Two factor authentication using a one-time password
Abstract
Methods and systems for online authentication eliminate the common username plus password combination, using instead a novel two-factor authentication that employs a mobile phone number and a one-time, limited life password. The user provides the mobile phone number to a login dialog and receives, from a service provider, the one-time password, e.g., via a text message, at the mobile device to which the phone number belongs. If the user enters the one-time password before it expires, the user is authenticated and logged in. A method for authentication or authorization to a website includes: receiving a phone number from a user via a communication network in response to a login prompt displayed to the user; transmitting a one-time password to the phone number using text messaging; and in response to receiving the one-time password back from the user, authenticating the user for transactions with the website.
Claims
exact text as granted — not AI-modified1 . A method comprising:
receiving, by an authentication system from a user through a network via a first secure subsystem, an identifier that is associated with an account; transmitting, by the authentication system to a user device using the identifier, a one-time password; receiving, by the authentication system from the user through the network via the first secure subsystem, a user input; determining, by the authentication system, that the user input includes the one-time password that was transmitted to the user device; authenticating, by the authentication system in response to determining that the user input includes the one-time password that was transmitted to the user device, the user with the first secure subsystem and at least one other-website second secure subsystem without further use of the one-time password or user identifier.
2 . The method of claim 1 , wherein authenticating the user with the first secure subsystem further comprises:
generating, by the authentication system, unique identifier that represents the account; and transmitting, by the authentication system to the first secure subsystem, profile information for the account that includes the unique identifier generated by the authentication system.
3 . The method of claim 2 , wherein the user is authenticated with the at least one second secure subsystem using the profile information.
4 . The method of claim 1 , wherein the user is authenticated with the first secure subsystem and at least one second secure subsystem in response only to receiving the user input that includes the one-time password.
5 . The method of claim 1 , wherein the one-time password is transmitted by the authentication system to the user device via a text message.
6 . The method of claim 1 , wherein the user device is distinct from the first secure subsystem.
7 . The method of claim 1 , wherein the first secure subsystem includes a website.
8 . An authentication system comprising:
a non-transitory memory; and one or more hardware processors that are coupled to the non-transitory memory and configured to execute instructions to cause the authentication system to perform operations comprising:
receiving, from a user through a network via a first secure subsystem, an identifier that is associated with an account;
transmitting, to a user device using the identifier, a one-time password;
receiving, from the user through the network via the first secure subsystem, a user input;
determining that the user input includes the one-time password that was transmitted to the user device;
authenticating, in response to determining that the user input includes the one-time password that was transmitted to the user device, the user with the first secure subsystem and at least one second secure subsystem without further use of the one-time password or user identifier.
9 . The system of claim 8 , wherein authenticating the user with the first secure subsystem further comprises:
generating a unique identifier that represents the account; and transmitting, to the first secure subsystem, profile information for the account that includes a unique identifier that represents the account.
10 . The system of claim 9 , wherein the user is authenticated with the at least one second secure subsystem using the profile information.
11 . The system of claim 8 , wherein the user is authenticated with the first secure subsystem and at least one second secure subsystem in response only to receiving the user input that includes the one-time password.
12 . The system of claim 8 , wherein the one-time password is transmitted to the user device via a text message.
13 . The system of claim 8 , wherein the user device is distinct from the first secure subsystem.
14 . The system of claim 8 , wherein the first secure subsystem includes a website.
15 . A non-transitory machine-readable medium having stored thereon machine-readable instructions executable to cause a machine to perform operations comprising:
receiving, from a user through a network via a first secure subsystem, an identifier that is associated with an account; transmitting, to a user device using the identifier, a one-time password; receiving, from the user through the network via the first secure subsystem, a user input; determining that the user input includes the one-time password that was transmitted to the user device; and authenticating, in response to determining that the user input includes the one-time password that was transmitted to the user device, the user with the first secure subsystem and at least one second secure subsystem without further use of the one-time password or user identifier.
16 . The non-transitory machine-readable medium of claim 15 , wherein authenticating the user with the first secure subsystem further comprises:
generating a unique identifier that represents the account; and transmitting, to the first secure subsystem, profile information for the account that includes a unique identifier that represents the account.
17 . The non-transitory machine-readable medium of claim 16 , wherein the user is authenticated with the at least one second secure subsystem using the profile information.
18 . The non-transitory machine-readable medium of claim 15 , wherein the user is authenticated with the first secure subsystem and at least one second secure subsystem in response only to receiving the user input that includes the one-time password.
19 . The non-transitory machine-readable medium of claim 15 , wherein the one-time password is transmitted to the user device via a text message.
20 . The non-transitory machine-readable medium of claim 15 , wherein the user device is distinct from the first secure subsystem.Join the waitlist — get patent alerts
Track US2016308856A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.