Mutual Authentication of a User and Service Provider
Abstract
The present invention relates to a method and system for mutual authentication of a user and service provider, said method comprising acts of: authenticating an event by a key generation module (KGM), said event is generated on a computing device by a user, sending a shared secret of registered user for the event by an authentication server to the key generation module (KGM), generating one time key by the KGM for the event, transmitting the one time key by appending the shared secret to registered user mobile device, and performing at least one of: authenticating the user for said event by the KGM when a registered user enters the one-time key on the computing device within a predetermined time period, or terminating the event upon receipt of predefined key sequence from the mobile device.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method for authentication of an event, the method comprising:
receiving, at a key generation module (KGM), a notification of an event generated at a computing device; transmitting the notification of the event to an authentication server; receiving, at the KGM, from the authentication server, a shared secret provided by a user previously registered for the event; generating, by the KGM, a one-time key for the event; appending the shared secret to the one-time key to generate an appended key; causing the appended key to be transmitted to a mobile device associated with the user previously registered for the event; and authenticating the event in response to receiving a notification from the computing device within a predetermined time period indicating the one-time key was entered at the computing device.
2 . The method of claim 1 , wherein the appended key is transmitted using at least one of Single Data Message Format (SDMF), Multiple Data Message Format (MDMF), Unstructured Supplementary Services Data (USSD), 3G video over voice, interactive voice response (IVR), placed telephone call and general packet radio service (GPRS).
3 . The method of claim 1 , wherein the computing device is a point of sale terminal (POS) and the event is initiated in response to a credit card being read by the POS.
4 . The method of claim 1 , wherein transmitting the appended key to the mobile device comprises invoking automatically a mobile application on the mobile device to render the appended key.
5 . The method of claim 1 , wherein the shared secret is at least one of an image, a sound, a word, a phrase, a video, a number, and an alphanumeric word.
6 . The method of claim 1 , wherein the one-time key is at least one of a symbol, an alphanumeric word, and a number.
7 . The method of claim 1 , further comprising terminating the event responsive to receiving a notification from the computing device indicating that an invalid key was entered at the computing device, wherein the invalid key is different from the one-time key.
8 . The method of claim 7 , wherein the invalid key includes a predefined key sequence known to the user previously registered for the event.
9 . The method of claim 8 , further comprising receiving the predefined key sequence from the mobile device associated with the user previously registered for the event.
10 . The method of claim 7 , further comprising locking an account associated with the user previously registered for the event.
11 . A method for authentication of an event, the method comprising:
receiving, at a key generation module (KGM), a notification of an event generated at a computing device; transmitting the notification of the event to an authentication server; receiving, at the KGM, from the authentication server, a shared secret provided by a user previously registered for the event; generating, by the KGM, a one-time key for the event; appending the shared secret to the one-time key to generate an appended key; causing the appended key to be transmitted to a mobile device associated with the user previously registered for the event; and responsive to receiving a notification within a predetermined time period indicating the one-time key was entered at the computing device, authenticating the event.
12 . The method of claim 11 , wherein the appended key is transmitted using at least one of Single Data Message Format (SDMF), Multiple Data Message Format (MDMF), Unstructured Supplementary Services Data (USSD), 3G video over voice, interactive voice response (IVR), placed telephone call and general packet radio service (GPRS).
13 . The method of claim 11 , wherein the computing device is a point of sale terminal (POS) and the event is initiated in response to a credit card being read by the POS.
14 . The method of claim 11 , wherein transmitting the appended key to the mobile device comprises invoking automatically a mobile application on the mobile device to render the appended key.
15 . The method of claim 11 , wherein the shared secret is at least one of an image, a sound, a word, a phrase, a video, a number, and an alphanumeric word.
16 . The method of claim 11 , wherein the one-time key is at least one of a symbol, an alphanumeric word, and a number.
17 . The method of claim 11 , further comprising terminating the event responsive to receiving a notification from the computing device indicating that an invalid key was entered at the computing device, wherein the invalid key is different from the one-time key.
18 . The method of claim 17 , wherein the invalid key includes a predefined key sequence known to the user previously registered for the event.
19 . The method of claim 18 , further comprising receiving the predefined key sequence from the mobile device associated with the user previously registered for the event.
20 . The method of claim 17 , further comprising locking an account associated with the user previously registered for the event.Join the waitlist — get patent alerts
Track US2017286957A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.