US2018248862A1PendingUtilityA1

Second factor authorization via a hardware token device

Assignee: IBMPriority: Feb 27, 2017Filed: Dec 27, 2017Published: Aug 30, 2018
Est. expiryFeb 27, 2037(~10.6 yrs left)· nominal 20-yr term from priority
H04L 63/062H04L 2463/082H04L 63/0838H04L 63/0853
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A credential associated with a username is received from a user. The credential is verified. A key identification and a first one-time password are received from a hardware token device. In response to validating the first one-time password, the username is linked to the key identification. A first access token and a first refresh token are generated. The first access token and the first refresh token are sent to the user.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for providing second factor authorization using a hardware token device, the method comprising:
 receiving, by one or more computer processors, a credential associated with a username from a user, wherein the credential is selected from the group consisting of: a username, a password, an access token, a refresh token, an application program interface key, a client identification, a client username, and an authorization code;   verifying, by the one or more computer processors, the credential;   receiving, by the one or more computer processors, a key identification and a first one-time password from a hardware token device, wherein
 the key identification is specific to and identifies the hardware token device; and 
 the hardware token device connection is selected from the group consisting of connected to a computing device or disconnected from a computing device; 
   validating, by the one or more computer processors, the first one-time password;   responsive to validating the first one-time password, linking, by the one or more computer processors, the username to the key identification;   generating, by the one or more computer processors, a first access token and a first refresh token;   sending, by the one or more computer processors, the first access token and the first refresh token to the user;   receiving, by the one or more computer processors, the first access token from the user, wherein the first access token has expired;   sending, by the one or more computer processors, a request to the user to send the first refresh token;   receiving, by the one or more computer processors, the first refresh token and a second one-time password, wherein the second one-time password is sent from the specific hardware token device;   validating, by the one or more computer processors, the first refresh token;   determining, by the one or more computer processors, the username associated with the first refresh token;   retrieving, by the one or more computer processors, the key identification from the linked username and key identification from the specific hardware token device;   determining, by the one or more computer processors, that the second one-time password is invalid;   responsive to determining that the second one-time password is invalid, notifying, by the one or more computer processors, the user, wherein the notification is selected from the group consisting of a text-based notice, an audible notice, a haptic notice, and a visual notice;   generating, by the one or more computer processors, a second access token and a second refresh token;   sending, by the one or more computer processors, the second access token and the second refresh token to the user;   determining, by the one or more computer processors, that the first refresh token is invalid; and   responsive to determining that the first refresh token is invalid, notifying, by the one or more computer processors, the user.

Join the waitlist — get patent alerts

Track US2018248862A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.