentication method implementation has been used in the current authentication process in any authentication pool.

20. The system of claim 18 , wherein first and second authentication pools including authentication methods directed to at least authentication an identity of a healthcare provider authorized to administer the controlled substance.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2011
From: SKEEL, TRENT N; COOPER, ERIC W; KESHAV, TRAVIS
To: EPIC SYSTEMS CORPORATION
Reel/Frame 026310/0099 →
Continuity (3)
Provisional Application 61447316 · Feb 28, 2011
Provisional Application 61347116 · May 21, 2010
Related Publication 20110289572A1 · Nov 24, 2011