US2017286957A1PendingUtilityA1

Mutual Authentication of a User and Service Provider

Assignee: KACHYNG INCPriority: Mar 31, 2010Filed: Jun 23, 2017Published: Oct 5, 2017
Est. expiryMar 31, 2030(~3.7 yrs left)· nominal 20-yr term from priority
Inventors:Resh Wallaja
H04L 9/14H04L 9/0819G06Q 20/00H04L 9/321H04L 9/0861G06Q 20/20H04L 63/0869H04L 9/3226H04L 9/3228H04L 63/18H04L 2209/56G06Q 20/401G06Q 20/40975
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention relates to a method and system for mutual authentication of a user and service provider, said method comprising acts of: authenticating an event by a key generation module (KGM), said event is generated on a computing device by a user, sending a shared secret of registered user for the event by an authentication server to the key generation module (KGM), generating one time key by the KGM for the event, transmitting the one time key by appending the shared secret to registered user mobile device, and performing at least one of: authenticating the user for said event by the KGM when a registered user enters the one-time key on the computing device within a predetermined time period, or terminating the event upon receipt of predefined key sequence from the mobile device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method for authentication of an event, the method comprising:
 receiving, at a key generation module (KGM), a notification of an event generated at a computing device;   transmitting the notification of the event to an authentication server;   receiving, at the KGM, from the authentication server, a shared secret provided by a user previously registered for the event;   generating, by the KGM, a one-time key for the event;   appending the shared secret to the one-time key to generate an appended key;   causing the appended key to be transmitted to a mobile device associated with the user previously registered for the event; and   authenticating the event in response to receiving a notification from the computing device within a predetermined time period indicating the one-time key was entered at the computing device.   
     
     
         2 . The method of  claim 1 , wherein the appended key is transmitted using at least one of Single Data Message Format (SDMF), Multiple Data Message Format (MDMF), Unstructured Supplementary Services Data (USSD), 3G video over voice, interactive voice response (IVR), placed telephone call and general packet radio service (GPRS). 
     
     
         3 . The method of  claim 1 , wherein the computing device is a point of sale terminal (POS) and the event is initiated in response to a credit card being read by the POS. 
     
     
         4 . The method of  claim 1 , wherein transmitting the appended key to the mobile device comprises invoking automatically a mobile application on the mobile device to render the appended key. 
     
     
         5 . The method of  claim 1 , wherein the shared secret is at least one of an image, a sound, a word, a phrase, a video, a number, and an alphanumeric word. 
     
     
         6 . The method of  claim 1 , wherein the one-time key is at least one of a symbol, an alphanumeric word, and a number. 
     
     
         7 . The method of  claim 1 , further comprising terminating the event responsive to receiving a notification from the computing device indicating that an invalid key was entered at the computing device, wherein the invalid key is different from the one-time key. 
     
     
         8 . The method of  claim 7 , wherein the invalid key includes a predefined key sequence known to the user previously registered for the event. 
     
     
         9 . The method of  claim 8 , further comprising receiving the predefined key sequence from the mobile device associated with the user previously registered for the event. 
     
     
         10 . The method of  claim 7 , further comprising locking an account associated with the user previously registered for the event. 
     
     
         11 . A method for authentication of an event, the method comprising:
 receiving, at a key generation module (KGM), a notification of an event generated at a computing device;   transmitting the notification of the event to an authentication server;   receiving, at the KGM, from the authentication server, a shared secret provided by a user previously registered for the event;   generating, by the KGM, a one-time key for the event;   appending the shared secret to the one-time key to generate an appended key;   causing the appended key to be transmitted to a mobile device associated with the user previously registered for the event; and   responsive to receiving a notification within a predetermined time period indicating the one-time key was entered at the computing device, authenticating the event.   
     
     
         12 . The method of  claim 11 , wherein the appended key is transmitted using at least one of Single Data Message Format (SDMF), Multiple Data Message Format (MDMF), Unstructured Supplementary Services Data (USSD), 3G video over voice, interactive voice response (IVR), placed telephone call and general packet radio service (GPRS). 
     
     
         13 . The method of  claim 11 , wherein the computing device is a point of sale terminal (POS) and the event is initiated in response to a credit card being read by the POS. 
     
     
         14 . The method of  claim 11 , wherein transmitting the appended key to the mobile device comprises invoking automatically a mobile application on the mobile device to render the appended key. 
     
     
         15 . The method of  claim 11 , wherein the shared secret is at least one of an image, a sound, a word, a phrase, a video, a number, and an alphanumeric word. 
     
     
         16 . The method of  claim 11 , wherein the one-time key is at least one of a symbol, an alphanumeric word, and a number. 
     
     
         17 . The method of  claim 11 , further comprising terminating the event responsive to receiving a notification from the computing device indicating that an invalid key was entered at the computing device, wherein the invalid key is different from the one-time key. 
     
     
         18 . The method of  claim 17 , wherein the invalid key includes a predefined key sequence known to the user previously registered for the event. 
     
     
         19 . The method of  claim 18 , further comprising receiving the predefined key sequence from the mobile device associated with the user previously registered for the event. 
     
     
         20 . The method of  claim 17 , further comprising locking an account associated with the user previously registered for the event.

Join the waitlist — get patent alerts

Track US2017286957A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.