US2012137353A1PendingUtilityA1

Method and system for abstracted and randomized one-time use passwords for transactional authentication

Assignee: SMALES ANTONYPriority: Nov 30, 2010Filed: Nov 23, 2011Published: May 31, 2012
Est. expiryNov 30, 2030(~4.4 yrs left)· nominal 20-yr term from priority
Inventors:Antony Smales
G06F 21/36H04L 9/3226H04L 9/3271G06F 21/83H04L 63/0838G06F 21/31
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A security system and method for authenticating a user's access to a system is disclosed. The security system receives an authentication request from the user and responds by generating a security matrix based on a previously stored user keyword and user preference data, the security matrix being different for each authentication request. The security system sends the security matrix to the user and awaits a one-time code in response to the security matrix. The user forms the one-time code based on the user keyword, the user preferences, and the security matrix. The security system validates the one-time code against the security matrix, the keyword, and the user preferences, and responds by sending an authentication result to the user that either permits or denies access to the system. Additionally, the security system sends a success or fail message to the system to be accessed.

Claims

exact text as granted — not AI-modified
1 . A method for validating a user's authenticity to access a secure system, the method comprising:
 receiving an authentication request from the user;   generating a security matrix based on a user ID and user preference data and sending said matrix to the user;   receiving a one-time code from the user in response to the security matrix;   validating the one-time code based on the security matrix, the user ID, at least one user keyword, and user preference data;   after validating the one-time code, sending an authentication result to the user, said authentication result being based on the one-time code, the security matrix, the user ID, the user keyword, and user preferences; and   sending a success or fail message, distinct from the authentication result, to the secure system based on the authentication result.   
     
     
         2 . The method of  claim 1 , wherein the user keyword is stored in encrypted form. 
     
     
         3 . The method of  claim 1 , generating a security matrix based on a user ID and user preference data includes generating a randomly arranged security matrix as specified by the user preference data. 
     
     
         4 . The method of  claim 1 , generating a security matrix based on a user ID and user preference data includes generating an alphabetically arranged security matrix as specified by the user preference data. 
     
     
         5 . The method of  claim 1 ,
 wherein the authentication request includes a system ID; and   wherein the matrix generation is based on the user preference data, the user ID, and the system ID.   
     
     
         6 . The method of  claim 1 , wherein the step of generating a security matrix based on the user ID and user preference data includes constructing a custom representation of the security matrix. 
     
     
         7 . The method of  claim 1 ,
 wherein the system has system preference data; and   wherein the step of generating a security matrix is based on the user ID, user preference data, and system preference data.   
     
     
         8 . The method of  claim 1 , wherein the step of generating a security matrix includes generating a matrix that is different from any previously generated matrix. 
     
     
         9 . The method of  claim 1 , wherein the authentication result includes a session ID to be used by the secure system. 
     
     
         10 . The method of  claim 1 , wherein the step of receiving the one-time code includes receiving the user ID, and system ID. 
     
     
         11 . The method of  claim 1 ,
 wherein the user keyword consists of a plurality of characters; and   wherein the security matrix maps each character of the keyword to a corresponding number.   
     
     
         12 . The method of  claim 11 , wherein the user-preference data includes an indication to form the one-time code by modifying with an offset each number to which a character of the user keyword is mapped. 
     
     
         13 . The method of  claim 11 , wherein the user-preference data includes an indication to form the one-time code by modifying with a crawl each number to which a character of the user keyword is mapped. 
     
     
         14 . The method of  claim 11 , wherein the user-preference data includes an indication to form the one-time code by modifying with a jump each number to which a character of the user keyword is mapped. 
     
     
         15 . The method of  claim 11 , wherein the user-preference data includes an indication to form the one-time code by modifying with a mask each number to which a character of the user keyword is mapped. 
     
     
         16 . The method of  claim 11 , wherein the user-preference data includes an indication to form the one-time code by modifying with a user-chosen letter each number to which a character of the user keyword is mapped. 
     
     
         17 . The method of  claim 11 , wherein the user-preference data includes an indication to form the one-time code by modifying with a user-chosen word having a size equal to the keyword each number to which a character of the user keyword is mapped. 
     
     
         18 . The method of  claim 1 ,
 wherein the step of receiving a one-time code from the user in response to the security matrix includes generating the one-time code based on an alternative keyword;   wherein validating the one-time code includes validating the one-time code based on the alternative keyword; and   wherein sending the success or fail message includes a panic indication to the secure system such that the secure system protects the user.   
     
     
         19 . A security system for validating a user's authenticity to access a secure system, the security system comprising:
 a security computer that is programmed
 to store a user keyword and user preference data, 
 to receive an authentication request including a user ID from the user to access the secure system and to generate a security matrix in response to said authentication request based on stored user preference data and the user ID, 
 to send the security matrix to the user and to receive from the user a one-time code, 
 to validate the one-time code using the generated security matrix, the user keyword, and user preference data, and to send an authentication result based on the validation to the user, and 
 to send a success or fail message, distinct from the authentication result, to the secure system based on the authentication result; and 
   a client interface that enables the user to transmit to the security system an authentication request to access the secure system, receives and displays the security matrix, and enables the user to send the one-time code to the security system.   
     
     
         20 . The security system of  claim 17 , wherein the security system receives the authentication request via the secure system. 
     
     
         21 . The security system of  claim 17 , wherein the security system sends the security matrix to the user via the secure system. 
     
     
         22 . The security system of  claim 17 ,
 wherein the security system sends the security matrix to the secure system; and   wherein the secure system generates a custom representation of the security matrix and sends it to the user.   
     
     
         23 . The security system of  claim 17 , wherein the security system receives the one-time code via the secure system 
     
     
         24 . The security system of  claim 17 , wherein the security system sends the authentication result via the secure system. 
     
     
         25 . The security system of  claim 17 , wherein the client interface is a browser that runs on a client computer system. 
     
     
         26 . The security system of  claim 17 , wherein the client interface is an ATM machine. 
     
     
         27 . The security system of  claim 17 , wherein the client interface is a point of sale terminal. 
     
     
         28 . The security system of  claim 17 , wherein the client interface is a browser of a computer system operated by a customer representative of the system for which access is requested.

Join the waitlist — get patent alerts

Track US2012137353A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.