Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

68 results about "Multi-factor authentication" patented technology

Multi-factor authentication (MFA) is an authentication method in which a computer user is granted access only after successfully presenting two or more pieces of evidence (or factors) to an authentication mechanism: knowledge (something the user and only the user knows), possession (something the user and only the user has), and inherence (something the user and only the user is).

Contactless card and personal identification system

For multifactor authentication, a transaction device can receive encrypted data from a contactless card within a communication range of a short-range communication antenna, communicate the encrypted data to an authenticating device, solicit a user PIN in response to authentication of the encrypted data by the authenticating device, receive an input PIN, communicate the input PIN to a separate device storing a record PIN for the contactless card, and authorize a transaction initiated in connection with the contactless card in response to matching of the input PIN with the record PIN by the separate device. The input PIN can be received from the contactless card itself or a user interface, and the separate device can include the authenticating device or the contactless card itself. In different embodiments, the input PIN or the record PIN can include an EMV PIN stored in an EMV applet on the contactless card.
Owner:CAPITAL ONE SERVICES LLC

Systems and processes for multifactor authentication and identification

A system can include a server having a processor configured to receive, from a first computing device, first data associated with at least one historical data attack. The processor can encode the first data into at least one fixed-size representation. The processor can generate at least one anonymized vector representation based on the at least one fixed-size representation. The processor can receive, from a second computing device, second data associated with a potential attacker. The processor can encode the second data into at least one additional fixed-size representation. The processor can generate a second anonymized vector representation based on the at least one additional fixed-size representation. The processor can generate a confidence measure of the potential attacker as an attacker based on a comparison between the at least one anonymized vector representation and the second anonymized vector representation.
Owner:T STAMP INC

Multi-factor authentication with device and carrier validation

The invention provides systems, methods, and computer-readable media for multi-factor authentication (MFA) using device and carrier validation. A user device generates an attested blob containing cryptographic keys and a Universal Integrated Circuit Card (UICC)-originated International Mobile Subscriber Identity (IMSI), which is transmitted to a cloud-based MFA service. The service validates the attested blob, coordinates with an Original Equipment Manufacturer (OEM) service, and executes an Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA) process with the carrier network to establish mutual trust. Authentication data, including a validated phone number independent of the device's stored number, is securely stored in a cloud wallet. The invention enhances security by mitigating risks such as spoofing, replay attacks, and SIM swapping, providing a novel authentication framework compatible with modern networks.
Owner:SYNIVERSE TECHNOLOGIES LLC

Methods, devices, and systems for facilitating firearms safety

Methods, systems, and devices for facilitating firearms safety are provided. A multi-factor authentication is performed to verify an identity of a user trying to access a secure firearm. Presence of a user contact with the secure firearm is detected, the secure firearm being in a locked state. Upon detecting the presence of the user contact with the firearm, the user is prompted to enter a passcode via a keypad on the secure firearm. Also, a biometric attribute of the user is obtained by a biometric sensor on the secure firearm. It is determined, if the user is an authorized user based on the passcode entered by the user and the biometric attribute of the user. In response to determining that the user is the authorized user, the secure firearm is unlocked.
Owner:BROOKS-MALLORY BETTY CAROL

Limiting discovery of a protected resource in a zero trust access model

According to an embodiment, a system comprises one or more processors and one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the system to perform operations. The operations comprise determining that an endpoint device has requested to discover a location of a protected resource that is protected by a gateway, determining whether the endpoint device has provided a token that is valid, and permitting the endpoint device to discover the location of the protected resource based on determining that the endpoint device has provided the token that is valid. The token indicates that the endpoint device successfully completed a first multi-factor authentication procedure in connection with accessing an authentication enforcement resource.
Owner:CISCO TECHNOLOGY INC

Multi-factor authentication based on audio message

Techniques are described for accessing an account on a public device. In some implementations, an audio message is received from a portable computing device, requesting to establish an account access session between the portable computing device and the public device. A first communication based on the audio message is sent from the public device to a backend server. The backend server analyzes the first communication to determine whether the portable computing device is authorized to establish the account access session. A second communication is received from the backend server, indicating that the portable computing device is authorized. In response, the account access session is established between the portable computing device and the public device, wherein the account access session is employed by an application executing on the portable computing device to access account information associated with an account of a user of the portable computing device.
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Multi-factor authentication using wearable devices

According to one aspect, a method includes receiving, by a head-mounted display device, an authentication code associated with multi-factor authentication; receiving image data from an image camera on the head-mounted display device; detecting, by the head-mounted display device, that the image data includes an interface for receiving the authentication code; and displaying, by the head-mounted display device, the authentication code in a location corresponding to the interface.
Owner:GOOGLE LLC

Dynamic multi-factor authentication for premises access

Systems, methods, and devices are described herein. An example system is disclosed. The system includes at least one computing device configured to communicate with a premises monitoring system located at a premises. The at least one computing device is further configured to determine that a plurality of authentication factors associated with a person at the premises monitoring system have been satisfied, determine a respective weight of a plurality of weights for each of the plurality of authentication factors, determine a security factor for the premises monitoring system, calculate an authentication value for the person based on the security factor and the plurality of weights for the plurality of authentication factors, determine that the authentication value meets a predefined authentication threshold, and in response to determining that the authentication value meets the predefined authentication threshold, deem the person authenticated.
Owner:THE ADT SECURITY CORPORATION

System and method for providing location-based access in 5g

In one embodiment, a method includes transmitting, to a multi-factor authentication (MFA) agent running on a user device, a request for a location of the user device, receiving, from the MFA agent, the location of the user device, wherein the location is determined by the MFA agent to be a most common location indicated by a plurality of location indicators, receiving, from a policy server, a location-based access policy, appending, to the location-based access policy, the location of the user device and determining, based on the location of the user device and the location-based access policy, whether to allow the user device to access one or more of: a remote service, a remote database, and a remote device.
Owner:CISCO TECHNOLOGY INC

Limiting discovery of a protected resource in a zero trust access model

According to an embodiment, a system comprises one or more processors and one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the system to perform operations. The operations comprise determining that an endpoint device has requested to discover a location of a protected resource that is protected by a gateway, determining whether the endpoint device has provided a token that is valid, and permitting the endpoint device to discover the location of the protected resource based on determining that the endpoint device has provided the token that is valid. The token indicates that the endpoint device successfully completed a first multi-factor authentication procedure in connection with accessing an authentication enforcement resource.
Owner:CISCO TECHNOLOGY INC

Multi-Factor Authentication and Post-Authentication Processing System

An end-user computing device may utilize a device to capture input from an electronic tag of a physical asset. The end-user computing device may generate supplemental digital data associated with the input. The end-user computing device may transmit the input and the supplemental digital data to an authentication and digital assets server. The authentication and digital assets server may authenticate the physical asset and transmit the authentication results to the end-user computing device, which may display the authentication results. If the authentication of the physical asset is successful, the authentication and digital assets server may select one or more digital assets and transmit the one or more digital assets to the end-user computing device. The end-user computing device may display the one or more digital assets.
Owner:NIKE INC

Multi factor authentication using different devices

Customizing an application on a mobile device includes storing at least a portion of customization data in a customization server that is independent of the mobile device, a user of the mobile device accessing the customization server independently of the mobile device, receiving authorization data from the customization server that enables the mobile device to securely receive customization data from the customization server, and the mobile device using the authorization data to cause the customization server to provide the customization data to the mobile device. The authorization data may be provided by postal message, email message, an SMS text message, and / or a visual code provided on a screen of a computer used to access the customization server. The user may use a computer to provide credential information to access the customization server. Customizing the application may allow the mobile device to access a user service on behalf of the user.
Owner:ASSA ABLOY AB

Biometric Multi-Account Transaction Card

PendingUS20260252837A1MicrocontrollerBiometric data
A biometric multi-account transaction card and associated transaction system. The card includes a card body conforming to ISO / IEC 7810 ID-1, a fingerprint sensor configured to capture user biometric data, an optical element for facial-recognition or optical sensing, and an integrated circuit contact module for EMV communication is disclosed. A secure element stores a non-reversible biometric template and multiple tokenized payment credentials organized in credential slots. A microcontroller executes biometric-matching algorithms, account-selection logic, and generates EMV-compliant cryptograms, while an NFC antenna enables contactless operation. A cooperating point-of-sale terminal displays account options received from the card and can perform facial recognition for multi-factor authentication. Upon successful authentication, the card transmits a tokenized payment credential corresponding to a selected account.
Owner:WOODLEY TYWANA

Multi-factor authentication system for property management

A multi-factor authentication system for property management may provide user a convenient and safe property management service via enrolling with service for multi-factor authentication via an application. The user may log in the multi-factor authentication service platform during the enrollment phase via the application to acquire an account and obtain authority for use, thereby to access the service provided by the multi-factor authentication service platform via a property management station system. In addition, during the property management service, the user may acquire the property management service in fewer steps and a more secure manner during an authentication phase with the multi-factor authentication service platform, thereby to enforce security for identity authentication.
Owner:WANG CHIH CHUN

Concealed three-dimensional data object for multi factor authentication

A workspace management system includes a networked workspace scheduling server. A conferencing device has a three-dimensional authentication object encoded with data that is read using light detection and ranging (LIDAR) and disposed behind a bezel cover. The bezel cover has at least a visible mode and a concealed mode. Upon the bezel cover being in a visible mode, the three-dimensional authentication object is visible to a LIDAR scanner, and upon the bezel cover being in a concealed mode, the three-dimensional authentication object is not visible to the LIDAR scanner. At least one security camera is configured to capture an image of the three-dimensional authentication object of the conferencing device. A mobile user device has an application installed thereon. A form authentication token associated with the mobile user device and encoded in the three-dimensional authentication object is retrievable by the application.
Owner:CRESTRON ELECTRONICS INC

Innovative system for analysing payment means and automatically activating discounts

PCT designated stageWO2026142477A1Mobile Telephone NumberElectronic systems
The invention relates to a smart electronic system for automatically managing and activating discounts during payment. The system is based on linking consumer data (such as national identification number, mobile phone number, and bank card or digital wallet details) to central databases of banking and non-banking offers and discounts. An authentication engine matches the consumer data to the databases, then a smart comparison module selects the best available discount. The discount is automatically applied to the payment at points of sale or in electronic payment portals, and the consumer is immediately notified of the discount applied. The system can be integrated with banks, digital wallets, communications companies, loyalty programmes and work places, and also comprises data protection mechanisms using encryption and multifactor authentication. The invention enables maximum benefit from discounts without manual intervention by the consumer, which enhances the payment experience and the effectiveness of commercial offers for banks and businesses.
Owner:ALSHARIF HANI

Authentication service with shared session tokens for sharing authentication

Disclosed are systems, apparatuses, methods, computer readable medium, and circuits for sharing multifactor authentication with shared session tokens using an authentication service. According to at least one example, a method includes: in response to receiving a request to check an authentication status from a first application, transmitting a first message to an authentication service including shared information; providing first authentication credentials related to a first authentication to the authentication service; and receiving a message related to a second authentication to bypass the second authentication.
Owner:CISCO TECHNOLOGY INC

Multi-factor enabled access using randomly selected digital identity authentication factors

Techniques are described for providing multifactor authentication using randomly selected Digital Identity factors associated with a human user or individual seeking access to a facility, building, computer system, network, application, memory, etc. Digital Identity factors are or memory. Digital Identity factors are retrieved and stored by an authentication agent. The Digital Identity factors can be retrieved from a network such as the internet or can be previously provided by a customer or human individual requesting authorization. Upon receiving a request for authentication, a plurality of Digital Authentication factors are randomly selected. A request is sent to an environment associated with the human individual seeking access, the request including information regarding the randomly selected Digital Authentication factors. A reply is received having information regarding the randomly selected authentication factors. The information in the reply is compared with the randomly Digital Identity factors to determine whether to grant or deny access.
Owner:CISCO TECHNOLOGY INC

Systems and methods of contactless card as one authentication factor for multiple factor authentication

Systems and methods for authenticating a user using a contactless card as one authentication factor for multiple factor authentication are provided. In an exemplary embodiment, a server receives a first request of authenticating a user using a first authentication factor, authenticates the user using the first authentication factor, and receives a second request of authenticating the user using a contactless card as a second authentication factor. The server receives a cryptogram of the contactless card, validates the cryptogram, decrypts the cryptogram, and extracts a unique customer identifier of the contactless card. The server verifies the unique customer identifier, authenticates the user using the unique customer identifier, and transmits an authentication result of authenticating the user using the contactless card as the second authentication factor.
Owner:CAPITAL ONE SERVICES LLC

Multifactor authentication using network address translation data

The present disclosure describes a device, computer-readable medium, and method for multifactor authentication using network address translation data. A method performed by a processing system includes receiving, from a host device in a communication network, a request to authenticate a user, wherein the request includes a purported identity of the user and a public internet protocol address assigned to a user endpoint device from which a request to access a resource at the host device was sent, querying a provider edge server for a verification that the purported identity matches an identity associated with a private internet protocol address that is mapped to the public internet protocol address, receiving a first response from the provider edge server, determining whether to authenticate the user based on the first response from the provider edge server, and sending a second response to the host device indicating a result of the determining.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Electronic signature evidence storage management system and method

The invention discloses an electronic signature evidence storage management system, which belongs to the technical field of privacy protection and comprises a data acquisition module, an evaluation module and an encryption analysis module. The data acquisition module acquires data through a touch input device and an environment sensor, and performs preprocessing and multi-factor identity verification; the evaluation module comprises a risk evaluation unit for judging whether continuous evidence storage operation is allowed or not and a credibility evaluation unit for triggering an evidence storage strategy of a corresponding level; and the encryption analysis module comprises an encryption unit for performing four-stage encryption processing and an encryption adjustment unit for dynamically adjusting an encryption strategy when an abnormal mode is detected. A comprehensive safety protection system is constructed, the comprehensiveness and safety of identity verification are effectively improved, the signature consistency is ensured, the name imposing risk is prevented, the potential risk is recognized in time, the safety of data in all links is ensured through encryption analysis, and the overall safety and reliability of the system are improved.
Owner:ZHONGHENG NUOSEN (QINGDAO) TECHNOLOGY CO LTD

Multi-factor authentication providing a credential via a contactless card for secure messaging

Exemplary embodiments may use a contactless card as a secondary form of authentication in a multi-factor authentication for a secure messaging service. The recipient party of a request to initiate a messaging service session (such as a server computing device) may be programmed to use the phone number of the originating device to look up records regarding an identity of a party and their associated phone number as a primary credential and then may require an authentication credential originating from the contactless card as a secondary credential for the initiating party. In some instances, the credential originating from the contactless card is a onetime password that is valid only for a period of time. The recipient party determines whether the onetime password is valid. If both credentials are valid, a secure messaging session may be initiated with the initiating party.
Owner:CAPITAL ONE SERVICES LLC

Computer-based systems configured to dynamically generate authentication steps to perform at least one action and methods of use thereof

In some embodiments, the present disclosure provides an exemplary method that may include steps of determining an identity of at least one user of a plurality of users based on a multi-factor authentication; utilizing an identity tokenizer to generate at least one temporary identity token associated with the identity of the user; transmitting the at least one temporary identity token to an external computing device for authentication; receiving an authenticated digital token from the external computing device; automatically utilizing the authenticated digital token to retrieve a plurality of data items of an account information; utilizing a security module to link the authenticated digital token and the plurality of data items; generating a unique-universal identifier associated with the security module and the authenticated digital token; and utilizing the unique-universal identifier and the security module associated with the authenticated digital token.
Owner:CAPITAL ONE SERVICES LLC

Multifactor authentication using three-dimensional data objects for configurable workspaces

In some implementations, the device may include a mobile user device having a first side and a second side, the mobile user device having a first wireless communication interface communicatively coupled to a cloud network, an optical imaging camera positioned on the first side of said mobile user device, a first LIDAR camera disposed on the first side, and a display screen disposed on said second side of said mobile user device. In addition, the device may include a conferencing device having an outer enclosure, the conferencing device including a display screen housed withing said outer enclosure, a bezel cover that forms a part of the outer enclosure and covers said display screen, where said bezel cover includes an electrochromatic region that is transparent when electrically energized and said electrochromatic region is opaque when de-energized. The device may include a three-dimensional object encoded with a symbology for representing data in the x-direction, y-direction, and z-direction, said three-dimensional object disposed behind said electrochromatic region of said bezel cover and inside the interior of said enclosure. Moreover, the device may include a remote cloud server having a network interface communicatively coupled to said remote cloud server, the remote cloud server having CPU and a nonvolatile storage.
Owner:CRESTRON ELECTRONICS INC

Remote folders for real time remote collaboration

Described are systems and methods that enable secure real time communication (“RTC”) sessions that may be used, for example, for editing and movie production. Client devices may interact with an RTC management system to collaborate on different files retained on the different client devices, without the files having to be uploaded from the client device on which it is stored. In addition, on-going multifactor authentication may be performed for each client device of an RTC session during the RTC session and / or video authentication may be used to grant access into an RTC session. Still further, to improve the quality of the exchanged video information and to reduce transmission requirements, in response to detection of events, such as a pause event, a high resolution image of a paused video may be generated and sent for presentation on the display of each client device, instead of continuing to stream a paused video.
Owner:EVERCAST LLC

Systems and methods for using multi-factor authentication

ActiveUS12718303B2User deviceInternet privacy
An authentication computing device stores a cardholder profile that is associated with a candidate cardholder and includes a cardholder identifier, a device identifier, payment account data, and trusted authentication data in a database system, receives an authentication request that is associated with a tax filing of the candidate cardholder and includes a filing identifier from a revenue computing device, detects the authentication request is associated with the candidate cardholder based upon the filing identifier and the cardholder profile, transmits an identity challenge requesting authentication data associated with the candidate cardholder to a user device associated with the device identifier, receives a challenge response including response authentication data from the user device, determines an authentication status associated with the authentication request based on a comparison of the response authentication data and the trusted authentication data, and transmits the authentication status to the revenue computing device.
Owner:MASTERCARD INT INC

Single device-level passcode that provides automated access to multiple computing devices and passcode-protected applications and web sites / services

A single device-level passcode serves to unlock a passcode vault, such that, automated login / access to other computing devices, applications, networks and / or websites / web services, which have the user's passcodes stored in the vault, occurs. Specifically, in the case of other computing devices, short-range wireless communication between the initial logged-in computing device and another computing device triggers retrieval of the other computing devices passcode from the passcode vault and automated user log-in at other computing device. The passcode may be mapped to previously-captured user characteristics, such that multi-factored authentication including user characteristic verification may occur at the time the passcode vault is unlocked (i.e., when the single passcode is entered), continuously throughout the device session and / or when the passcode vault is accessed to retrieve a passcode for another device, network, application or web site / service.
Owner:BANK OF AMERICA CORP

System and method for multi-factor authentication of a communication device metadata with user authentication

The present invention relates to a system and a method for multi-factor authentication of communication device metadata. The system includes a communication device, and a recipient device that work together to authenticate communication device metadata using digital signatures and a user's identity through voice biometrics. User enrolls into the system by providing voice samples, from which a unique voiceprint is created and stored. For authenticating the communication device metadata with user authentication, the user issues a voice command, and the system extracts voice signatures which are compared with the stored voiceprint to verify the user's identity. Upon successful authentication, the communication device metadata is accessed, and corresponding digital signatures are generated. Further, the system authenticates the generated digital signatures and user's identity. If both are verified, the communication device metadata is considered valid and used for further processing.
Owner:CHANDRAN DEEPAK R +1

Multi-factor authentication method and system for WEB3 services

A method and system for multi-factor authenticating users in Web3 services includes a multi-factor authentication (e.g., 2FA) provider configured to validate that an end-user owns a public key in a blockchain based on a cryptocurrency or a NFT transference, the public key used as a first factor for the authentication. The authentication provider interacts with a smart contract to perform the multi-factor authentication in an operation in a smart contract by using off-chain data as the other factor(s) required for the multi-factor authentication. The off-chain data are received in a user terminal, e.g., a smartphone via SMS or a mobile application, associated with the account created in the authentication provider. The authentication result is read by each node executing the smart contract and, when a consensus is reached among nodes, a new block representing the result is generated in the blockchain.
Owner:TELEFÓNICA INNOVACIÓN DIGITAL S L U

Information processing apparatus, method for controlling information processing apparatus, and storage medium

In an information processing apparatus having a multifactor authentication function, when user authentication is performed by an authentication server, an additional extended authentication application, or the like, a case where an additional security measure related to multifactor authentication is possible cannot be correctly determined, and a security measure status cannot be displayed in some cases.SOLUTION: In the multi-function peripheral 100, when the application used in the user verification is a standard verification application incorporated in advance in the firmware of the multi-function peripheral 100 and the verification server is not used (No in S414), the security measure status related to the multi-factor verification is displayed based on the setting value related to the multi-factor verification (S415, S416, S412), and when the application used in the user verification is an additional extended verification application (Yes in S411), the fact that the security measure related to the multi-factor verification has been implemented is displayed regardless of the setting value related to the multi-factor verification (S412).SELECTED DRAWING: Figure 4B
Owner:CANON KK