WO2017180384A1 - Method and apparatus for using a biometric template to control access to a user credential for a shared wireless communication device - Google Patents
Method and apparatus for using a biometric template to control access to a user credential for a shared wireless communication device Download PDFInfo
- Publication number
- WO2017180384A1 WO2017180384A1 PCT/US2017/026093 US2017026093W WO2017180384A1 WO 2017180384 A1 WO2017180384 A1 WO 2017180384A1 US 2017026093 W US2017026093 W US 2017026093W WO 2017180384 A1 WO2017180384 A1 WO 2017180384A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- user
- mobile device
- biometric template
- request
- credential
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
- H04L63/062—Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0861—Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
- H04L9/3231—Biological data, e.g. fingerprint, voice or retina
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/068—Authentication using credential vaults, e.g. password manager applications or one time password [OTP] applications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/30—Security of mobile devices; Security of mobile applications
- H04W12/33—Security of mobile devices; Security of mobile applications using wearable devices, e.g. using a smartwatch or smart-glasses
Definitions
- a digital certificate may be created in a public key infrastructure (PKI) and may be used to identify ownership of a public key as a part of a cryptographic protocol executed to authenticate an end entity (that is, a user or wireless communication device) and subsequently grant access to a service.
- PKI public key infrastructure
- the end entity In order to obtain the digital certificate from a PKI, the end entity typically sends a certificate signing request to a component (for example, a registration authority (RA) or a certificate authority (CA)) in a PKI.
- RA registration authority
- CA certificate authority
- the certificate generated by the PKI certifies the ownership of a public key by the named subject of the certificate and binds an identity of the end entity to the public key by including the identity of the end entity and the public key in the certificate and signing the certificate with the private key of a trusted CA.
- the CA may include other information about the end entity in the certificate.
- the CA may include attributes that can be used to provide an indication of the applications and services that the end entity should be allowed to access, or other attributes of the end entity such as a role or rank, or group affiliation.
- some wireless communication devices further include biometric authentication. For example, when a user first authenticates to a device, the user can be required to provide biometric information. Typically, such biometric identification also is stored on the user's device. If the biometric information input by the user matches the biometric identification maintained by the device then the user is permitted access to the device. Such biometric information further may be used to authenticate the user in obtaining a certificate.
- biometric authentication For example, when a user first authenticates to a device, the user can be required to provide biometric information. Typically, such biometric identification also is stored on the user's device. If the biometric information input by the user matches the biometric identification maintained by the device then the user is permitted access to the device. Such biometric information further may be used to authenticate the user in obtaining a certificate.
- FIG. 1 is a block diagram of a wireless communication system in which service instance selection is implemented in accordance with some embodiments of the present invention.
- FIG. 2 is a block diagram of a mobile device of the wireless communication system of FIG. 1 in accordance with some embodiments of the present invention.
- FIG. 3 is a block diagram of a user credential server of the wireless
- FIG. 4 is a block diagram of a service network element of the wireless communication system of FIG. 1 in accordance with some embodiments of the present invention.
- FIG. 5A is a logic flow diagram illustrating a method performed by the wireless communication system of FIG. 1 in controlling a distribution of a user biometric template in accordance with some embodiments of the present invention.
- FIG. 5B is continuation of the logic flow diagram of FIG. 5 A illustrating a method performed by the wireless communication system of FIG. 1 in controlling a distribution of a user biometric template in accordance with some embodiments of the present invention.
- FIG. 6 is a logic flow diagram illustrating a method performed by the wireless communication system of FIG. 1 in controlling access to a user credential in accordance with some embodiments of the present invention.
- references to specific implementation embodiments such as “circuitry” may equally be accomplished via replacement with software instruction executions either on general purpose computing apparatus (e.g., CPU) or specialized processing apparatus (e.g., DSP).
- general purpose computing apparatus e.g., CPU
- specialized processing apparatus e.g., DSP
- a mobile wireless communication device can be shared among numerous users from an agency and across multiple work shifts. Such shared wireless communication devices may be referred to herein as shared devices or shareable devices. Further, such shared devices can be shared somewhat randomly, wherein a user starting a work shift may randomly pick up any one of multiple mobile devices available for use. In such instances, a single certificate issued to the device cannot be used to identify the current user of the mobile device.
- FirstNet First Responder Network
- the shared device may have to store biometric templates and certificates for, in some cases, hundreds of users. If the shared device with biometric templates and certificates for multiple users is lost or stolen, the biometric template and certificate for each user that is stored in the device would have to be revoked. Furthermore, because each user is set up to share multiple devices, a user could have at least one biometric template and certificate on each shared device. When a user with a biometric template and certificate on multiple shared devices is terminated by the enterprise, the user biometric template and certificate may have to be removed from each of the shared devices.
- one exemplary embodiment provides a method for controlling access to a user credential using a biometric template.
- the method includes receiving, from a mobile device, an authentication request.
- the authentication request includes a device credential associated with the mobile device.
- the method further includes receiving, from the mobile device, a request for a biometric template of a user.
- the method further includes determining, by reference to at least one of a group consisting of the device credential and an authorization database, that the mobile device is authorized to receive the biometric template of the user based on at least one attribute controlling a use of the biometric template.
- the method further includes, in response to determining that the mobile device is authorized to receive the biometric template of the user, conveying the biometric template of the user to the mobile device.
- Another exemplary embodiment provides a method for authenticating a user on a mobile device.
- the method includes receiving, by a input/output interface of the mobile device, a user identifying input.
- the method further includes, in response to receiving the user identifying input, authenticating, by the mobile device, to a biometric template server.
- the method further includes, in response to authenticating to the biometric template server, conveying, by the mobile device to the biometric template server, the user identifying input.
- the method further includes, in response to conveying the user identifying input, receiving, by the mobile device, one or more messages including a biometric template for the user.
- the method further includes authenticating, by the mobile device, the user based on the biometric template.
- the mobile device includes an input/output interface, a wireless interface, a processor, and at least one memory device.
- the memory device is configured to store a set of instructions that, when executed by the processor, cause the processor to receive, via the input/output interface, a user identifying input from a user of the mobile device.
- the memory device is further configured to cause the processor to, in response to receiving the user identifying input, authenticate to a biometric template server and convey, to the biometric template server via the wireless interface, the user identifying input.
- the memory device is further configured to cause the processor to, in response to conveying the user identifying input, receive, via the wireless interface, one or more messages including a biometric template for the user.
- the memory device is further configured to cause the processor to, authenticate the user based on the biometric template.
- the memory device is further configured to cause the processor to assemble a request for a user credential based on metadata included in the one or more messages.
- the memory device is further configured to cause the processor to sign the request for a user credential to produce a signed request.
- the memory device is further configured to cause the processor to, convey, via the wireless interface, to a user credential server, the signed request.
- the memory device is further configured to cause the processor to, in response to conveying the signed request, receive, via the wireless interface, the user credential.
- a single biometric template may include one or more biometric identifiers (for example, an iris scan, fingerprint, palm print, facial-recognition-ready photograph, voice data, an electrocardiogram, and the like), which may be used to authenticate an associated user.
- biometric identifiers for example, an iris scan, fingerprint, palm print, facial-recognition-ready photograph, voice data, an electrocardiogram, and the like
- FIG. 1 illustrates an exemplary embodiments of a wireless communication system 100 in accordance with an embodiment of the present invention.
- the wireless communication system 100 includes a first mobile device 104 and a second mobile device 106.
- the first mobile device 104 and the second mobile device 106 may be any mobile wireless communication device that includes functionality to allow biometric authentication and to securely authenticate users.
- the biometric authentication (that is, the comparison of a biometric sample to a biometric template) is performed on the first mobile device 104 and the second mobile device 106, and the collection of a biometric sample is performed by one or more collection devices linked to, but separate from, the first mobile device 104 and the second mobile device 106.
- a body worn biometric sensor may be connected via a wired or wireless connection to the first mobile device 104, the second mobile device 106, or both.
- Each of the first mobile device 104 and the second mobile device 106 may be, for example, a cellular telephone, a smart phone, a Land Mobile Radio (LMR), a personal digital assistant (PDA), laptop computer, or personal computer with radio frequency (RF) capabilities, or any other type of mobile device with wide area wireless communication capabilities, such as wide area network (WAN) or wireless local area network (WLAN) capabilities, and/or short-range wireless communication capabilities, such as Bluetooth or near-field communication (NFC) capabilities.
- LMR Land Mobile Radio
- PDA personal digital assistant
- RF radio frequency
- the first mobile device 104 and the second mobile device 106 may be referred to as a mobile station (MS), user equipment (UE), user terminal (UT), subscriber station (SS), subscriber unit (SU), remote unit (RU), access terminal, and so on.
- MS mobile station
- UE user equipment
- UT user terminal
- SS subscriber station
- SU subscriber unit
- RU remote unit
- the wireless communication system 100 further includes an infrastructure 120 comprising a radio access network (RAN) 122 that is in communication, via a data network 126, with a user credential server 130 and a public safety agency or enterprise service network 140 (hereinafter referred to as a "service network 140").
- RAN radio access network
- service network 140 a public safety agency or enterprise service network 140
- the user credential server 130 may be part of the service network 140 or may be separate from, and accessible by, the service network 140.
- the RAN 122 includes a wireless access node 124 that provides wireless communication services to mobile devices (for example, the first mobile device 104 and the second mobile device 106) residing in a coverage area of the access node via a corresponding air interface, such as the air interface 116.
- the air interface 116 includes an uplink and a downlink, which uplink and downlink each include multiple traffic channels and multiple signaling channels.
- the wireless access node 124 may be any network-based wireless access node, such as a Node B, an evolved Node B (eNB), an access point (AP), or base station (BS).
- the RAN 122 also may include one or more access network controllers (not shown), such as a Radio Network Controller (RNC) or a Base Station Controller (BSC), coupled to the one or more wireless access nodes;
- RNC Radio Network Controller
- BSC Base Station Controller
- the functionality of such an access network controller may be implemented in the access node.
- the user credential server 130 may be one or more of an identity management server (IdM), a Registration Authority (RA), a Certificate Authority (CA), an entire public key infrastructure (PKI) (containing an RA and CA as well as other PKI components), or any other type of public key cryptography system that manages public keys.
- IdM identity management server
- RA Registration Authority
- CA Certificate Authority
- PKI entire public key infrastructure
- the user credential server 130 issues and maintains user credentials for each of the users of the wireless communication system 100.
- the user credentials may include a signed data structure, for example, a digital certificate or an identity token, that a user can use to authenticate himself or herself to other elements of wireless communication system 100 and/or establish a secure connection with such other elements.
- the service network 140 includes a user subscription database 142 (for example, a Home Subscriber Server (HSS)), which maintains subscription and profile information for each user subscribed to the services of the service network 140 (for example, user 102). Some embodiments refer to the user 102 as a subscriber.
- the profile information for the user 102 may include a role of the user 102 in the wireless communication system 100 (for example, an employment area, title, or responsibility associated with the user 102), or a relationship between the user 102 and one or more other members of a communication group that includes the user 102.
- the profile information for the user 102 may also include a rank or other prioritization of the user 102 over another user (for example, whether the user 102 is a fire/police officer or non-officer, or whether the user is a fire/police battalion commander, lieutenant, or sergeant).
- the profile information for the user 102 may also identify a service network sub-network, such as a service network department or precinct, to which the user 102 belongs.
- the service network 140 further includes a device authorization database 144, a policy and attribute access control database 146, and a biometric template server 148.
- the device authorization database 144 maintains a list of identifiers of mobile devices, such as the first mobile device 104 and the second mobile device 106, that are shareable devices, that is, that may be used by each of multiple different users, such as the user 102.
- some embodiments provide shareable devices that are enhanced to perform biometric authentication to control which users can authenticate to the service network 140 using the devices.
- the policy and attribute access control database 146 maintains attributes of users ("authorization attributes"), such as the user 102, who are authorized to use a shared device, such as the first mobile device 104 and the second mobile device 106.
- the policy and attribute access control database 146 also maintains policies controlling such users' use of a shared device with the service network 140, such as contextual and situational conditions on use.
- attributes may include, for example, the user profile information as described above.
- Other attributes may include mobile device types (such as mobile device brands, mobile devices having certain applications available, such as voice, video, data, and Push-to-Talk (PTT), or mobile devices supporting certain versions of hardware or software) or mobile device pools (for example, a list or range of identifiers of multiple shared mobile devices) that a user is limited to using; applications, functions, or resources of a shared device that a user is allowed to access/use; a user assurance level, that is, a level of authentication that a user is considered to be authenticated at when the user is authenticated using a biometric template; and attributes controlling the use of the biometric template (for example, whether the biometric template is for use merely in an initial authentication of the user or may also be used for continuous authentication).
- mobile device types such as mobile device brands, mobile devices having certain applications available, such as voice, video, data, and Push-to-Talk (PTT), or mobile devices supporting certain versions of hardware or software
- mobile device pools for example, a list or range of identifiers of multiple shared mobile devices that
- policies and attributes may also include a biometric template lifetime, that is, a limited period of time during which a biometric template is valid and the corresponding user is allowed to use the shared device.
- a biometric template lifetime expires, a mobile device storing or using the biometric template deletes the biometric template, and may be required to delete any user credentials, such as certificates, downloaded by the mobile device from the user credential server 130 during the lifetime of the biometric template.
- attributes may include attributes controlling the users' use of a user credential, such as a user credential validity period, which limits the useful life of a received user credential, and a user credential subject name.
- the policy and attribute access control database 146 may be pre-provisioned into the service network 140 by an operator of the service network 140.
- the biometric template server 148 maintains a biometric template for each user authorized to use a shared device, such as the first mobile device 104 and the second mobile device 106, and further maintains a user identifying input or inputs associated with each biometric template.
- Each biometric template maintained by the biometric template server 148 includes any one or more types of biometric data, that is, one or more biometric identifiers (for example, an iris scan, fingerprint, palm print, facial-recognition- ready photograph, voice data, an electrocardiogram, and the like) that may be used to authenticate an associated user.
- the user identifying input includes data (for example, a user name, codeword, key, personal identification number, or voice input such as the user saying his or her name, and the like), that may be input to a mobile device by a user, such as the user 102, of the mobile device and that can be used by biometric template server 148 to uniquely identify a biometric template of the user.
- data for example, a user name, codeword, key, personal identification number, or voice input such as the user saying his or her name, and the like
- biometric template server 148 can retrieve a biometric template associated with the received user identifying input, and return the retrieved biometric template to the mobile device.
- the user subscription database 142, device authorization database 144, policy and attribute access control database 146, and biometric template server 148 are each an element of service network 140, each may be referred to as a service network element of the wireless communication system 100.
- the elements of the RAN 122 such as the wireless access node 124, data network 126, user credential server 130, and the multiple service network elements 142, 144, 146, and 148 are each an element of the infrastructure 120, each may also be referred to as an infrastructure element of the wireless communication system 100.
- the infrastructure 120 can be any type of communication network, wherein the first mobile device 104 and the second mobile device 106 communicate with infrastructure elements using any suitable over-the-air protocol and modulation scheme.
- the infrastructure 120 may include a further number of infrastructure elements for a commercial embodiment that are commonly referred to as, but not limited to, bridges, switches, zone controllers, routers, authentication centers, or any other type of infrastructure equipment facilitating communications between entities in a wireless or wired network environment.
- the wireless communication system 100 is illustrated by reference to a limited number of devices for ease of illustration. However, any suitable number of mobile devices and infrastructure elements may be implemented in a commercial system without loss of generality of the teachings herein.
- FIG. 2 is a block diagram of one exemplary embodiment of a shared mobile device 200, which is representative of the first mobile device 104 and the second mobile device 106.
- the mobile device 200 generally includes a processor 202, at least one memory device 204, a wireless interface 216, and an input/output (I/O) interface 218.
- I/O input/output
- FIG. 2 depicts the mobile device 200 in an oversimplified manner, and a practical embodiment may include additional components and suitably configured processing logic to support known or conventional operating features that are not described in detail herein.
- the mobile device 200 operates under the control of the processor 202 , such as one or more microprocessors, microcontrollers, digital signal processors (DSPs), combinations thereof or such other devices known to those having ordinary skill in the art.
- the processor 202 operates the corresponding mobile device according to data and instructions stored in the at least one memory device 204, such as random access memory (RAM), dynamic random access memory (DRAM), and/or read only memory (ROM) or equivalents thereof, that stores data and instructions that may be executed by the corresponding processor so that the mobile device may perform the functions described herein.
- RAM random access memory
- DRAM dynamic random access memory
- ROM read only memory
- the data and instructions maintained by the at least one memory device 204 include software programs that include an ordered listing of executable instructions for implementing logical functions.
- the software in at least one memory device 204 may include a suitable operating system and software programs.
- the operating system controls the execution of other computer programs, and provides scheduling, input-output control, file and data management, memory management, and
- the programs may include various or applications ("apps"), add-ons, and the like configured to provide user functionality with the mobile device 200.
- the at least one memory device 204 also maintains one or more mobile device identifiers (for example, a mobile station identifier (MS ID), a subscriber unit identifier (SU ID), an International Mobile Subscriber Identity (IMSI), or a
- MS ID mobile station identifier
- SU ID subscriber unit identifier
- IMSI International Mobile Subscriber Identity
- the at least one memory device 204 also maintains a service network identifier, which identifies the service network 140 (for example, a public safety agency), to which the mobile device belongs, and a service network sub-network identifier which identifies the sub-network (for example, an identifier of a department or a precinct of the public safety agency) of the service network 140, to which the mobile device belongs.
- a service network identifier which identifies the service network 140 (for example, a public safety agency), to which the mobile device belongs
- a service network sub-network identifier which identifies the sub-network (for example, an identifier of a department or a precinct of the public safety agency) of the service network 140, to which the mobile device belongs.
- the mobile device 200 further includes a security module 206.
- the security module 206 includes security functions such as, for example, encryption, decryption, key generation, certificate data signing, and the like.
- the security module 206 may be implemented in hardware, software, or a combination thereof.
- the security module 206 also includes algorithms for generating, sending, receiving, manipulating, and storing the user credentials 208, private keys, public keys, digital certificates, identity tokens, and the like for use in secure authentication to the service network 140 (or elements thereof).
- the security module 206 maintains an encryption/decryption key that is shared with biometric template server 148 and that may be used to encrypt and decrypt a biometric template maintained by the biometric template server 148.
- the security module 206 and the biometric template server 148 do not share a symmetric key. Instead, the security module 206 has access to the public key of the biometric template server 148, and the biometric template server 148 has access to the public key of the security module 206.
- mobile device 200 may additionally include a hardware security module (HSM) 210.
- HSM 210 is a hardware-based encryption and key management device that provides hardware-based cryptographic functions similar to the security module 206, and provides tamper protection for the user credentials 208.
- the device private keys are generated in the HSM and are not exposed to any other component of the mobile device, but a CA certificate and a device RA certificate maintained by the HSM 210 can be copied to the at least one memory device 204 for efficiency of cryptographic operations.
- the HSM 210 is a CRYPTRTM micro chip available from Motorola Solutions, Inc., which micro chip may be installed in a microSD slot of a mobile device.
- a CRYPTR-based PKI operation is more secure than a software-based key storage approach. That is, the CRYPTR generates and stores private keys in a tamper resistant hardware security module. For any PKI operation, data is sent to the CRYPTR and the CRYPTR does the signing and returns the signed data to a requesting application. Thus, the private keys are never exposed to any application executing on a mobile device.
- the wireless interface 216 facilitates an exchange of wireless communications with the RAN 122.
- the wireless interface 216 may include a wireless area network (WAN) radio transceiver with a corresponding antenna for exchanging WAN communications with the RAN 122.
- the I/O interface 218 allows a user to input information into, and receive information from, the mobile device 200.
- the I/O interface 218 may include a keypad, a touch screen, a scroll ball, a scroll bar, buttons, bar code scanner, a microphone, and the like.
- the I/O interface 218 may include a display device such as a liquid crystal display (LCD), touch screen, and, a audio speaker the like for displaying system output.
- LCD liquid crystal display
- the I/O interface 218 also includes one or more biometric data collection devices 220 that collect biometric data from a user of the mobile device, for example, user 102, and store the collected biometric data in at least one memory device 204.
- the one or more biometric data collection devices 220 may include an imaging device, such as a digital camera, that the user 102 can use to take his or her picture, a fingerprint scanner that the user 102 can use to scan his or her fingerprint into the mobile device 200, an iris scanner that the user 102 can use to scan his or her iris pattern into the mobile device 200, or a microphone that collects voice audio patterns of the user 102.
- the collected biometric data of the user 102 may be conveyed to the service network 140 for storage in the biometric template server 148, or it may be compared to a biometric template downloaded by the mobile device 200 from biometric template server 148 to verify an identity of a user attempting to use the mobile device 200.
- the I/O interface 218 may also include, for example, a serial port, a parallel port, a small computer system interface (SCSI), an infrared (IR) interface, a universal serial bus (USB) interface, a microSD slot, and the like for communicating with, or coupling to, an external device.
- SCSI small computer system interface
- IR infrared
- USB universal serial bus
- microSD slot and the like for communicating with, or coupling to, an external device.
- the components (202, 204, 210, 216, and 218) of the mobile device 200 are communicatively coupled via a local interface 222.
- the local interface 222 may be, for example, one or more buses or other wired or wireless connections, as is known in the art.
- the local interface 222 may have additional elements, which are omitted for simplicity, such as controllers, buffers (caches), drivers, repeaters, and receivers, among many others, to enable communications.
- the local interface 222 may include address, control, and/or data connections to enable appropriate communications among the aforementioned components.
- the one or more biometric data collection devices 220 may be physically located on a separate device that this is securely paired to the mobile device 200 using, for example, Bluetooth or another suitable wireless protocol.
- FIG. 3 illustrates an exemplary embodiments of a user credential server 130.
- the user credential server 130 may be, for example, a public key infrastructure element such as a Registration Authority (RA) and/or a Certificate Authority (CA).
- the user credential server 130 operates under the control of a processor 302, for example, one or more microprocessors, microcontrollers, digital signal processors (DSPs), combinations thereof or such other devices known to those having ordinary skill in the art.
- a processor 302 for example, one or more microprocessors, microcontrollers, digital signal processors (DSPs), combinations thereof or such other devices known to those having ordinary skill in the art.
- DSPs digital signal processors
- the processor 302 operates the user credential server 130 according to data and instructions stored in an at least one memory device 304, such as random access memory (RAM), dynamic random access memory (DRAM), and/or read only memory (ROM) or equivalents thereof, that stores data and programs that may be executed by the corresponding processor so that the server may perform the functions described herein.
- RAM random access memory
- DRAM dynamic random access memory
- ROM read only memory
- the user credential server 130 further includes one or more network interfaces 306 for connecting to other elements of the infrastructure 120, such as the user subscription database 142, device authorization database 144, policy and attribute access control database 146, biometric template server 148, and data network 126.
- the user credential server 130 communicates via the one or more network interfaces 306 and the data network to other devices of the wireless communication system 100, such as the first mobile device 104 and the second mobile device 106.
- the one or more network interfaces 306 may include a wireless, a wireline, and/or an optical interface that is capable of conveying messages (for example, data packets) to, and receiving messages from, the data network 126.
- the user credential server 130 further includes, or is in communication with via the one or more network interfaces 306, a Certificate Repository (CR) 310.
- the CR 310 is implemented with an electronic database, which is used to provide persistent storage digital certificates 312, such as, for example, user certificates, RA certificate 134, CA certificate 138, and device certificates associated with the first mobile device 104 and the second mobile device 106, which device certificates may be used by the user credential server 130 to validate, and securely communication with, the mobile devices.
- the first mobile device 104 and the second mobile device 106 use a public key pair without a certificate to authenticate to the user credential server 130, the biometric template server 148, and other servers of the service network 140.
- the components (302, 304, 306, 310) of the user credential server 130 are communicatively coupled via a local interface 308.
- the local interface 308 may be, for example, one or more buses or other wired or wireless connections, as is known in the art.
- the local interface 308 can have additional elements, which are omitted for simplicity, such as controllers, buffers (caches), drivers, repeaters, and receivers, among many others, to enable communications.
- the local interface 308 may include address, control, and/or data connections to enable appropriate communications among the aforementioned components.
- FIG. 4 illustrates an exemplary embodiment of a service network element 400, such as the user subscription database 142, device authorization database 144, policy and attribute access control database 146, and biometric template server 148.
- the service network element 400 includes a processor 402, for example, one or more
- the service network element 400 further includes at least one memory device 404, such as random access memory (RAM), dynamic random access memory (DRAM), and/or read only memory (ROM) or equivalents thereof, which is in communication with the processor 402 via a corresponding local interface 408.
- Each of the at least one memory devices 404 stores data and programs, such as group call programs, that may be executed by the processor 402 and that allow the service network element 400 to perform functions to operate in wireless communication system 100.
- the memory of the device authorization database 144 maintains a list of mobile devices, such as the first mobile device 104 and the second mobile device 106, that are shareable devices (that is, that may be used by each of multiple different users, such as user 102). It should be noted that, in some embodiments, the device authorization database 144 is not used.
- the device certificate issued to the mobile device contains one or more attributes that indicate to the biometric template server 148 that the mobile device is authorized to request a biometric template, and that indicate to the user credential server 130 that the mobile device is authorized to request a user credential.
- the memory of the policy and attribute access control database 146 maintains attributes of users (for example, contextual and situational conditions on use), such as the user 102, who are authorized to use a shared device, and policies controlling such users' use of the shared device to access the service network 140.
- attributes of users for example, contextual and situational conditions on use
- users for example, contextual and situational conditions on use
- policies controlling such users' use of the shared device to access the service network 140.
- the memory of the biometric template server 148 maintains a biometric template for each user authorized to use a shared device.
- the biometric template server 148 may be pre-provisioned with the biometric templates by an operator of service network 140 or may, as described in detail below, receive a biometric template from a user via a mobile device when the user initially enrolls in service network 140.
- the service network element 400 further includes one or more network interfaces 406 (one shown) that are in communication with the processor 402 via the respective local interface 408 and that provides for interfacing with other service network elements and with other infrastructure elements of the wireless communication system 100.
- the local interface 408 may be, for example, one or more buses or other wired or wireless connections, as is known in the art.
- the local interface 408 may include additional elements, which are omitted for simplicity, such as controllers, buffers (caches), drivers, repeaters, and receivers, among many others, to enable communications.
- the local interface 408 may include address, control, and/or data connections to enable appropriate communications among the aforementioned components of the service network element 400.
- a mobile device such as first mobile device 104 or the second mobile device 106
- the user credential server 130 a service network element 400 (such as the user subscription database 142, the device authorization database 144, the policy and attribute access control database 146, and the biometric template server 148) is implemented with or in software programs and instructions stored in the respective memory and executed by the associated processor.
- a user credential scheme for example, a PKI scheme, uses a user credential, such as a digital certificate, to verify that a particular public key belongs to a certain end entity (for example, the user 102) and may be used for access control.
- the certificate is an electronic document that is issued by a trusted party and that is used to prove ownership of a public key.
- the certificate includes information about the key and an identity of the key owner, and further includes a digital signature of a Certificate Authority (CA), that is, an entity that has verified that the certificate's contents are correct.
- CA Certificate Authority
- a user via client software on a mobile device of a user, has to go through a user credential enrollment process with the user credential server.
- the user credential server 130 may include a CA that issues and controls the life cycle of the user certificates, and may include an RA that performs the user/mobile device authentication for the CA before any user credential can be generated for the user/mobile device.
- the wireless communication system 100 provides for an infrastructure- based storage of biometric templates of users, wherein a biometric template for a given user may be downloaded by a shared mobile device when that user logs into the device and then may be used to authenticate the user as part of a user credential enrollment process. [0046] FIGS.
- 5A and 5B illustrate an exemplary method 500 for controlling the distribution of a biometric template for a user, such as user 102, using the wireless communication system 100.
- the first mobile device 104 currently being used by user 102, conveys to the biometric template server 148, and the biometric template server receives from the first mobile device 104, a first authentication request whereby the first mobile device 104 requests to be authenticated to the biometric template server 148.
- the first authentication request includes a first device credential associated with the first mobile device, such as a mobile station identifier (MS ID), a subscriber unit identifier (SU ID), an International Mobile Subscriber Identity (IMSI), a Temporary Mobile Subscriber Identity (TMSI), a device certificate, or a public key pair that identifies the first mobile device in wireless communication system 100.
- the device credential contains enough information for the biometric template server 148 to determine that the first mobile device 104 is authorized to upload the biometric template.
- the biometric template server 148 can uniquely identify the first mobile device 104 and refer to device authorization database 144.
- the biometric template server 148 can use those attributes to determine that the first mobile device 104 is authorized to access or upload biometric templates.
- the first mobile device 104 conveys to biometric template server 148, and the biometric template server receives from the first mobile device, a request to upload a biometric template from the first mobile device to the biometric template server.
- the request may include a user identifying input that identifies a user of the first mobile device, that is, user 102.
- the user may provide a user identifying input to the first mobile device 104.
- the user identifying input includes data, such as a user name, codeword or a key, that may be input to the first mobile device 104 by a user and that can be used by biometric template server 148 to retrieve a biometric template of the user.
- the user identifying input may be a username, a password, a 2-factor authentication, a biometric input, a smart card input and/or another identifier associated with the user.
- the user identifying input also can include one or more other factors associated with the user, for example, something that user knows, something that the user has, and/or something that the user is.
- An operator of wireless communication system 100 may set the type of user identifying input for the user when the user begins working for the system operator.
- biometric template server 148 determines that first mobile device 104 is authorized to upload the biometric template to the biometric template server. That is, in response to receiving the first authentication request and the request to upload a biometric template, and by reference to one or more of the first device credential and the device authorization database 144, the biometric template server 148 determines that first mobile device 104 is authorized to operate in the wireless communication system 100. Based on such a determination, the biometric template server 148 further determines that the first mobile device 104 is authorized to upload a biometric template to the biometric template server. In some embodiments, the first mobile device 104 may be a specialized device dedicated to uploading biometric templates.
- the biometric template server 148 may determine that the first mobile device 104 is authorized to upload a biometric template to the biometric template server 148 based on one or more attributes that control a use of the biometric template and are associated with the user 102.
- the biometric template server 148 may retrieve one or more attributes associated with the user 102, such as an agency or enterprise that employs the user, a department that the user works for within the agency or enterprise, an agency precinct where the user is stationed, such as a police department or fire department precinct, a geographical jurisdiction of the agency or enterprise that employs the user or where the user currently is stationed, a role of the user or a rank of the user within the agency or enterprise that employs the user.
- attributes associated with the user 102 such as an agency or enterprise that employs the user, a department that the user works for within the agency or enterprise, an agency precinct where the user is stationed, such as a police department or fire department precinct, a geographical jurisdiction of the agency or enterprise that employs the user or where the user currently is stationed, a role of the user or a rank of the user within the agency or enterprise that employs the user.
- the biometric template server 148 further may obtain, from the policy and attribute access control database 146, information concerning the requisite attributes for uploading a biometric template to the biometric template server 148 via the first mobile device 104, such as an agency, enterprise, precinct, and geographical jurisdiction to which the first mobile device 104 is registered, or a required role or rank of a user who is authorized to upload biometric templates to the biometric template server 148.
- the biometric template server 148 may compare the attributes associated with the user 102 to the attributes associated with the mobile device and authorize the first mobile device 104 to upload a biometric template to the biometric template server 148 when the attributes match.
- the attributes considered by the biometric template server 148 may include a requisite assurance level before the biometric template server 148 authorizes the user or mobile device to upload the biometric template or an authority indicator.
- the first mobile device 104 uploads to the biometric template server 148 a biometric template of the user 102 of the first mobile device 104. That is, in response to determining that the first mobile device 104 is authorized to upload a biometric template to the biometric template server 148, the biometric template server 148 notifies the first mobile device 104 that the first mobile device 104 may proceed to upload the biometric template.
- the first mobile device 104 collects, from the user 102 and via the one or more biometric data collection devices 220 of the first mobile device 104, biometric data of the user, for example, an iris scan, a fingerprint, a palm print, a facial-recognition-ready photograph, voice data, or an electrocardiogram that may be used to identify the user.
- biometric data of the user for example, an iris scan, a fingerprint, a palm print, a facial-recognition-ready photograph, voice data, or an electrocardiogram that may be used to identify the user.
- the first mobile device 104 conveys, to the biometric template server 148, a biometric template including the biometric data collected from the user 102.
- the first mobile device 104 may also send some amount of metadata associated with the user of the biometric template.
- the first mobile device 104 before uploading the biometric template to the biometric template server 148, the first mobile device 104 encrypts the biometric template using, for example, one or more of a user provided PIN, the public key of the biometric template server 148, or a shared key known to the biometric template server 148 and the first mobile device 104.
- the biometric template server 148 stores the biometric template in association with an identifier of user 102, such as the user identifying input provided by the first mobile device 104. Additionally, the biometric template server 148 may encrypt the biometric template using an encryption/decryption key known to, and maintained by each of a plurality of, mobile devices and the biometric template server 148 to produce an encrypted biometric template, and store the encrypted biometric template. Use of an encrypted biometric template provides enhanced authentication security, as only a mobile device in possession of the encryption/decryption key will be able to use the biometric template to authenticate a user.
- the biometric template server 148 encrypts the biometric template regardless of whether it has already been encrypted by the first mobile device 104.
- Blocks 502 through 510 may be repeated in order to store multiple biometric identifiers (for example, an iris scan, fingerprint, palm print, facial- recognition-ready photograph, voice data, an electrocardiogram, and the like) for the user 102.
- the multiple biometric identifiers are contained in a single biometric template.
- the stored biometric template is available to be downloaded to, for example, the second mobile device 106, which can use the template to authenticate the user 102 on the second mobile device 106.
- the user 102 At some point in time after uploading the biometric template of user 102 to biometric template server 148 via first mobile device 104, the user 102 provides user identifying input to the second mobile device 106.
- the user identifying input matches the input entered at block 504, above, and can therefore be used by biometric template server 148 to retrieve the biometric template of the user 102.
- the second mobile device 106 conveys to the biometric template server 148, and the biometric template server receives from the second mobile device 106, a second authentication request, whereby the second mobile device 106 requests to be authenticated with the biometric template server 148.
- the second authentication request includes a second device credential associated with the second mobile device 106 that may indicate that the mobile device is authorized to access biometric template data.
- the second mobile device 106 conveys to the biometric template server 148, and the biometric template server 148 receives from the second mobile devicel06 , a request to download a biometric template associated with the user 102 from the biometric template server 148.
- This request may include, or may be accompanied or preceded by, the user identifying input that identifies the current user 102 of the second mobile device.
- the user identifying input includes data, which can be used by biometric template server 148 to retrieve the biometric template of the user.
- the biometric template server 148 determines that the second mobile device 106 is authorized to download the biometric template from the biometric template server 148. That is, in response to receiving the second authentication request and the request to download the biometric template, and by reference to one or more of the second device credential and the device authorization database 144, the biometric template server 148 determines that second mobile device 106 is authorized to operate in the wireless communication system 100. Based on such a determination, the biometric template server 148 further determines that the second mobile device is authorized to download a biometric template and, based on the user identifying input received from the second mobile device 106, retrieves the biometric template associated with the user 102.
- the biometric template server 148 in determining that second mobile device 106 is authorized to download a biometric template to the biometric template server, the biometric template server 148 further may consider metadata (for example, one or more attributes that are associated with user 102) and that will control a use of the biometric template.
- the biometric template server 148 may retrieve metadata including one or more attributes associated with the user 102, such as an agency or enterprise that employs the user, a department that the user works for within the agency or enterprise, an agency precinct where the user is stationed, such as a police department or fire department precinct, a geographical jurisdiction of the agency or enterprise that employs the user or where the user currently is stationed, a role of the user or a rank of the user within the agency or enterprise that employs the user.
- the biometric template server 148 further may obtain, from the policy and attribute access control database 146, information concerning the requisite attributes for downloading a biometric template from the biometric template server 148 via the second mobile device 106.
- Such attributes may include, for example, an agency, enterprise, precinct, and geographical jurisdiction to which the mobile device is registered, or a required role or rank of a user who is authorized to download biometric templates from the biometric template server.
- the biometric template server 148 compares the attributes associated with the user 102 to the attributes associated with the second mobile device 106. In one embodiment, the second mobile device 106 is authorized to download a biometric template from the biometric template server 148 when the attributes match.
- the attributes considered by the biometric template server 148 further, or instead, may include a requisite assurance level before the biometric template server authorizes the user/mobile device to upload the biometric template or an authority indicator.
- the biometric template is decrypted by the second mobile device 106 using the same user input or key used to encrypt it.
- the decrypted biometric template may be used by the second mobile device 106 to authenticate the user 102 and to control access to, and a downloading (at blocks 520, 522) by the second mobile device 106 of, a user credential for user 102.
- FIG. 6 illustrates an exemplary method 600 for operating the wireless
- the method 600 assumes that the biometric template server 148, as described above, maintains a biometric template, preferably in an encrypted format, for a user, such as the user 102.
- the biometric template may include multiple biometric identifiers for the user 102.
- the user 102 obtains the first mobile device 104 and provides to first mobile device 104 a user identifying input, as described in detail above.
- the user identifying input may be part of a login of the user to the first mobile device 104.
- An operator of wireless communication system 100 may set the type of user identifying input for the user 102 when the user 102 begins working for or with the system operator.
- the first mobile device 104 authenticates to the biometric template server 148, and conveys a request for a biometric template, which request includes the user identifying input.
- the first mobile device 104 may authenticate using a device certificate that includes a mobile device identifier, such as an IMEI and/or an IMS!
- the device credential contains enough information for the biometric template server 148 to determine that the first mobile device 104 is authorized to upload the biometric template.
- the user identifying input allows biometric template server 148 to retrieve the biometric template associated with the user 102.
- the first mobile device 104 receives one or more messages, the one or more messages including the biometric template for the user.
- the first mobile device 104 authenticates the user based on the received biometric template.
- Biometric authentication methods are known, and will not be described in greater detail, except to say that biometric authentication of the user is performed by taking fresh biometric samples from the user and comparing them to the data in the biometric templates.
- the received biometric template is received encrypted and is decrypted by the first mobile device 104 before authentication.
- the first mobile device 104 may decrypt the received template with at least one of the private key of the first mobile device 104, a shared key known to the biometric template server 148 and the first mobile device 104, or with user provided input such as a PIN..
- the first mobile device 104 decrypts the encrypted biometric template based on the user input to produce a decrypted template, and the user 102 is authenticated by the first mobile device 104 based on the decrypted biometric template.
- the first mobile device 104 In response to successfully authenticating the user 102, the first mobile device 104 allows the user access to the device and it's applications. In some embodiments, the first mobile device 104 may cause the screen and keyboard to unlock, and may provide the user access to other resources on the mobile device.
- the first mobile device 104 assembles a request for a user credential, such as a digital certificate, for the first mobile device 104 based on the metadata received in the one or more messages (for example, the conditions on use).
- the user credential request may be a PKI Certificate Management Protocol (CMP) certification request, as described in Internet Engineering Task Force (IETF) Request For Comments (RFC) 4210.
- CMP PKI Certificate Management Protocol
- IETF Internet Engineering Task Force
- RRC Request For Comments
- the first mobile device 104 signs the user credential request using its private key of a private/public key pair associated with the device to produce a signed user credential request (that is, a signed request), and, at block 614, conveys the signed user credential request to the user credential server 130.
- the first mobile device 104 may be authorized to act as an RA, in which event the first mobile device 104 may sign the user credential request with the private key, (that is, a registration authority key) of a private/public key pair associated with the device RA certificate of the first mobile device 104.
- the first mobile device 104 authenticates to the user credential server 130 with a device credential that indicates that the mobile device is authorized to request user credentials.
- the device credential further indicates that the first mobile device 104 performs biometric user authentication prior to sending the user credential request to the user credential serverl 30.
- the user credential server 130 validates the user credential request.
- the user credential server 130 validates the user credential request by validating the first mobile device 104's signature of the user credential request, using a public key of the private/public key pair associated with the device such as the public key contained in the first mobile device 104's device certificate.
- the user credential server 130 further may validate the user credential request by use of a corresponding device RA public key.
- the user credential server 130 generates a user credential response, such as a CMP Certification Response, that includes the user credential for the first mobile device 104.
- a user credential response such as a CMP Certification Response
- the user credential server 130 conveys the user credential response to the first mobile device 104 via the data network 126 and the RAN 122.
- the user credential server 130 does not send a response to the first mobile device 104, but instead the first mobile device 104 polls the certificate repository for the newly issued user certificate.
- the user credential server 130 only returns a uniform resource locator (URL) that the first mobile device 104 can use to obtain the user credential.
- URL uniform resource locator
- the first mobile device 104 securely stores the user credential in its security module 206, HSM 210, or both. In some embodiments, the first mobile device 104 requires biometric authorization of the user 103 to securely store the user credential.
- a includes ... a
- or “contains ... a” does not, without more constraints, preclude the existence of additional identical elements in the process, method, article, or apparatus that comprises, has, includes, contains the element.
- the terms “a” and “an” are defined as one or more unless explicitly stated otherwise herein.
- the terms “substantially,” “essentially,” “approximately,” “about” or any other version thereof, are defined as being close to as understood by one of ordinary skill in the art, and in one non-limiting embodiment the term is defined to be within 10%, in another embodiment within 5%, in another embodiment within 1% and in another embodiment within 0.5%.
- the term “coupled” as used herein is defined as connected, although not necessarily directly and not necessarily mechanically.
- a device or structure that is "configured” in a certain way is configured in at least that way, but may also be configured in ways that are not listed.
- processors or “processing devices” such as microprocessors, digital signal processors, customized processors and field programmable gate arrays (FPGAs) and unique stored program instructions (including both software and firmware) that control the one or more processors to implement, in conjunction with certain non- processor circuits, some, most, or all of the functions of the method and/or apparatus described herein.
- some or all functions could be implemented by a state machine that has no stored program instructions, or in one or more application specific integrated circuits (ASICs), in which each function or some combinations of certain of the functions are implemented as custom logic.
- ASICs application specific integrated circuits
- Both the state machine and ASIC are considered herein as a "processing device" for purposes of the foregoing discussion and claim language.
- an embodiment can be implemented as a computer-readable storage element or medium having computer readable code stored thereon for programming a computer (e.g., comprising a processing device) to perform a method as described and claimed herein.
- Examples of such computer-readable storage elements include, but are not limited to, a hard disk, a CD-ROM, an optical storage device, a magnetic storage device, a ROM (Read Only Memory), a PROM (Programmable Read Only Memory), an EPROM (Erasable Programmable Read Only Memory), an EEPROM (Electrically Erasable Programmable Read Only Memory) and a Flash memory.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computing Systems (AREA)
- Biomedical Technology (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Software Systems (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Life Sciences & Earth Sciences (AREA)
- Biodiversity & Conservation Biology (AREA)
- Telephonic Communication Services (AREA)
- Telephone Function (AREA)
- Storage Device Security (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CA3019168A CA3019168A1 (en) | 2016-04-13 | 2017-04-05 | Method and apparatus for using a biometric template to control access to a user credential for a shared wireless communication device |
| GB1815538.2A GB2564595A (en) | 2016-04-13 | 2017-04-05 | Method and apparatus for using a biometric template to control access to a user credential for a shared wireless communication device |
| DE112017002032.8T DE112017002032T5 (en) | 2016-04-13 | 2017-04-05 | A method and apparatus for using a biometric template to control access to user credentials for a shared wireless communication device |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US15/097,767 US20170300678A1 (en) | 2016-04-13 | 2016-04-13 | Method and apparatus for using a biometric template to control access to a user credential for a shared wireless communication device |
| US15/097,767 | 2016-04-13 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017180384A1 true WO2017180384A1 (en) | 2017-10-19 |
Family
ID=58549300
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2017/026093 Ceased WO2017180384A1 (en) | 2016-04-13 | 2017-04-05 | Method and apparatus for using a biometric template to control access to a user credential for a shared wireless communication device |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20170300678A1 (en) |
| CA (1) | CA3019168A1 (en) |
| DE (1) | DE112017002032T5 (en) |
| GB (1) | GB2564595A (en) |
| WO (1) | WO2017180384A1 (en) |
Families Citing this family (20)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2013082329A1 (en) * | 2011-11-29 | 2013-06-06 | Bruce Ross | Layered security for age verification and transaction authorization |
| WO2016081726A1 (en) * | 2014-11-19 | 2016-05-26 | Booz Allen & Hamilton | Device, system, and method for forensic analysis |
| EP3536002B1 (en) * | 2016-11-08 | 2020-11-18 | Aware, Inc. | Decentralized biometric identity authentication |
| US11588813B2 (en) * | 2016-12-08 | 2023-02-21 | Mastercard International Incorporated | Systems and methods for biometric authentication using existing databases |
| EP3632034B1 (en) * | 2017-06-02 | 2021-10-13 | Visa International Service Association | Methods and systems for ownership verification using blockchain |
| RU2659675C1 (en) * | 2017-07-07 | 2018-07-03 | Илья Владимирович Редкокашин | Method of personal information transmission |
| SE1751451A1 (en) | 2017-11-24 | 2019-05-25 | Fingerprint Cards Ab | Biometric template handling |
| KR102510543B1 (en) * | 2018-04-26 | 2023-03-16 | 삼성전자주식회사 | Electronic device carrying out communication with wearable device receiving biometric information |
| CN110858245B (en) * | 2018-08-24 | 2021-09-21 | 珠海格力电器股份有限公司 | Authorization method and data processing equipment |
| US10810293B2 (en) * | 2018-10-16 | 2020-10-20 | Motorola Solutions, Inc. | Method and apparatus for dynamically adjusting biometric user authentication for accessing a communication device |
| US11140239B2 (en) | 2019-12-30 | 2021-10-05 | Motorola Mobility Llc | End a shareable device interactive session based on user intent |
| US11640453B2 (en) | 2019-12-30 | 2023-05-02 | Motorola Mobility Llc | User authentication facilitated by an additional device |
| US11019191B1 (en) | 2019-12-30 | 2021-05-25 | Motorola Mobility Llc | Claim a shareable device for personalized interactive session |
| US11284264B2 (en) * | 2019-12-30 | 2022-03-22 | Motorola Mobility Llc | Shareable device use based on user identifiable information |
| WO2021226471A1 (en) * | 2020-05-08 | 2021-11-11 | Marc Duthoit | Computer-implemented user identity verification method |
| WO2022046088A1 (en) * | 2020-08-31 | 2022-03-03 | Google Llc | Home toy magic wand management platform interacting with toy magic wands of visitors |
| JP7590927B2 (en) * | 2021-06-07 | 2024-11-27 | 株式会社日立製作所 | DATA MANAGEMENT SYSTEM, DATA MANAGEMENT METHOD, AND DATA MANAGEMENT PROGRAM |
| US11653193B1 (en) * | 2021-12-14 | 2023-05-16 | Motorola Solutions, Inc. | Communication system and method for controlling access to portable radio public safety service applications |
| CN113993115B (en) * | 2021-12-27 | 2022-04-01 | 飞天诚信科技股份有限公司 | Automatic unlocking screen method, device, electronic device and readable storage medium |
| JP7766808B2 (en) * | 2022-06-10 | 2025-11-10 | 楽天モバイル株式会社 | Certificate Enrollment for Shared Network Elements |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20070220274A1 (en) * | 2005-10-17 | 2007-09-20 | Saflink Corporation | Biometric authentication system |
| JP2015121910A (en) * | 2013-12-24 | 2015-07-02 | 株式会社日立製作所 | Portable key device and device control method |
| US20150220931A1 (en) * | 2014-01-31 | 2015-08-06 | Apple Inc. | Use of a Biometric Image for Authorization |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8325994B2 (en) * | 1999-04-30 | 2012-12-04 | Davida George I | System and method for authenticated and privacy preserving biometric identification systems |
| US20080052527A1 (en) * | 2006-08-28 | 2008-02-28 | National Biometric Security Project | method and system for authenticating and validating identities based on multi-modal biometric templates and special codes in a substantially anonymous process |
-
2016
- 2016-04-13 US US15/097,767 patent/US20170300678A1/en not_active Abandoned
-
2017
- 2017-04-05 GB GB1815538.2A patent/GB2564595A/en not_active Withdrawn
- 2017-04-05 WO PCT/US2017/026093 patent/WO2017180384A1/en not_active Ceased
- 2017-04-05 DE DE112017002032.8T patent/DE112017002032T5/en not_active Withdrawn
- 2017-04-05 CA CA3019168A patent/CA3019168A1/en not_active Abandoned
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20070220274A1 (en) * | 2005-10-17 | 2007-09-20 | Saflink Corporation | Biometric authentication system |
| JP2015121910A (en) * | 2013-12-24 | 2015-07-02 | 株式会社日立製作所 | Portable key device and device control method |
| US20160224779A1 (en) * | 2013-12-24 | 2016-08-04 | Hitachi, Ltd. | Portable key device and device control method |
| US20150220931A1 (en) * | 2014-01-31 | 2015-08-06 | Apple Inc. | Use of a Biometric Image for Authorization |
Also Published As
| Publication number | Publication date |
|---|---|
| CA3019168A1 (en) | 2017-10-19 |
| US20170300678A1 (en) | 2017-10-19 |
| DE112017002032T5 (en) | 2019-01-24 |
| GB201815538D0 (en) | 2018-11-07 |
| GB2564595A (en) | 2019-01-16 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US20170300678A1 (en) | Method and apparatus for using a biometric template to control access to a user credential for a shared wireless communication device | |
| US9882726B2 (en) | Method and apparatus for initial certificate enrollment in a wireless communication system | |
| US10367817B2 (en) | Systems and methods for challengeless coauthentication | |
| US9451454B2 (en) | Mobile device identification for secure device access | |
| AU2006298507B2 (en) | Method and arrangement for secure autentication | |
| CN105516103B (en) | Method, device and system for binding smart home appliances | |
| EP2879421B1 (en) | Terminal identity verification and service authentication method, system, and terminal | |
| US11271922B2 (en) | Method for authenticating a user and corresponding device, first and second servers and system | |
| US12490092B2 (en) | WPA3-personal cloud based network access and provisioning | |
| WO2019191213A1 (en) | Digital credential authentication | |
| JP2019508763A (en) | Local device authentication | |
| JP2005512396A (en) | Use of public key pairs at terminals to authenticate and authorize telecommunications subscribers to network providers and business partners | |
| CN112020716A (en) | Remote Biometrics | |
| CN113569210A (en) | Distributed identity authentication method, device access method and device | |
| WO2018207174A1 (en) | Method and system for sharing a network enabled entity | |
| US11665162B2 (en) | Method for authenticating a user with an authentication server | |
| JP2017139026A (en) | Method and apparatus for reliable authentication and logon | |
| WO2020263938A1 (en) | Document signing system for mobile devices | |
| JP2015111440A (en) | Method and apparatus for trusted authentication and log-on | |
| US11849326B2 (en) | Authentication of a user of a software application | |
| CN121312170A (en) | Silent two-factor authentication based on application authentication and key management (AKMA) |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| ENP | Entry into the national phase |
Ref document number: 201815538 Country of ref document: GB Kind code of ref document: A Free format text: PCT FILING DATE = 20170405 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 1815538.2 Country of ref document: GB |
|
| ENP | Entry into the national phase |
Ref document number: 3019168 Country of ref document: CA |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17718274 Country of ref document: EP Kind code of ref document: A1 |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 17718274 Country of ref document: EP Kind code of ref document: A1 |