System and method for authorizing access to access-controlled environments

Inventors

Hoyos, HectorBraverman, JasonStreit, ScottXiao, GeoffreyMather, Jonathan Francis

Assignees

Veridium IP Ltd

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-10678898-B2

Patent

Publication Date

2020-06-09

Expiration Date


Abstract

Systems and methods are provided for authorizing a user to access an access-controlled environment. The system includes a system server platform that communicates with fixed PC's, servers and mobile devices (e.g., smartphones) operated by users. The systems and methods described herein enable a series of operations whereby a user attempting to access an access-controlled environment is prompted to biometrically authenticate using the user's preregistered mobile device. Biometric authentication can include capturing images of the user's biometric features, encoding the features as a biometric identifier, comparing the biometric identifier to a previously generated biometric identifier and determining liveness. In addition, the authentication system can further authorize the user and electronically grant access to the access-controlled environment. In this manner the secure authentication system can, based on biometric authentication, authorize a user's access to devices, online services, physical locations or any networked environment that require user authorization.

Core Innovation

The invention coordinates access to an access-controlled environment (ACE) for a user using a trusted server that verifies a biometric authentication application executing on the user’s personal mobile computing device. The trusted server receives an application certificate uniquely identifying the biometric authentication application and verifies that the application certificate is valid. It also receives a representation of the user’s identity and a representation of at least a component of the user computing device and tests the representation of the user’s identity against a trusted set of user identification information to verify the user is authorized to access the ACE.

During user enrollment, the trusted server causes generation of a key pair comprising a private key and a corresponding public key. The private key and the unique identifier are stored by the user device, and the trusted server stores the public key in association with the assigned unique identifier to create a registered instance of a user identity. The identity instance is created as a function of verifying the application certificate, verifying the user identity, and generating the key pair.

For authorization, the trusted server receives a communication including information asserting an identity of one or more of the user and the user device, a representation of the private key, and a current biometric representation of the user’s biometric features captured by the user device using an associated biometric capture device. The trusted server identifies the user instance, verifies that the representation of the private key corresponds to the public key associated with the identified user instance, and confirms that the current biometric representation matches a registered biometric representation of the user previously stored by the server. Based on the authorizing step, the trusted server facilitates user access to the ACE in conjunction with one or more remote computing devices.

Claims Coverage

The document includes two independent claims. They require a trusted server that verifies a biometric authentication application certificate, creates a server-registered user identity instance using a key pair and unique identifier, and authorizes ACE access only after private-key/public-key correspondence and biometric matching.

Secure coordination of ACE access using trusted server verification

A trusted server receives and verifies an application certificate uniquely identifying a biometric authentication application executing on the user’s personal mobile computing device, receives representations of the user’s identity and the user computing device, tests the identity representation against a trusted set of user identification information to verify authorization to access the ACE, and provides a unique identifier assigned for the user based on the representation of the user’s identity.

Key-pair enrollment creating a registered user identity instance

During user enrollment, the method causes generation of a key pair comprising a private key and a corresponding public key, where the private key and the unique identifier are stored by the user device, and the trusted server stores the public key in association with the assigned unique identifier to create a registered instance of a user identity as a function of verifying the application certificate, verifying the user identity, and generating the key pair.

Authorization via private-key/public-key correspondence and biometric matching

The method receives a communication including information asserting an identity of one or more of the user and the user device, a representation of the private key, and a current biometric representation captured by the user device, then authorizes access by identifying the user instance, verifying that the representation of the private key corresponds to the public key associated with the identified user instance, confirming that the current biometric representation matches a registered biometric representation previously stored for the identified user instance, and facilitating access to the ACE using the trusted server with one or more remote computing devices.

Trusted-server system modules for enrollment and authorization of ACE access

A system with a network communication interface, computer-readable storage medium, and one or more processors executing software modules including an enrollment module that receives an application certificate and representations of the user’s identity and user-device component, verifies the certificate, tests the identity representation against a trusted set of user identification information to verify authorization to access the ACE, provides a unique identifier, causes generation of a key pair where the private key and unique identifier are stored by the user device, and a database module that stores the public key in association with the unique identifier to create a registered instance of a user identity.

Authorization module using private-key/public-key verification and biometric confirmation

A system where a communication module receives from the user device a communication including information asserting an identity of one or more of the user and the user device, a representation of the private key, and a current biometric representation captured using an associated biometric capture device; and an authorization module authorizes user access based on identifying the user instance, verifying that the representation of the private key corresponds to the public key associated with the identified user instance, confirming that the current biometric representation matches a registered biometric representation previously stored by the server, and facilitating user access to the ACE using the trusted server in conjunction with one or more remote computing devices.

Across the independent claims, the core inventive coverage is the combination of verifying an application certificate for a biometric authentication application on a personal mobile device, enrolling a key pair with server-registered public key tied to a unique identifier and a registered user identity instance, and authorizing ACE access only after verifying private-key/public-key correspondence and confirming current biometric representation matches a registered biometric representation.

Stated Advantages

Enables secure coordination of access to an access-controlled environment (ACE) using a trusted server in conjunction with one or more remote computing devices.

Supports authorization by combining application certificate validation, key-pair correspondence verification, and matching of current biometric representation to a registered biometric representation.

Avoids storing sensitive account data within the user device enrollment/identity assertion framework as described for registered instances keyed to identity rather than account data.

Documented Applications

Authorizing a user to access an access-controlled environment (ACE) such as websites, VPNs, doors, ATMs, and transactions, coordinated through a cloud/system-server platform and remote computing devices/ACE back-ends.

Secure coordination of access where the user operates a user computing device executing a biometric authentication application to confirm user identity for access to the ACE.

Integration with an ACE legacy authentication system via a trusted set of user identification information and authorization notifications.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.