Claims
- 1. A method for generating a trusted communication channel with a client, the method comprising:
providing an agent module at the client; providing a task set including one or more tasks; determining one or more client components needed to complete each of the one or more tasks of the task set; and determining whether each of the needed one or more client components is trustworthy.
- 2. The method of claim 1 further comprising transmitting to the client an equivalent component for one of the one or more needed client components determined not to be trustworthy.
- 3. The method of claim 1 further comprising retrieving a candidate set of strong authentication data using at least one of the one or more needed client components determined to be trustworthy.
- 4. The method of claim 3 wherein the candidate set of strong authentication data is a candidate set of biometric data.
- 5. The method of claim 1 further comprising transmitting a candidate set of strong authentication data using at least one of the one or more needed client components determined to be trustworthy.
- 6. The method of claim 5 wherein the candidate set of strong authentication data is a candidate set of biometric data.
- 7. The method of claim 6 further comprising:
comparing the candidate set of biometric data with a reference set of biometric data to verify a user associated with the client; and if there is a sufficient match between the candidate set of biometric data and the reference set of biometric data, transmitting an application program for execution on the client.
- 8. The method of claim 6 further comprising comparing the candidate set of biometric data with a reference set of biometric data to authenticate a user associated with the client,
- 9. The method of claim 8 further comprising:
determining one or more additional client components needed to complete each task of the new task set; and determining whether each of the needed one or more additional client components is trustworthy.
- 10. The method of claim 8 wherein the new task set includes a task of retrieving user credentials for the authenticated user, the method further comprising:
retrieving the reference set of biometric data associated with an electronic vault associated with the authenticated user; and retrieving from the electronic vault the user credentials.
- 11. The method of claim 1 further comprising retrieving a reference set of biometric data from a template.
- 12. A client for generating a trusted communication channel, the client comprising:
a task set having one or more tasks; one or more client components needed to complete the one or more tasks of the task set, and an agent module configured to determine whether each of the one or more client components is trustworthy.
- 13. The client of claim 12 wherein the agent module is further configured to retrieve a candidate set of strong authentication data using those one or more client components that are determined to be trustworthy.
- 14. The client of claim 13 wherein the candidate set of strong authentication data is a candidate set of biometric data.
- 15. The client of claim 12 further comprising a transceiver module configured to transmit a candidate set of strong authentication data using those one or more client components that are determined to be trustworthy.
- 16. The client of claim 15 wherein the candidate set of strong authentication data is a candidate set of biometric data.
- 17. The client of claim 12 further comprising a transceiver module configured to receive a new task set, and
wherein the agent module is further configured to determine one or more additional client components needed to complete each task of the new task set and to determine whether each of the needed one or more additional client components is trustworthy.
- 18. The client of claim 12 further comprising:
one or more equivalent components needed to complete the one or more tasks or the task set; and a transceiver module configured to request and receive the one or more equivalent components in response to the agent module determining that at least on of the one or more client components are not trustworthy.
- 19. A system for generating a trusted communication channel, the system comprising:
a client having:
a task set having one or more tasks, one or more client components needed to complete the one or more tasks of the task set, and an agent module configured to determine whether each of the one or more client components is trustworthy; and a server in communication with the client, the server having:
a reference set of strong authentication data.
- 20. The server of claim 19 wherein the reference set of strong authentication data is a reference set of biometric data.
- 21. The system of claim 19 wherein the server further comprises:
one or more equivalent components needed to complete the one or more tasks or the task set; and a transceiver module configured to transmit the one or more equivalent components in response to the agent module determining that at least on of the one or more client components are not trustworthy.
- 22. The client of claim 19 wherein the agent module is further configured to retrieve a candidate set of strong authentication data using those one or more client components that are determined to be trustworthy.
- 23. The client of claim 22 wherein the candidate set of strong authentication data is a candidate set of biometric data.
- 24. The client of claim 19 further comprising a transceiver module configured to transmit a candidate set of strong authentication data using those one or more client components that are determined to be trustworthy.
- 25. The client of claim 24 wherein the candidate set of strong authentication data is a candidate set of biometric data.
- 26. The system of claim 20 wherein the server further comprises:
a comparator module to compare a candidate set of biometric data received from the client with the reference set of biometric data to verify a user associated with the client, and a transceiver module configured to allow transmission of an application program for execution on the client if there is a sufficient match between the candidate set of biometric data and the reference set of biometric data.
- 27. The system of claim 20 wherein the server further comprises:
a comparator module to compare a candidate set of biometric data received from the client with the reference set of biometric data to verify a user associated with the client; and a transceiver module configured to transmit a new task set to the client if there is a sufficient match between the candidate set of biometric data and the reference set of biometric data.
- 28. The system of claim 24 wherein the agent module is further configured to determine one or more additional client components needed to complete each task of the new task set and to determine whether each of the needed one or more additional client components is trustworthy.
- 29. The system of claim 19 wherein the server further comprises an electronic vault.
- 30. The system of claim 19 wherein the electronic vault further comprises one or more realms having one or more vaults having one or more folders.
- 31. An article of manufacture having computer-readable program portions embodied therein for generating a trusted communication channel with a client, the article comprising:
a computer-readable program portion for providing an agent module at the client; a computer-readable program portion for providing a task set, the task set including one or more tasks; a computer-readable program portion for determining one or more client components needed to complete each of the one or more tasks in the task set; and a computer-readable program portion for determining whether each of the one or more client components is trustworthy.
- 32. A method for provisioning a client computer, the method comprising:
establishing an identity of a client user based on strong authentication data; and based on the established user identity, remotely providing to the client computer a set of provisioning modules specific to the user for execution on the client computer, the execution of the provisioning modules causing transfer of information onto the client computer.
- 33. The method of claim 32 wherein the strong authentication data is biometric indicia.
- 34. The method of claim 32 wherein execution of the provisioning modules causes installation of at least one of application programs and user-specific data onto the client computer.
- 35. The method of claim 33 wherein the biometric indicia are obtained from the user by the client computer and transmitted to a server for identity establishment.
- 36. The method of claim 33 wherein the biometric indicia are obtained from the user by the client computer and are analyzed by the client computer for identity establishment.
- 37. A system for provisioning a client computer, the system comprising:
an authentication module establishing an identity of a client user based on strong authentication data; and a server for remotely providing to the client computer, based on the established user identity, a set of provisioning modules specific to the user for execution on the client computer, the execution of the provisioning modules causing transfer information onto the client computer.
- 38. The system of claim 37 wherein the strong authentication data is biometric indicia.
- 39. The system of claim 37 wherein execution of the provisioning modules causes installation of at least one of application programs and user-specific data onto the client computer.
- 40. The system of claim 38 wherein the client computer comprises a biometric input device for obtaining the indicia.
- 41. The system of claim 40 wherein the client computer comprises a communication module for transmitting the indicia to the server for identity establishment.
- 42. The system of claim 40 wherein the client computer comprises an analysis module for analyzing the indicia for identity establishment.
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims the benefit of and priority to the co-pending U.S. Provisional Application Serial No. 60/291,900, filed May 18, 2001, entitled “Network-Based Biometric Authentication,” the entirety of which is incorporated herein by reference.
Provisional Applications (1)
|
Number |
Date |
Country |
|
60291900 |
May 2001 |
US |