US2016308856A1PendingUtilityA1

Two factor authentication using a one-time password

Assignee: PAYPAL INCPriority: Apr 13, 2012Filed: Jun 24, 2016Published: Oct 20, 2016
Est. expiryApr 13, 2032(~5.7 yrs left)· nominal 20-yr term from priority
Inventors:Paul Rockwell
H04L 2463/082H04L 63/0846H04W 12/06H04L 9/3228H04L 63/102H04L 63/0838G06F 21/43
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and systems for online authentication eliminate the common username plus password combination, using instead a novel two-factor authentication that employs a mobile phone number and a one-time, limited life password. The user provides the mobile phone number to a login dialog and receives, from a service provider, the one-time password, e.g., via a text message, at the mobile device to which the phone number belongs. If the user enters the one-time password before it expires, the user is authenticated and logged in. A method for authentication or authorization to a website includes: receiving a phone number from a user via a communication network in response to a login prompt displayed to the user; transmitting a one-time password to the phone number using text messaging; and in response to receiving the one-time password back from the user, authenticating the user for transactions with the website.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 receiving, by an authentication system from a user through a network via a first secure subsystem, an identifier that is associated with an account;   transmitting, by the authentication system to a user device using the identifier, a one-time password;   receiving, by the authentication system from the user through the network via the first secure subsystem, a user input;   determining, by the authentication system, that the user input includes the one-time password that was transmitted to the user device;   authenticating, by the authentication system in response to determining that the user input includes the one-time password that was transmitted to the user device, the user with the first secure subsystem and at least one other-website second secure subsystem without further use of the one-time password or user identifier.   
     
     
         2 . The method of  claim 1 , wherein authenticating the user with the first secure subsystem further comprises:
 generating, by the authentication system, unique identifier that represents the account; and   transmitting, by the authentication system to the first secure subsystem, profile information for the account that includes the unique identifier generated by the authentication system.   
     
     
         3 . The method of  claim 2 , wherein the user is authenticated with the at least one second secure subsystem using the profile information. 
     
     
         4 . The method of  claim 1 , wherein the user is authenticated with the first secure subsystem and at least one second secure subsystem in response only to receiving the user input that includes the one-time password. 
     
     
         5 . The method of  claim 1 , wherein the one-time password is transmitted by the authentication system to the user device via a text message. 
     
     
         6 . The method of  claim 1 , wherein the user device is distinct from the first secure subsystem. 
     
     
         7 . The method of  claim 1 , wherein the first secure subsystem includes a website. 
     
     
         8 . An authentication system comprising:
 a non-transitory memory; and   one or more hardware processors that are coupled to the non-transitory memory and configured to execute instructions to cause the authentication system to perform operations comprising:
 receiving, from a user through a network via a first secure subsystem, an identifier that is associated with an account; 
 transmitting, to a user device using the identifier, a one-time password; 
 receiving, from the user through the network via the first secure subsystem, a user input; 
 determining that the user input includes the one-time password that was transmitted to the user device; 
 authenticating, in response to determining that the user input includes the one-time password that was transmitted to the user device, the user with the first secure subsystem and at least one second secure subsystem without further use of the one-time password or user identifier. 
   
     
     
         9 . The system of  claim 8 , wherein authenticating the user with the first secure subsystem further comprises:
 generating a unique identifier that represents the account; and   transmitting, to the first secure subsystem, profile information for the account that includes a unique identifier that represents the account.   
     
     
         10 . The system of  claim 9 , wherein the user is authenticated with the at least one second secure subsystem using the profile information. 
     
     
         11 . The system of  claim 8 , wherein the user is authenticated with the first secure subsystem and at least one second secure subsystem in response only to receiving the user input that includes the one-time password. 
     
     
         12 . The system of  claim 8 , wherein the one-time password is transmitted to the user device via a text message. 
     
     
         13 . The system of  claim 8 , wherein the user device is distinct from the first secure subsystem. 
     
     
         14 . The system of  claim 8 , wherein the first secure subsystem includes a website. 
     
     
         15 . A non-transitory machine-readable medium having stored thereon machine-readable instructions executable to cause a machine to perform operations comprising:
 receiving, from a user through a network via a first secure subsystem, an identifier that is associated with an account;   transmitting, to a user device using the identifier, a one-time password;   receiving, from the user through the network via the first secure subsystem, a user input;   determining that the user input includes the one-time password that was transmitted to the user device; and   authenticating, in response to determining that the user input includes the one-time password that was transmitted to the user device, the user with the first secure subsystem and at least one second secure subsystem without further use of the one-time password or user identifier.   
     
     
         16 . The non-transitory machine-readable medium of  claim 15 , wherein authenticating the user with the first secure subsystem further comprises:
 generating a unique identifier that represents the account; and   transmitting, to the first secure subsystem, profile information for the account that includes a unique identifier that represents the account.   
     
     
         17 . The non-transitory machine-readable medium of  claim 16 , wherein the user is authenticated with the at least one second secure subsystem using the profile information. 
     
     
         18 . The non-transitory machine-readable medium of  claim 15 , wherein the user is authenticated with the first secure subsystem and at least one second secure subsystem in response only to receiving the user input that includes the one-time password. 
     
     
         19 . The non-transitory machine-readable medium of  claim 15 , wherein the one-time password is transmitted to the user device via a text message. 
     
     
         20 . The non-transitory machine-readable medium of  claim 15 , wherein the user device is distinct from the first secure subsystem.

Join the waitlist — get patent alerts

Track US2016308856A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.