Claims
- 1. An method of authenticating identity of a user of a client on a computer network including:
extracting a biometric template from the user; bundling the extracted biometric template with a supplied user credential and predetermined session code; providing the extracted biometric template, supplied user credential and predetermined session code to an authentication server; comparing the extracted biometric template, supplied user credential and predetermined session code with, respectively, a registered biometric template, a registered user credential and a session code stored in the authentication server.
- 2. The method of claim 1 further including:
generating a new session code in the authentication server, the new session code different from the predetermined session code; and forwarding the new session code to the client to be used during a subsequent transaction.
- 3. The method of claim 2 further including storing a copy of the new session code in the authorization server.
- 4. The method of claim 3 further including providing a positive authentication response to a service requesting user authentication on the condition that the extracted biometric template match the registered biometric template, the supplied user credential match the registered user credential and the predetermined session code match the session code stored in the authentication server.
- 5. The method of claim 4 wherein extracting the extracted biometric template includes:
providing a biometric input device connected to the client; inputting biometric information from the user into the biometric input device.
- 6. The method of claim 5 wherein bundling the extracted biometric template with the supplied user credential and predetermined session code is completed by the client.
- 7. The method of claim 6 wherein bundling the extracted biometric template with the supplied user credential includes bundling the extracted biometric template with a user ID, password or token.
- 8. The method of claim 7 wherein inputting biometric information from the user includes inputting user fingerprint information.
- 9. A system for authenticating a user on a computer network including:
a service provider for providing a service to clients on the computer network; a client for providing authentication information prior to receiving services from the service provider, the authentication information including at least a supplied user credential associated with the user of the client, a predetermined session code and an extracted biometric template representing biometric information associated with the user of the client; and an authentication server for verifying the identity of the user by analyzing the supplied user ID, the predetermined session code and the extracted biometric template.
- 10. The system of claim 9 wherein the predetermined session code is generated by the authentication server and provided to the client to the used during an authentication transaction.
- 11. The system of claim 10 wherein;
the supplied user credential is entered into the client by the user; the predetermined session code is provided by the client to the authentication server; the extracted biometric template is generated from biometric information entered by the user into the client computer; and the supplied user credential, the predetermined session code and the extracted biometric template are each forwarded to the authentication server from the client.
- 12. The system of claim 11 further including at least a registered user credential, a session code stored in the authentication server and a registered biometric template each stored in the authentication server and each associated with the user of the client wherein the authentication server will compare the supplied user credential with the registered user credential, predetermined session code with the session code stored in the authentication server and the extracted biometric template with the registered biometric template.
- 13. The system of claim 12 further including a fingerprint input device connected with the client and wherein the extracted biometric template and the registered biometric template are each fingerprint templates.
RELATED APPLICATIONS
[0001] The present application claims priority to U.S. Provisional Patent Application No.
[0002]60/288,207, filed May 2, 2001, entitled “Authentication Server Using Multiple Metrics for Identity Verification” by Eric Pu, Dong Won Lee, Rick Sadler, and William Tong, and incorporate that provisional application by reference.
Provisional Applications (1)
|
Number |
Date |
Country |
|
60288207 |
May 2001 |
US |