US2016241549A1PendingUtilityA1
Method and apparatus for the secure authentication of a web site
Est. expiryFeb 25, 2019(expired)· nominal 20-yr term from priority
Inventors:Isaac J. Labaton
G10L 15/02H04L 63/0838G06Q 20/401H04L 63/0823H04L 63/0428G06Q 20/10G06Q 20/3674H04L 2463/102
48
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Methods for the authentication of a web site by a visitor to the web site. The visitor uses a device, such as a portable device like a cell phone to compute a dynamic identification string and a one-time password. The dynamic identification string is sent to a service provider, such as a certification service server associated with the web site. In response, the server computes a one-time password that is transmitted to the visitor's device. The device computed one-time password can then be compared to the server computed one-time password in order to authenticate the web site.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for authenticating a web site to a user of a system having an authentication module and a transceiver module, the method comprising:
(a) with the authentication module:
(i) computing a one-time code,
(ii) computing a first one-time password having a predetermined relationship to the one-time code, and
(iii) outputing the one-time code but not the first one-time password; and
(b) with the transceiver module:
(i) sending the one-time code via a global telecommunications network for receipt by a certification server computer associated with the web site, which certification server computer is programmed to use the one-time code: (A) to authenticate the user, and (B) to compute a second one-time password in the predetermined relationship to the one-time code, and
(ii) in response to part (b)(i), receiving the second one-time password, which indicates authentication of the web site if the second one-time password matches the first one-time password.
2 . The method of claim 1 wherein the authentication module is a separate device not in electronic communication with the transceiver module.
3 . The method of claim 1 wherein outputting the one-time code in part (a)(iii) includes transmitting the one-time code to the transceiver module via an audible signal.
4 . The method of claim 1 further comprising displaying, on a display of the authentication module, the first one-time password computed in part (a)(ii).
5 . The method of claim 1 wherein the authentication module is not connected to the global telecommunications network.
6 . The method of claim 5 wherein computing the one-time code in part (a)(i) includes applying a first function to a first indicia stored by the authentication module, which first indicia is derived from a first seed provided by an arbitration entity in control of the certification server computer, and wherein the web site is controlled by an entity other than the arbitration entity.
7 . The method of claim 6 wherein computing the one-time code in part (a)(i) further includes applying a second function to a second indicia stored by the authentication module, which second indica is derived from a second seed provided by the entity in control of the web site.
8 . The method of claim 1 wherein the predetermined relationship of the first and the second one-time passwords to the one-time code is based on a formula and at least one seed.
9 . The method of claim 1 further comprising the second one-time password being received only if the certification server computer has authenticated the user based on the content of the one-time code.
10 . The method of claim 1 wherein the authentication of the user is based on the one-time code matching the output of a formula and at least one seed, which formula and at least one seed are stored both by the authentication module and by the certification server computer.
11 . A system to authenticating a web site to a user, the system comprising:
(a) an authentication module programmed:
(i) to compute a one-time code,
(ii) to compute a first one-time password having a predetermined relationship to the one-time, and
(iii) to output the one-time but not the first one-time password; and
(b) a transceiver module, communicatively coupled to a global telecommunications network, and programmed:
(i) to send the one-time code via the global telecommunications network for receipt by a certification server computer associated with the web site, which certification server computer is programmed to use the one-time code: (A) to authenticate the user, and (B) to compute a second one-time password in the predetermined relationship to the one-time code, and
(ii) in response to part (b)(i), to receive the second one-time password, which indicates authentication of the web site if the second one-time password matches the first one-time password.
12 . The system of claim 11 wherein the authentication module is a separate device not in electronic communication with the transceiver module.
13 . The system of claim 11 wherein the authentication module is programmed to output the one-time code by transmitting the one-time code to the transceiver module via an audible signal.
14 . The system of claim 11 wherein the authentication module comprises a display and wherein the authentication module is programmed to display the first one-time password computed in part (a)(ii).
15 . The system of claim 11 wherein the authentication module is not connected to the global telecommunications network.
16 . The system of claim 15 wherein the authentication module is programmed to compute the one-time code in part (a)(i) by applying a first function to a first indicia stored by the authentication module, which first indicia is derived from a first seed provided by an arbitration entity in control of the certification server computer, and wherein the web site is controlled by an entity other than the arbitration entity.
17 . The system of claim 16 wherein the authentication module is programmed to compute the one-time code in part (a)(i) by applying a second function to a second indicia stored by the authentication module, which second indica is derived from a second seed provided by the entity in control of the website.
18 . The system of claim 11 wherein the predetermined relationship of the first and the second one-time passwords to the one-time code is based on a formula and at least one seed.
19 . The system of claim 11 wherein the transceiver module is programmed to receive the second one-time password only if the certification server computer has authenticated the user based on the content of the one-time code.
20 . The system of claim 11 wherein the authentication of the user is based on the one-time code matching the output of a formula and at least one seed, which formula and at least one seed are stored both by the authentication module and by the certification server computer.Join the waitlist — get patent alerts
Track US2016241549A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.