IP Library Granted Patent US 10,078,425
Granted Patent B2
US 10,078,425 · App. 14/945,671 · Granted Sep 18, 2018

Strong authentication via distributed stations

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,078,425
App. No.
14/945,671
Granted
Sep 18, 2018
Kind
B2
Abstract

In various embodiments, authentication stations are distributed within a facility, particularly in spaces where mobile devices are predominantly used—e.g., a hospital's emergency department. Each such station includes a series of authentication devices. Mobile device may run applications for locating the nearest such station and, in some embodiments, pair wirelessly with the station so that authentication thereon will accord a user access to the desired resource via a mobile device.

Claims (38)

1. A method of authentication and log-on to access a secure resource via a computer network, the method comprising the steps of:

sending, via a computational device, an access request to a secure resource from a user via a network;

receiving, from the secure resource, a user authentication requirement involving an authentication modality, wherein the computational device does not support the authentication modality and cannot be solely utilized to satisfy the user authentication requirement;

locating, via a mobile device, a nearest authentication station supporting the authentication modality, wherein the nearest authentication station and the computational device are located at different locations;

establishing wireless communication between the mobile device and the authentication station;

obtaining, by the authentication station using the authentication modality, authentication credentials from the user, the user having traveled to the authentication station;

causing transmission of the authentication credentials to an authentication server different from the authentication station;

receiving, by the authentication station, an authentication confirmation from the authentication server and, via multiple-party communication among the mobile device, the authentication station, the computational device, and the secure resource, according access to the secure resource via the computational device.

2. The method of claim 1 , wherein the mobile device is the computational device.

3. The method of claim 1 , wherein the mobile device is different from, but in wireless communication with, the computational device.

4. The method of claim 1 , wherein the step of establishing wireless communication between the mobile device and the authentication station comprises claiming, by the mobile device, the authentication station until the authentication credentials have been received by the authentication station.

5. The method of claim 1 , wherein the multiple-party communication comprises:

wirelessly communicating, by the authentication station via a secure link, the obtained authentication credentials to the wireless device; and

wirelessly communicating, by the wireless device via a secure link, the authentication credentials to the authentication server.

6. The method of claim 5 , wherein the computational device is different from the wireless device, and further comprising the steps of:

wirelessly communicating, by the authentication station to the wireless device via a secure link, a token indicating acceptance of the obtained authentication credentials; and

wirelessly communicating, by the wireless device via a secure link, the token to the computational device, whereby access to the secure resource is accorded to the computational device.

7. The method of claim 1 , wherein the multiple-party communication comprises:

wirelessly communicating, by the wireless device via a secure link to the authentication server, the authentication credentials and session data identifying a session between an application running on the wireless device and the secure resource; and

causing, by the authentication server, the computational device to be accorded access to the secure resource over the session.

8. The method of claim 1 , further comprising displaying, by the mobile device, a map showing a current location of the mobile device and a location of the authentication station.

9. A system for facilitating authentication and log-on to access a secure resource via a computer network using an authentication modality, the system comprising:

a network;

a plurality of authentication stations;

an authentication server different from the authentication stations;

a computational device configured for requesting access to a secure resource via the network but lacking the authentication modality, wherein the computational device is located at a location different from locations of the authentication stations; and

a mobile device comprising a processor and a memory storing an application, the application, when executed by the processor as a running process, causing the mobile device to identify a nearest one of the authentication stations supporting the authentication modality and establish wireless communication therewith,

wherein the identified authentication station is configured to (i) receive, using the authentication modality, authentication credentials from a user located at the authentication station, (ii) transmit the authentication credentials to the authentication server, and (iii) receive an authentication confirmation from the authentication server,

and further wherein the mobile device, the authentication station, the computational device, and the secure resource, are configured for multiple-party communication whereby access is accorded to the secure resource via the computational device.

10. The system of claim 9 , wherein the mobile device further comprises a display and a mapping application which, when executed by the processor as a running process, causes a map showing a current location of the mobile device and a location of the authentication station to appear on the display.

11. The system of claim 10 , wherein the mobile device is the computational device.

12. The system of claim 10 , wherein the mobile device is different from, but in wireless communication with, the computational device.

13. The system of claim 10 , wherein the mobile device is configured to wirelessly claim the identified authentication station until the authentication credentials have been received by the authentication station.

14. The system of claim 10 , wherein the multiple-party communication comprises:

wireless communication by the authentication station of the obtained authentication credentials to the wireless device via a secure link, and

wireless communication by the wireless device of the authentication credentials to the authentication server via a secure link.

15. The system of claim 14 , wherein (i) the computational device is different from the wireless device and (ii) the multiple-party communication further comprises wireless communication by the authentication station to the wireless device via a secure link of a token indicating acceptance of the obtained authentication credentials, the wireless device being configured to use the token to obtain access to the secure resource.

16. The system of claim 10 , wherein (i) the multiple-party communication comprises wireless communication, by the wireless device via a secure link to the authentication server, of the authentication credentials and session data identifying a session between an application running on the wireless device and the secure resource, and (ii) the authentication server is configured to accord the computational device access to the secure resource over the session.

Assignments (8)
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY COLLATERAL AT REEL/FRAME NO. 59644/0097 Recorded Sep 18, 2024
From: BLUE OWL CAPITAL CORPORATION (FORMERLY KNOWN AS OWL ROCK CAPITAL CORPORATION), AS COLLATERAL AGENT
To: IMPRIVATA, INC.
Reel/Frame 068981/0732 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 8, 2022
From: IMPRIVATA, INC.
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 059644/0097 →
SECURITY INTEREST Recorded Dec 22, 2020
From: IMPRIVATA, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 054836/0937 →
RELEASE OF SECURITY INTEREST Recorded Dec 2, 2020
From: GOLUB CAPITAL MARKETS LLC
To: IMPRIVATA, INC
Reel/Frame 054510/0572 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Oct 25, 2017
From: SILICON VALLEY BANK, AS AGENT
To: IMPRIVATA, INC.
Reel/Frame 044293/0295 →
SECURITY INTEREST Recorded Oct 24, 2017
From: IMPRIVATA, INC.
To: GOLUB CAPITAL MARKETS LLC
Reel/Frame 043934/0875 →
PATENT SECURITY AGREEMENT Recorded Sep 19, 2016
From: IMPRIVATA, INC.
To: SILICON VALLEY BANK
Reel/Frame 040069/0102 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2016
From: ULLRICH, MEINHARD DIETER
To: IMPRIVATA, INC.
Reel/Frame 039135/0082 →