IP Library Patent Application 13226667
Patent Application
App. No. 13/226,667

RANDOM CHALLENGE ACTION FOR AUTHENTICATION OF DATA OR DEVICES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/226,667
Abstract

An authentication system is enhanced by prompting an individual to perform a randomly-selected challenge action. For example, the individual may be requested to move the device in a particular motion, after entering a username/password combination. The randomly-selected challenge action verifies the individual is located at the device, which prevents automated attacks to steal the individual's identity. The challenge action improves security by preventing attackers from spoofing an individual's authentication information. The enhanced authentication system may be used on mobile devices, such as mobile phones and laptop computers, to provide access to secure data, such as bank account information.

Claims (51)

1 . A method, comprising:

requesting authentication information for an individual;

receiving authentication information for the individual;

presenting the individual with a random challenge action;

receiving a response to the challenge action from the individual; and

authenticating the individual based at least on the authentication information and the challenge action response.

2 . The method of claim 1 , in which the step of authenticating comprises:

identifying the individual based on at least the authentication information; and

verifying the individual is present at a device based on at least the challenge action response.

3 . The method of claim 2 , in which the challenge action is a motion gesture comprising at least one of moving the device in a circle clockwise, moving the device in a circle counter-clockwise, shaking the device, shaking the device with a twisting motion, moving the device in a figure-eight pattern, moving the device back and forth at waist level, and placing the device on top of the individual's head.

4 . The method of claim 3 , in which the response to the challenge action is received through at least one of a still camera, a motion camera, a microphone, an accelerometer, and a gyroscope.

5 . The method of claim 4 , in which the motion gesture further comprises repeating the motion.

6 . The method of claim 3 , in which the step of requesting authentication information and the step of presenting a challenge action are performed by a client application, and in which the authenticating step comprises:

transmitting, to a server, the authentication information and the challenge action response; and

receiving, from the server, an authentication message indicating at least one of allow access and deny access.

7 . The method of claim 6 , further comprising receiving, from the server, a configuration for a client device for the individual.

8 . The method of claim 7 , in which the client device is a mobile device.

9 . A computer program product, comprising:

a non-transitory computer-readable medium comprising:

code to request authentication information for an individual;

code to receive authentication information for the individual;

code to present the individual with a random challenge action;

code to receive a response to the challenge action from the individual; and

code to authenticate the individual based at least on the authentication information and the challenge action response.

10 . The computer program product of claim 9 , in which the medium further comprises:

code to identify the individual based on at least the authentication information; and

code to verify the individual is present at a device based on at least the challenge action response.

11 . The computer program product of claim 10 , in which the challenge action is a motion gesture.

12 . The computer program product of claim 11 , in which the code to verify comprises code to detect at least one of moving the device in a circle clockwise, moving the device in a circle counter-clockwise, shaking the device, shaking the device with a twisting motion, moving the device in a figure-eight pattern, moving the device back and forth at waist level, and placing the device on top of the individual's head.

13 . The computer program product of claim 12 , in which the code to detect comprises code to detect repeating the motion.

14 . The computer program product of claim 11 , in which the step of requesting authentication information and the step of presenting the challenge action are performed by a client application, and in which the medium further comprises:

code to transmit, to a server, the authentication information and the challenge action response; and

code to receive, from the server, an authentication message indicating at least one of allow access and deny access.

15 . The computer program product of claim 14 , in which the medium further comprises code to receive, from the server, a configuration for a client device for the individual.

16 . A system, comprising:

a memory;

a sensor;

at least one processor coupled to the memory and coupled to the sensor, in which the at least one processor is configured:

to request authentication information for an individual;

to receive authentication information for the individual;

to present the individual with a random challenge action;

to receive a response to the challenge action request from the individual through the sensor; and

to authenticate the individual based at least on the authentication information and the challenge action response.

17 . The system of claim 16 , in which the at least one processor is further configured:

to identify the individual based on at least the authentication information; and

to verify the individual is present at a device based on at least the challenge action response.

18 . The system of claim 17 , in which the challenge action is a motion gesture and the at least one processor is further configured to detect at least one of moving the device in a circle clockwise, moving the device in a circle counter-clockwise, shaking the device, shaking the device with a twisting motion, moving the device in a figure-eight pattern, moving the device back and forth at waist level, and placing the device on top of the individual's head.

19 . The system of claim 16 , further comprising a server, in which the at least one processor is configured:

to transmit, to a server, the authentication information; and

to receive, from the server, a response indicating at least one of allow access or deny access.

20 . The system of claim 19 , in which the at least one processor is further configured to receive, from the server, a configuration for a client device for the individual.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2014
From: BRUSO, KELSEY L; NEWTON, GLEN E
To: UNISYS CORPORATION
Reel/Frame 033224/0731 →
RELEASE OF SECURITY INTEREST Recorded Mar 26, 2013
From: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL TRUSTEE
To: UNISYS CORPORATION
Reel/Frame 030082/0545 →
RELEASE OF SECURITY INTEREST Recorded Mar 15, 2013
From: DEUTSCHE BANK TRUST COMPANY
To: UNISYS CORPORATION
Reel/Frame 030004/0619 →