US2010122327A1PendingUtilityA1

Secure authentication for accessing remote resources

Assignee: APPLE INCPriority: Nov 10, 2008Filed: Nov 10, 2008Published: May 13, 2010
Est. expiryNov 10, 2028(~2.3 yrs left)· nominal 20-yr term from priority
H04L 63/08H04L 63/18H04L 63/168
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, systems, and apparatus, including computer program products, for secure authentication for accessing remote resources are disclosed. In some implementations, a user is authenticated for a first time on an interface using a first communications channel; the user is authenticated a second time on the interface using a second communications channel; access privileges are determined based on authenticating the user for the second time; and a random Uniform Resource Locator (URL) is generated based on the access privileges, where the random URL is single-use and indirectly associated with a requested resource.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 receiving a first authentication factor from an interface using a first communications channel;   determining access privileges based on the first authentication factor;   generating a first random Uniform Resource Locator (URL) and a first resource based on the access privileges, the first resource being identified by the first random URL and configured to receive a second authentication factor, and the first random URL being single-use;   providing the first resource to the interface using the first communications channel; and   providing the second authentication factor to the interface using a second communications channel.   
   
   
       2 . The method of  claim 1 , further comprising:
 receiving the second authentication factor from the interface using the first resource; and   determining access privileges based on the second authentication factor received from the interface.   
   
   
       3 . The method of  claim 2 , further comprising:
 generating a second random URL, the second random URL being single-use and indirectly associated with a second resource;   providing the second random URL to the interface;   receiving a request from the interface to access the second resource;   determining an actual location of the second resource using the second random URL; and   providing the interface access to the second resource.   
   
   
       4 . The method of  claim 3 , wherein determining the actual location includes:
 mapping the second random URL to a third URL, the third URL directly identifying the location of the second resource.   
   
   
       5 . The method of  claim 3 , wherein determining the actual location includes:
 mapping the second random URL to a function, the function being operable to provide the interface direct access to the second resource.   
   
   
       6 . The method of  claim 1 , wherein the first resource is a web page. 
   
   
       7 . The method of  claim 1 , wherein the second communications channel uses a Short Message Service (SMS) protocol. 
   
   
       8 . The method of  claim 1 , wherein the second resource is video and providing the interface access to the second resource includes streaming the video to the interface. 
   
   
       9 . A method comprising:
 receiving a first authentication factor from an interface using a first communications channel;   determining access privileges based on the first authentication factor;   receiving a request from the interface to access a resource;   generating a first random Uniform Resource Locator (URL) based on the access privileges, the first random URL being single-use and indirectly associated with the resource; and   providing the first random URL to the interface using a second communications channel.   
   
   
       10 . The method of  claim 9 , further comprising:
 determining an actual location of the resource using the first random URL; and   providing the interface access to the resource.   
   
   
       11 . The method of  claim 10 , wherein determining the actual location includes:
 mapping the first random URL to a second URL, the second URL directly identifying the location of the resource.   
   
   
       12 . The method of  claim 10 , wherein determining the actual location includes:
 mapping the first random URL to a function, the function being operable to provide the interface direct access to the resource.   
   
   
       13 . The method of  claim 9 , wherein the second communications channel uses a Short Message Service (SMS) protocol. 
   
   
       14 . A method comprising:
 receiving a first authentication factor from an interface using a first communications channel;   determining access privileges based on the first authentication factor;   providing a challenge to the interface using a second communications channel, based on the access privileges;   receiving a response from the interface using the second communications channel;   determining access privileges based on the response;   generating a first random Uniform Resource Locator (URL) based on the access privileges, the first random URL being single-use and indirectly associated with a resource; and   providing the first random URL to the interface.   
   
   
       15 . The method of  claim 14 , further comprising:
 receiving a request from the interface to access the resource;   determining an actual location of the resource using the first random URL; and   providing the interface access to the resource.   
   
   
       16 . The method of  claim 15 , wherein determining the actual location includes:
 mapping the first random URL to a second URL, the second URL directly identifying the location of the resource.   
   
   
       17 . The method of  claim 15 , wherein determining the actual location includes:
 mapping the first random URL to a function, the function being operable to provide the interface direct access to the second resource.   
   
   
       18 . A method comprising:
 transmitting a first authentication factor from an interface using a first communications channel;   receiving a first random Uniform Resource Locator (URL) using the first communications channel, the first random URL being single-use;   presenting a first resource in the interface, the first resource being identified by the first random URL and configured to receive a second authentication factor; and   receiving a second authentication factor through a second communications channel, the second authentication factor being presented in the interface.   
   
   
       19 . The method of  claim 18 , wherein the second authentication factor appears in a semi-transparent object in the interface. 
   
   
       20 . The method of  claim 18 , wherein the second authentication factor is automatically provided to the first resource in the interface. 
   
   
       21 . A method comprising:
 authenticating a user for a first time on an interface using a first communications channel;   authenticating the user for a second time on the interface using a second communications channel;   determining access privileges based on authenticating the user for the second time; and   generating a random Uniform Resource Locator (URL) based on the access privileges, the random URL being single-use and indirectly associated with a requested resource.   
   
   
       22 . A system comprising:
 a processor; and   a computer-readable medium coupled to the processor and having instructions contained thereon, which, when executed by the processor causes the processor to perform the operations of:
 authenticating a user for a first time on an interface using a first communications channel; 
 authenticating the user for a second time on the interface using a second communications channel; 
 determining access privileges based on authenticating the user for the second time; and 
 generating a random Uniform Resource Locator (URL) based on the access privileges, the random URL being single-use and indirectly associated with a requested resource. 
   
   
   
       23 . A computer program product, encoded on a computer-readable medium, operable to cause a data processing apparatus to:
 authenticate a user for a first time on an interface using a first communications channel;   authenticate the user for a second time on the interface using a second communications channel;   determine access privileges based on authenticating the user for the second time; and   generate a random Uniform Resource Locator (URL) based on the access privileges, the random URL being single-use and indirectly associated with a requested resource.

Join the waitlist — get patent alerts

Track US2010122327A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.