MLchartDataset catalogue

Patent · US2009183008A1 · A1 · US

Identity authentication and secured access systems, components, and methods

(11) Publication number
US2009183008A1
(21) Application number
12/172,654
(22) Filing date
2008-07-14
(30) Priority date
2007-07-12
(43) Publication date
2009-07-16
(51) IPC
G06K 5/00; H04K 1/00; H04L 9/32; G06F 21/00; H04L 29/06
(52) CPC
  • H04L Transmission of digital information, e.g. telegraphic communication: 9/0866, 2209/56, 2209/80, 2463/082, 63/0853, 63/0861, 9/3231, 9/3234
  • G06F Electric digital data processing: 21/32, 21/34, 21/62, 2221/2107
  • H04W Wireless communication networks: 12/068
(72) Inventors
Brian C. Jobmann
(54) Title
Identity authentication and secured access systems, components, and methods
(57) Abstract

Security tokens contain data that is each uniquely encrypted based on a unique biometric identifier of an authorized user of that token. Decoders receive the token and the user's biometric identifier, convert the biometric identifier to a biometric key, and apply the biometric key to decrypt the token. In this way, the decoders authenticate the users without performing a biometric identifier comparison. In some embodiments pieces or sets of the data are stored in designated data compartments, which are individually encrypted based on authority keys, and all of the encrypted data compartments are collectively encrypted based on the biometric key to create the token. The decoders store only the authority keys corresponding to the data compartments which they have authorization to open. In addition, in some embodiments the token and the biometric identifier are encrypted and sent to a remote authentication server for decryption of the token.

Full text
View on Google Patents

Claims (40)

  1. An identity authentication system for one or more users, the system comprising: at least one credential issued to one of the users, wherein the credential includes a security token comprising data encrypted by encryption software with a cryptographic algorithm and encrypted based on a biometric key that is generated from a biometric identifier of the user; and at least one decoder including a token interface device and a biometric input device and having access to decryption software with the cryptographic algorithm and conversion software, wherein the biometric input device receives the biometric identifier from the user, the conversion software converts the biometric identifier to the biometric key, the token interface device receives the token from the user credential, and the decryption software applies the cryptographic algorithm and the biometric key to the token to decrypt and thereby open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.
  2. The system of claim 1, wherein the token includes at least one data compartment storing the data, wherein the data compartment is encrypted by the same or different encryption software and encrypted based on at least one authority key.
  3. The system of claim 2, wherein the decoder has access to the at least one authority key, wherein after opening the token the decoder applies the decryption software and the at least one authority key to open the data compartment.
  4. The system of claim 2, wherein the token encryption and the data compartment encryption are based on at least two biometric keys generated from the same or a different biometric identifier of the user.
  5. The system of claim 4, wherein the decoder generates the at least two biometric keys from the same or the different biometric identifier, wherein the decoder has access to the at least one authority key, wherein after opening the token with a first one of the biometric keys the decoder applies the decryption software, the at least one authority key, and a second one of the biometric keys to open the data compartment.
  6. The system of claim 1, wherein the token includes a plurality of data compartments each able to store one piece or set of the data and each encrypted by the same or different encryption software and encrypted based on at least one of a plurality of authority keys, and wherein the authority-key encrypted data compartments are collectively encrypted based on the biometric key to form the token.
  7. The system of claim 6, wherein the decoder has access to at least one of the authority keys, wherein after opening the token the decoder applies the same or different decryption software and its at least one authority key to open the data compartment corresponding to its at least one authority key, and wherein the decoder cannot open any of the data compartments for which it does not have access to the corresponding authority key.
  8. The system of claim 1, further comprising a set-up workstation including at least one biometric input device, at least one token interface device, conversion software, and encryption software with the cryptographic algorithm, wherein the biometric input device receives the biometric identifier from the user, the conversion software converts the biometric identifier to the biometric key, the encryption software applies the cryptographic algorithm and the biometric key to encrypt the data to form the token, and the token interface device transfers the token to the credential.
  9. The system of claim 8, wherein the set-up workstation has access to at least one authority key, encrypts at least a portion of the data in a data compartment based on the authority key, and then encrypts the data compartment based on the biometric key.
  10. The system of claim 1, wherein the credential is a digital wallet credential and the token includes bank card information.
  11. The system of claim 1, wherein the credential is an insurance card credential and the token includes insurance information.
  12. The system of claim 1, wherein the credential is a medical passport credential and the token includes medical services information.
  13. The system of claim 1, wherein the credential is a government-issued identification credential and the token includes user identification information.
  14. The system of claim 1, wherein the credential is a perimeter access credential and, upon the decoder authenticating the token, the user is permitted entrance into a secured-perimeter area.
  15. The system of claim 1, wherein the credential is an ATI worker credential, the decoder is operably connected to ATI systems, and, upon the decoder authenticating the token, the user is permitted entrance into a secured-perimeter area of an airport.
  16. The system of claim 1, wherein the credential is an ATI passenger credential, the token is encrypted based on a public biometric key generated based on the user's biometric identifier and decryptable by a private biometric key generated based on the user's biometric identifier, and, upon the decoder authenticating the token, the user is permitted entrance into a secured-perimeter area of an airport.
  17. The system of claim 1, wherein the credential is an ATI baggage credential, the token is created at an ATI check-in device at an airport, and the credential is attached to baggage that the user checks at the airport.
  18. A set-up workstation for creating a security credential for a user, comprising: at least one biometric input device; at least one token interface device; conversion software that is operable to convert biometric identifiers to biometric keys; and encryption software with a cryptographic algorithm, wherein the biometric input device receives a biometric identifier from a user, the conversion software converts the biometric identifier to a biometric key, the encryption software applies the cryptographic algorithm and the biometric key to encrypt data to form a token, and the token interface device transfers the token to the credential.
  19. The workstation of claim 18, wherein the workstation has access to at least one authority key and the encryption software applies the cryptographic algorithm and the authority key to encrypts at least a portion of the data in a data compartment and then applies the cryptographic algorithm and the biometric key to encrypt the authority key-encrypted data compartment.
  20. A method of creating a security credential for a user, comprising: receiving a biometric identifier from the user; converting the biometric identifier to a biometric key; encrypting data based on the biometric key to form a token; and transferring the token to the credential.
  21. The method of claim 20, further comprising: accessing at least one authority key; and encrypting at least a portion of the data in a data compartment based on the authority key before encrypting the data based on the biometric key.
  22. A decoder for opening a security token of a credential of a user; comprising: a token interface device; a biometric input device; decryption software with a cryptographic algorithm; and conversion software that is operable to convert biometric identifiers to biometric keys, wherein the biometric input device receives a biometric identifier from the user, the conversion software converts the biometric identifier to a biometric key, the token interface device receives the token from the user credential, and the decryption software applies the cryptographic algorithm and the biometric key to the token to decrypt and thereby open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.
  23. The decoder of claim 22, wherein the token includes at least one data compartment storing the data, the data compartment is encrypted by the same or different encryption software and encrypted based on at least one authority key, and the decoder has access to the at least one authority key, wherein after opening the token the decoder applies the decryption software and the at least one authority key to open the data compartment.
  24. The decoder of claim 23, wherein the token encryption and the data compartment encryption are based on at least two biometric keys generated from the same or a different biometric identifier of the user, and the decoder generates the at least two biometric keys from the same or the different biometric identifier, wherein the decoder has access to the at least one authority key, wherein after opening the token with a first one of the biometric keys the decoder applies the decryption software, the at least one authority key, and a second one of the biometric keys to open the data compartment.
  25. The decoder of claim 22, wherein the token includes a plurality of data compartments each able to store one piece or set of the data and each encrypted by the same or different encryption software and encrypted based on at least one of a plurality of authority keys, and wherein the authority-key encrypted data compartments are collectively encrypted based on the biometric key to form the token.
  26. The decoder of claim 22, wherein the decoder has access to at least one of the authority keys, wherein after opening the token the decoder applies the same or different decryption software and its at least one authority key to open the data compartment corresponding to its at least one authority key, and wherein the decoder cannot open any of the data compartments for which it does not have access to the corresponding authority key.
  27. A method of authenticating the identity of a user with a security token comprising data encrypted based on a biometric key that is based on a biometric identifier of the user, the method comprising: receiving the biometric identifier from the user; converting the biometric identifier to a biometric key; receiving the token from the user credential; decrypting the token using the biometric key open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.
  28. The method of claim 27, wherein the token includes at least one data compartment storing the data and encrypted based on at least one authority key, and further comprising: accessing the at least one authority key; decrypting the data compartment using the at least one authority key after decrypting the token using the biometric key.
  29. The method of claim 28, wherein the step of decrypting the data compartment includes decrypting the data compartment using the at least one authority key and using a second biometric key generated from the same or a different biometric identifier of the user.
  30. The method of claim 27, wherein the token includes a plurality of data compartments each storing a portion of the data and each encrypted based on at least one of a plurality of authority keys, and further comprising: accessing the authority keys; decrypting the data compartments using the authority keys after decrypting the token using the biometric key.
  31. An identity authentication system for one or more users, the system comprising: at least one credential issued to one of the users, wherein the credential includes a security token comprising data encrypted by encryption software with a cryptographic algorithm and encrypted based on a biometric key that is generated from a biometric identifier of the user; and at least one decoder including a token interface device, a biometric input device, and a network interface device, and having access to encryption software with the cryptographic algorithm, wherein the biometric input device receives the biometric identifier from the user, the token interface device receives the token from the user credential, the network interface device requests and receives a OTK, the encryption software applies the cryptographic algorithm and the OTK to encrypt the token and the biometric key into a package, and the network interface device transmits the encrypted package; and an authentication server including a network interface device, OTK generation software, conversion software, and decryption software with the cryptographic algorithm, wherein the network interface device receives the OTK request, the OTK generation software generates the OTK, the network interface device sends the OTK to the decoder and receives the encrypted package from the decoder, the conversion software converts the biometric identifier to the biometric key, and the decryption software applies the cryptographic algorithm and the biometric key to the token to decrypt and thereby open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.
  32. The system of claim 31, wherein the token includes at least one data compartment storing the data, the data compartment is encrypted by the same or different encryption software and encrypted based on at least one authority key, and the authentication server has access to the at least one authority key, wherein after opening the token the authentication server applies the decryption software and the at least one authority key to open the data compartment.
  33. The system of claim 32, wherein the token encryption and the data compartment encryption are based on at least two biometric keys generated from the same or a different biometric identifier of the user, the authentication server generates the at least two biometric keys from the same or the different biometric identifier, and the authentication server has access to the at least one authority key, wherein after opening the token with a first one of the biometric keys the authentication server applies the decryption software, the at least one authority key, and a second one of the biometric keys to open the data compartment.
  34. The system of claim 31, wherein the token includes a plurality of data compartments each able to store one piece or set of the data and each encrypted by the same or different encryption software and encrypted based on at least one of a plurality of authority keys, the authority-key encrypted data compartments are collectively encrypted based on the biometric key to form the token, and the authentication server has access to at least one of the authority keys, wherein after opening the token the authentication server applies the same or different decryption software and its at least one authority key to open the data compartment corresponding to its at least one authority key, and wherein the authentication server cannot open any of the data compartments for which it does not have access to the corresponding authority key.
  35. The system of claim 31, wherein the credential is a gaming credential and the token includes user identification and bank card information.
  36. The system of claim 31, wherein the credential is a network access credential and the token includes user identification information.
  37. An authentication server for opening a security token of a credential of a user, the system comprising: a network interface device; generation software that is operable to generate a OTK; conversion software that is operable to convert biometric identifiers to biometric keys; and decryption software with a cryptographic algorithm, wherein the OTK generation software generates a OTK, the network interface device sends the OTK to a decoder and receives an encrypted package from the decoder, the conversion software converts the biometric identifier to the biometric key, and the decryption software applies the cryptographic algorithm and the biometric key to the token to decrypt and thereby open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.
  38. The decoder of claim 37, wherein the token includes at least one data compartment storing the data, the data compartment is encrypted by the same or different encryption software and encrypted based on at least one authority key, and the authentication server has access to the at least one authority key, wherein after opening the token the authentication server applies the decryption software and the at least one authority key to open the data compartment.
  39. A method of authenticating the identity of a user with a security token comprising data encrypted based on a biometric key that is based on a biometric identifier of the user, the method comprising: receiving from a decoder a request for a OTK; generating the OTK and sending it to the decoder; receiving from the decoder a package that includes the token and the biometric key and that is encrypted based on the OTK; decrypting the encrypted package using the OTK to access the token and the biometric identifier; converting the biometric identifier to the biometric key; and decrypting the token using the biometric key to open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.
  40. The method of claim 39, wherein the token includes at least one data compartment storing the data and encrypted based on at least one authority key, and further comprising: accessing the at least one authority key; decrypting the data compartment using the at least one authority key after decrypting the token using the biometric key.

Description

The present invention relates generally to identity authentication systems and, in particular, to systems and methods for authenticating a user's identity and permitting an authenticated user to access to secured information and/or areas.

Currently there is an enormous problem with identity theft. Most people think of identity theft in the sense of financial identity theft, for example, stealing a credit card account number and/or social security number to make unauthorized purchases. While this is a significant portion of all identity theft incidents, there are many other types of identity theft including medical, insurance, perimeter, and network (or computer/electronic) identity theft. Medical and insurance identity thefts involve accessing one's medical and insurance information, respectively, which can be misused in unauthorized hands. Perimeter identity theft involves the theft of a personal identity in order to gain access to a restricted area - a particularly important issue for airports, nuclear power plants, municipal water supply facilities, etc. And network identity theft relates to the theft of a user identity in order to gain unauthorized access to a computer system such as a military or corporate computer network.

The technology currently available for identity security suffers from the significant problem of a lack of identity authentication. The U.S. government uses the term “strong authentication” as a rating of the robustness of the security of an identity authentication system.

Citations (22)

  • US20070024551A1
  • US20020124176A1
  • US6484259B1
  • US20020178370A1
  • US20030208684A1
  • US7844579B2
  • US7076062B1
  • US20070168290A1
  • US20030070101A1
  • US20030204732A1
  • US7200756B2
  • US20050081044A1
  • US7610616B2
  • US20060219776A1
  • US20070180261A1
  • US20070005511A1
  • US20070043594A1
  • US20070040017A1
  • US20070067642A1
  • US20070079136A1
  • US20070124597A1
  • US20070131759A1
Record as JSON
{
  "publication_number": "US2009183008A1",
  "country": "US",
  "kind": "A1",
  "title": "Identity authentication and secured access systems, components, and methods",
  "abstract": "Security tokens contain data that is each uniquely encrypted based on a unique biometric identifier of an authorized user of that token. Decoders receive the token and the user's biometric identifier, convert the biometric identifier to a biometric key, and apply the biometric key to decrypt the token. In this way, the decoders authenticate the users without performing a biometric identifier comparison. In some embodiments pieces or sets of the data are stored in designated data compartments, which are individually encrypted based on authority keys, and all of the encrypted data compartments are collectively encrypted based on the biometric key to create the token. The decoders store only the authority keys corresponding to the data compartments which they have authorization to open. In addition, in some embodiments the token and the biometric identifier are encrypted and sent to a remote authentication server for decryption of the token.",
  "claims": [
    "1. An identity authentication system for one or more users, the system comprising: at least one credential issued to one of the users, wherein the credential includes a security token comprising data encrypted by encryption software with a cryptographic algorithm and encrypted based on a biometric key that is generated from a biometric identifier of the user; and at least one decoder including a token interface device and a biometric input device and having access to decryption software with the cryptographic algorithm and conversion software, wherein the biometric input device receives the biometric identifier from the user, the conversion software converts the biometric identifier to the biometric key, the token interface device receives the token from the user credential, and the decryption software applies the cryptographic algorithm and the biometric key to the token to decrypt and thereby open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.",
    "2. The system of claim 1, wherein the token includes at least one data compartment storing the data, wherein the data compartment is encrypted by the same or different encryption software and encrypted based on at least one authority key.",
    "3. The system of claim 2, wherein the decoder has access to the at least one authority key, wherein after opening the token the decoder applies the decryption software and the at least one authority key to open the data compartment.",
    "4. The system of claim 2, wherein the token encryption and the data compartment encryption are based on at least two biometric keys generated from the same or a different biometric identifier of the user.",
    "5. The system of claim 4, wherein the decoder generates the at least two biometric keys from the same or the different biometric identifier, wherein the decoder has access to the at least one authority key, wherein after opening the token with a first one of the biometric keys the decoder applies the decryption software, the at least one authority key, and a second one of the biometric keys to open the data compartment.",
    "6. The system of claim 1, wherein the token includes a plurality of data compartments each able to store one piece or set of the data and each encrypted by the same or different encryption software and encrypted based on at least one of a plurality of authority keys, and wherein the authority-key encrypted data compartments are collectively encrypted based on the biometric key to form the token.",
    "7. The system of claim 6, wherein the decoder has access to at least one of the authority keys, wherein after opening the token the decoder applies the same or different decryption software and its at least one authority key to open the data compartment corresponding to its at least one authority key, and wherein the decoder cannot open any of the data compartments for which it does not have access to the corresponding authority key.",
    "8. The system of claim 1, further comprising a set-up workstation including at least one biometric input device, at least one token interface device, conversion software, and encryption software with the cryptographic algorithm, wherein the biometric input device receives the biometric identifier from the user, the conversion software converts the biometric identifier to the biometric key, the encryption software applies the cryptographic algorithm and the biometric key to encrypt the data to form the token, and the token interface device transfers the token to the credential.",
    "9. The system of claim 8, wherein the set-up workstation has access to at least one authority key, encrypts at least a portion of the data in a data compartment based on the authority key, and then encrypts the data compartment based on the biometric key.",
    "10. The system of claim 1, wherein the credential is a digital wallet credential and the token includes bank card information.",
    "11. The system of claim 1, wherein the credential is an insurance card credential and the token includes insurance information.",
    "12. The system of claim 1, wherein the credential is a medical passport credential and the token includes medical services information.",
    "13. The system of claim 1, wherein the credential is a government-issued identification credential and the token includes user identification information.",
    "14. The system of claim 1, wherein the credential is a perimeter access credential and, upon the decoder authenticating the token, the user is permitted entrance into a secured-perimeter area.",
    "15. The system of claim 1, wherein the credential is an ATI worker credential, the decoder is operably connected to ATI systems, and, upon the decoder authenticating the token, the user is permitted entrance into a secured-perimeter area of an airport.",
    "16. The system of claim 1, wherein the credential is an ATI passenger credential, the token is encrypted based on a public biometric key generated based on the user's biometric identifier and decryptable by a private biometric key generated based on the user's biometric identifier, and, upon the decoder authenticating the token, the user is permitted entrance into a secured-perimeter area of an airport.",
    "17. The system of claim 1, wherein the credential is an ATI baggage credential, the token is created at an ATI check-in device at an airport, and the credential is attached to baggage that the user checks at the airport.",
    "18. A set-up workstation for creating a security credential for a user, comprising: at least one biometric input device; at least one token interface device; conversion software that is operable to convert biometric identifiers to biometric keys; and encryption software with a cryptographic algorithm, wherein the biometric input device receives a biometric identifier from a user, the conversion software converts the biometric identifier to a biometric key, the encryption software applies the cryptographic algorithm and the biometric key to encrypt data to form a token, and the token interface device transfers the token to the credential.",
    "19. The workstation of claim 18, wherein the workstation has access to at least one authority key and the encryption software applies the cryptographic algorithm and the authority key to encrypts at least a portion of the data in a data compartment and then applies the cryptographic algorithm and the biometric key to encrypt the authority key-encrypted data compartment.",
    "20. A method of creating a security credential for a user, comprising: receiving a biometric identifier from the user; converting the biometric identifier to a biometric key; encrypting data based on the biometric key to form a token; and transferring the token to the credential.",
    "21. The method of claim 20, further comprising: accessing at least one authority key; and encrypting at least a portion of the data in a data compartment based on the authority key before encrypting the data based on the biometric key.",
    "22. A decoder for opening a security token of a credential of a user; comprising: a token interface device; a biometric input device; decryption software with a cryptographic algorithm; and conversion software that is operable to convert biometric identifiers to biometric keys, wherein the biometric input device receives a biometric identifier from the user, the conversion software converts the biometric identifier to a biometric key, the token interface device receives the token from the user credential, and the decryption software applies the cryptographic algorithm and the biometric key to the token to decrypt and thereby open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.",
    "23. The decoder of claim 22, wherein the token includes at least one data compartment storing the data, the data compartment is encrypted by the same or different encryption software and encrypted based on at least one authority key, and the decoder has access to the at least one authority key, wherein after opening the token the decoder applies the decryption software and the at least one authority key to open the data compartment.",
    "24. The decoder of claim 23, wherein the token encryption and the data compartment encryption are based on at least two biometric keys generated from the same or a different biometric identifier of the user, and the decoder generates the at least two biometric keys from the same or the different biometric identifier, wherein the decoder has access to the at least one authority key, wherein after opening the token with a first one of the biometric keys the decoder applies the decryption software, the at least one authority key, and a second one of the biometric keys to open the data compartment.",
    "25. The decoder of claim 22, wherein the token includes a plurality of data compartments each able to store one piece or set of the data and each encrypted by the same or different encryption software and encrypted based on at least one of a plurality of authority keys, and wherein the authority-key encrypted data compartments are collectively encrypted based on the biometric key to form the token.",
    "26. The decoder of claim 22, wherein the decoder has access to at least one of the authority keys, wherein after opening the token the decoder applies the same or different decryption software and its at least one authority key to open the data compartment corresponding to its at least one authority key, and wherein the decoder cannot open any of the data compartments for which it does not have access to the corresponding authority key.",
    "27. A method of authenticating the identity of a user with a security token comprising data encrypted based on a biometric key that is based on a biometric identifier of the user, the method comprising: receiving the biometric identifier from the user; converting the biometric identifier to a biometric key; receiving the token from the user credential; decrypting the token using the biometric key open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.",
    "28. The method of claim 27, wherein the token includes at least one data compartment storing the data and encrypted based on at least one authority key, and further comprising: accessing the at least one authority key; decrypting the data compartment using the at least one authority key after decrypting the token using the biometric key.",
    "29. The method of claim 28, wherein the step of decrypting the data compartment includes decrypting the data compartment using the at least one authority key and using a second biometric key generated from the same or a different biometric identifier of the user.",
    "30. The method of claim 27, wherein the token includes a plurality of data compartments each storing a portion of the data and each encrypted based on at least one of a plurality of authority keys, and further comprising: accessing the authority keys; decrypting the data compartments using the authority keys after decrypting the token using the biometric key.",
    "31. An identity authentication system for one or more users, the system comprising: at least one credential issued to one of the users, wherein the credential includes a security token comprising data encrypted by encryption software with a cryptographic algorithm and encrypted based on a biometric key that is generated from a biometric identifier of the user; and at least one decoder including a token interface device, a biometric input device, and a network interface device, and having access to encryption software with the cryptographic algorithm, wherein the biometric input device receives the biometric identifier from the user, the token interface device receives the token from the user credential, the network interface device requests and receives a OTK, the encryption software applies the cryptographic algorithm and the OTK to encrypt the token and the biometric key into a package, and the network interface device transmits the encrypted package; and an authentication server including a network interface device, OTK generation software, conversion software, and decryption software with the cryptographic algorithm, wherein the network interface device receives the OTK request, the OTK generation software generates the OTK, the network interface device sends the OTK to the decoder and receives the encrypted package from the decoder, the conversion software converts the biometric identifier to the biometric key, and the decryption software applies the cryptographic algorithm and the biometric key to the token to decrypt and thereby open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.",
    "32. The system of claim 31, wherein the token includes at least one data compartment storing the data, the data compartment is encrypted by the same or different encryption software and encrypted based on at least one authority key, and the authentication server has access to the at least one authority key, wherein after opening the token the authentication server applies the decryption software and the at least one authority key to open the data compartment.",
    "33. The system of claim 32, wherein the token encryption and the data compartment encryption are based on at least two biometric keys generated from the same or a different biometric identifier of the user, the authentication server generates the at least two biometric keys from the same or the different biometric identifier, and the authentication server has access to the at least one authority key, wherein after opening the token with a first one of the biometric keys the authentication server applies the decryption software, the at least one authority key, and a second one of the biometric keys to open the data compartment.",
    "34. The system of claim 31, wherein the token includes a plurality of data compartments each able to store one piece or set of the data and each encrypted by the same or different encryption software and encrypted based on at least one of a plurality of authority keys, the authority-key encrypted data compartments are collectively encrypted based on the biometric key to form the token, and the authentication server has access to at least one of the authority keys, wherein after opening the token the authentication server applies the same or different decryption software and its at least one authority key to open the data compartment corresponding to its at least one authority key, and wherein the authentication server cannot open any of the data compartments for which it does not have access to the corresponding authority key.",
    "35. The system of claim 31, wherein the credential is a gaming credential and the token includes user identification and bank card information.",
    "36. The system of claim 31, wherein the credential is a network access credential and the token includes user identification information.",
    "37. An authentication server for opening a security token of a credential of a user, the system comprising: a network interface device; generation software that is operable to generate a OTK; conversion software that is operable to convert biometric identifiers to biometric keys; and decryption software with a cryptographic algorithm, wherein the OTK generation software generates a OTK, the network interface device sends the OTK to a decoder and receives an encrypted package from the decoder, the conversion software converts the biometric identifier to the biometric key, and the decryption software applies the cryptographic algorithm and the biometric key to the token to decrypt and thereby open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.",
    "38. The decoder of claim 37, wherein the token includes at least one data compartment storing the data, the data compartment is encrypted by the same or different encryption software and encrypted based on at least one authority key, and the authentication server has access to the at least one authority key, wherein after opening the token the authentication server applies the decryption software and the at least one authority key to open the data compartment.",
    "39. A method of authenticating the identity of a user with a security token comprising data encrypted based on a biometric key that is based on a biometric identifier of the user, the method comprising: receiving from a decoder a request for a OTK; generating the OTK and sending it to the decoder; receiving from the decoder a package that includes the token and the biometric key and that is encrypted based on the OTK; decrypting the encrypted package using the OTK to access the token and the biometric identifier; converting the biometric identifier to the biometric key; and decrypting the token using the biometric key to open the token, wherein the token is only openable upon the user presenting the biometric identifier used to encrypt the token so that opening the token authenticates the user.",
    "40. The method of claim 39, wherein the token includes at least one data compartment storing the data and encrypted based on at least one authority key, and further comprising: accessing the at least one authority key; decrypting the data compartment using the at least one authority key after decrypting the token using the biometric key."
  ],
  "description_excerpt": "The present invention relates generally to identity authentication systems and, in particular, to systems and methods for authenticating a user's identity and permitting an authenticated user to access to secured information and/or areas.\n\nCurrently there is an enormous problem with identity theft. Most people think of identity theft in the sense of financial identity theft, for example, stealing a credit card account number and/or social security number to make unauthorized purchases. While this is a significant portion of all identity theft incidents, there are many other types of identity theft including medical, insurance, perimeter, and network (or computer/electronic) identity theft. Medical and insurance identity thefts involve accessing one's medical and insurance information, respectively, which can be misused in unauthorized hands. Perimeter identity theft involves the theft of a personal identity in order to gain access to a restricted area - a particularly important issue for airports, nuclear power plants, municipal water supply facilities, etc. And network identity theft relates to the theft of a user identity in order to gain unauthorized access to a computer system such as a military or corporate computer network.\n\nThe technology currently available for identity security suffers from the significant problem of a lack of identity authentication. The U.S. government uses the term “strong authentication” as a rating of the robustness of the security of an identity authentication system.",
  "cpc": [
    "H04L 9/0866",
    "G06F 21/32",
    "G06F 21/34",
    "G06F 21/62",
    "G06F 2221/2107",
    "H04L 2209/56",
    "H04L 2209/80",
    "H04L 2463/082",
    "H04L 63/0853",
    "H04L 63/0861",
    "H04L 9/3231",
    "H04L 9/3234",
    "H04W 12/068"
  ],
  "ipc": [
    "G06K 5/00",
    "H04K 1/00",
    "H04L 9/32",
    "G06F 21/00",
    "H04L 29/06"
  ],
  "inventors": [
    "Brian C. Jobmann"
  ],
  "filing_date": "2008-07-14",
  "publication_date": "2009-07-16",
  "priority_date": "2007-07-12",
  "application_number": "US-17265408-A",
  "family_id": "40229110",
  "cited_by_count": 153,
  "citations": [
    "US20070024551A1",
    "US20020124176A1",
    "US6484259B1",
    "US20020178370A1",
    "US20030208684A1",
    "US7844579B2",
    "US7076062B1",
    "US20070168290A1",
    "US20030070101A1",
    "US20030204732A1",
    "US7200756B2",
    "US20050081044A1",
    "US7610616B2",
    "US20060219776A1",
    "US20070180261A1",
    "US20070005511A1",
    "US20070043594A1",
    "US20070040017A1",
    "US20070067642A1",
    "US20070079136A1",
    "US20070124597A1",
    "US20070131759A1"
  ]
}

Record 5,541 of 8,000 in Patents full text (MLC-0201). Request the full dataset.