IP Library Granted Patent US 8,973,091
Granted Patent B2
US 8,973,091 · App. 13/644,143 · Granted Mar 3, 2015

Secure authentication using mobile device

Inventors: David M. T. Ting (Sudbury, MA); Michael C. Bilancieri (Marlborough, MA); Edward J. Gaudet (Hanover, MA); Jason Mafera (Francestown, NH)
Assignee: Imprivata, Inc.
H04L63/08H04L63/0492
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,973,091
App. No.
13/644,143
Granted
Mar 3, 2015
Kind
B2
Abstract

Representative embodiments of secure authentication include receiving, by a server, information from a mobile device identifying (i) the mobile device and (ii) an identifying tag read by the mobile device; accessing, by the server, a database to identify (i) a user associated with the mobile device, (ii) a secure device associated with the identifying tag, and (iii) a security policy associated with the secure device; and if the policy permits access by the identified user to the identified secure device, causing access to the secure device to be accorded to the user.

Claims (64)

1. A method of secure authentication comprising:

receiving, by a server, information from a mobile device (i) identifying the mobile device and (ii) obtained by the mobile device from an identifying tag physically associated with a secure device different from the mobile device;

accessing, by the server, a database to identify (i) a user associated with the mobile device, (ii) a secure device associated with the identifying tag, and (iii) the security policy associated with the secure device; and

based at least in part on the mobile-device identifying information and the information obtained from the tag determining if the policy permits access by the identified user to the identified secure device, and if so, causing access to the secure device to be accorded to the user.

2. The method of claim 1 , further comprising challenging the user for an authentication factor before causing access to the secure device to be accorded to the user.

3. The method of claim 1 , wherein the step of causing access comprises wirelessly communicating, via wireless cell phone communication, an authentication token to the mobile device for wireless presentation by the mobile device to the secure device.

4. The method of claim 3 , wherein the wireless presentation of the token by the mobile device to the secure device occurs via near-field communication.

5. The method of claim 3 , wherein the wireless presentation of the token by the mobile device to the secure device occurs via point-to-point Bluetooth.

6. The method of claim 1 , wherein the step of causing access comprises wirelessly communicating, from the server, an authorization directly to the secure device.

7. The method of claim 1 , wherein the step of causing access comprises wirelessly communicating, via wireless cell phone communication, a secure device identifier to the mobile device for enabling the mobile device to directly communicate with the secure device.

8. The method of claim 7 , wherein the secure device identifier is a Bluetooth MAC address of the secure device.

9. The method of claim 1 , wherein the step of causing access comprises wirelessly communicating, by the server to the secure device, information about the user of the mobile device for enabling the secure device to authenticate the user without further communication with the server.

10. The method of claim 1 , wherein the information is received from the mobile device via wireless cell phone communication.

11. The method of claim 1 , wherein the identifying tag is an RFID tag, a bar code, or a quick response code.

12. The method of claim 1 , wherein the secure device is located within a room in which a second secure device is located, access to the second secure device being automatically accorded upon access to the first secure device being accorded.

13. The method of claim 1 , further comprising:

receiving, by the server, information from the mobile device identifying a second identifying tag read by the mobile device;

accessing, by the server, a second database to identify (i) a person associated with the second identifying tag, and (ii) a second security policy associated with the person; and

if the second policy permits access by the user to a third database associated with the identified person, causing access to the third database to be accorded to the user.

14. The method of claim 13 , wherein the third database stores patient medical histories.

15. The method of claim 1 , further comprising challenging the user for a second authentication factor after according the user access to the secure device.

16. The method of claim 1 , further comprising terminating access to the secure device.

17. The method of claim 16 , wherein the termination of access is triggered by receiving, by a server, information from the mobile device identifying (i) the mobile device and (ii) the identifying tag associated with the secure device.

18. The method of claim 16 , wherein the termination of access is triggered by receiving, by a server, information from a second mobile device identifying (i) the second mobile device and (ii) the identifying tag associated with the secure device.

19. The method of claim 16 , wherein the termination of access is triggered by a lack of response from the mobile device after the secure device has requested communication therewith.

20. The method of claim 1 wherein access to the secure device is accorded only following sequential or simultaneous communications involving a plurality of mobile devices.

21. The method of claim 1 , further comprising:

obtaining, by the mobile device, vitals information from at least one monitor associated with a patient; and

transmitting, to the server, data identifying the monitor and the obtained vitals information obtained from the monitor.

22. The method of claim 1 , further comprising:

receiving, by the server, information from the mobile device identifying a printer; and

transmitting, from the server, a list of queued print jobs to the secure device,

wherein at least one of the queued print jobs is printed using the printer.

23. A method of secure authentication comprising:

receiving, by a server, information from a mobile device (i) identifying the mobile device and (ii) obtained by the mobile device from first and second identifying tags not associated with the mobile device;

accessing, by the server, a database to identify (i) a user associated with the mobile device, (ii) first and second secure devices associated, respectively, with the first and second identifying tags, and (iii) a security policy associated with the secure devices; and

based at least in part on the mobile-device identifying information and the information obtained from the tag, determining if the policy permits access by the identified user to the identified secure devices, and if so, causing access to the secure devices to be accorded to the user.

24. A method of secure authentication comprising:

causing communications among a server and a plurality of mobile devices;

determining, by the server, whether the communications satisfy a policy; and

if so, according access to a secure resource different from the mobile devices to at least one individual associated with at least one of the mobile devices based on the policy and the communications.

25. The method of claim 24 , wherein the plurality of mobile devices simultaneously communicate with the server.

26. The method of claim 24 , wherein the wherein the plurality of mobile devices sequentially communicate with the server.

27. An authentication system comprising:

a server for receiving information from a mobile device identifying (i) the mobile device and (ii) an identifying tag read by the mobile device, the identifying tag being physically associated with a secure device different from the mobile device; and

a database comprising records (i) associating users with mobile devices, (ii) associating secure devices with tag identifiers, and (iii) defining a security policy associated with the secure devices,

wherein the server comprises a processor for (i) accessing the database upon receipt of the information from the mobile device, (ii) determining based thereon whether a security policy applicable to the user associated with the mobile device is entitled to access the secure device associated with the identifying tag, and if so, (iii) facilitating access to the secure device by the user.

28. The authentication system of claim 27 , wherein the server is configured to wirelessly communicate with the mobile device via cell phone communication.

29. The authentication system of claim 27 , wherein the server is configured to communicate with the secure device via a computer network.

30. The authentication system of claim 27 , wherein the identifying tag is an RFID tag, a bar code, or a quick response code.

31. An authentication system comprising:

a server for receiving information from a mobile device identifying (i) the mobile device and (ii) an identifying tag read by the mobile device, the identifying tag being physically associated with a secure device different from the mobile device;

a secure device configured for local wireless communication with the mobile device; and

a database comprising records (i) associating users with mobile devices, (ii) associating the secure device with at least one tag identifier, and (iii) defining a security policy associated with the secure device,

wherein the server comprises a processor for (i) accessing the database upon receipt of the information from the mobile device, (ii) determining based on the information whether a security policy applicable to the user associated with the mobile device is entitled to access the secure device associated with the identifying tag, and if so, (iii) facilitating access to the secure device by the user.

32. The authentication system of claim 31 , wherein the mobile device communicates with the secure device via point-to-point Bluetooth.

33. The authentication system of claim 31 , wherein the mobile device communicates with the secure device via near-field communication.

34. The authentication system of claim 31 , wherein the identifying tag is an RFID tag, a bar code, or a quick response code.

35. A wireless mobile device comprising a processor for:

executing a first procedure for reading an identifying tag physically associated with a secure device different from the mobile device;

executing a second procedure for transmitting information from the identifying tag and information identifying the wireless mobile device to a server, the information including (i) data identifying the mobile device and (ii) data read from the tag by the mobile device;

executing a third procedure for receiving an authentication token from the server; and

executing a fourth procedure for according access to the secure device using the token if, based at least in part on the transmitted information, a security policy associated with the secure device permits access thereto by a user of the identified mobile device.

36. The wireless mobile device of claim 35 , wherein the identifying tag is read using near-field communication.

Assignments (8)
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY COLLATERAL AT REEL/FRAME NO. 59644/0097 Recorded Sep 18, 2024
From: BLUE OWL CAPITAL CORPORATION (FORMERLY KNOWN AS OWL ROCK CAPITAL CORPORATION), AS COLLATERAL AGENT
To: IMPRIVATA, INC.
Reel/Frame 068981/0732 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 8, 2022
From: IMPRIVATA, INC.
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 059644/0097 →
SECURITY INTEREST Recorded Dec 22, 2020
From: IMPRIVATA, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 054836/0937 →
RELEASE OF SECURITY INTEREST Recorded Dec 2, 2020
From: GOLUB CAPITAL MARKETS LLC
To: IMPRIVATA, INC
Reel/Frame 054510/0572 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Oct 25, 2017
From: SILICON VALLEY BANK, AS AGENT
To: IMPRIVATA, INC.
Reel/Frame 044293/0295 →
SECURITY INTEREST Recorded Oct 24, 2017
From: IMPRIVATA, INC.
To: GOLUB CAPITAL MARKETS LLC
Reel/Frame 043934/0875 →
PATENT SECURITY AGREEMENT Recorded Sep 19, 2016
From: IMPRIVATA, INC.
To: SILICON VALLEY BANK
Reel/Frame 040069/0102 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2013
From: TING, DAVID M.; GAUDET, EDWARD J.; MAFERA, JASON; BILANCIERI, MICHAEL C.
To: IMPRIVATA, INC.
Reel/Frame 030159/0073 →
Continuity (2)
Provisional Application 61542443 · Oct 3, 2011
Related Publication 20130145420A1 · Jun 6, 2013