US2019005212A1PendingUtilityA1

Direct authentication system and method via trusted authenticators

Assignee: ASGHARI KAMRANI NADERPriority: Aug 29, 2001Filed: Aug 14, 2018Published: Jan 3, 2019
Est. expiryAug 29, 2021(expired)· nominal 20-yr term from priority
G06Q 20/4014G06F 21/31H04L 63/0807H04L 63/062H04L 63/0892H04L 63/0838H04L 63/0421H04L 2463/082G06Q 20/3823G07F 7/1008G06Q 20/341G06F 2221/2115G06F 21/6245
66
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided for enabling online entities to determine whether a user is truly the person who he says using a “two-factor” authentication technique and authenticating customer's identity utilizing a trusted authenticator.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A system for enhancing online authentication of a user attempting to access an online system, the authentication system comprising one or more computing devices configured to perform operations comprising:
 receiving, via a computer network, after the user attempts to access the online system, a request for a user-authentication code for the user;   providing, via the computer network, the user-authentication code in response to the request for the user-authentication code, wherein:
 the user-authentication code is information generated by the authentication system for authenticating the user, 
 the user-authentication code is configured to be valid for a predetermined time, 
 the user-authentication code is configured to become invalid after the predetermined time, and 
 the user-authentication code is configured to become invalid after a first use to authenticate the user; 
   receiving, via the computer network, a user-authentication request for authenticating the user from the online system, the user-authentication request comprising the user-authentication code and user-identification information of the user;   authenticating the user based on at least the user-authentication code and the user-identification information included in the authentication request; and   providing, via the computer network, a result of the authenticating to the online system in response to the authentication request.   
     
     
         2 . The system of  claim 1 , wherein the user-authentication code is a SecureCode. 
     
     
         3 . The system of  claim 2 , wherein the SecureCode is comprised of alphabetic characters. 
     
     
         4 . The system of  claim 2 , wherein the SecureCode is comprised of numeric characters. 
     
     
         5 . The system of  claim 2 , wherein the SecureCode is a Personal Identification Number (PIN). 
     
     
         6 . The system of  claim 1 , wherein the computer network comprises a private network. 
     
     
         7 . The system of  claim 1 , wherein the user-authentication code is variable and has a different value each time the system provides it. 
     
     
         8 . The system of  claim 1 , wherein authenticating the user comprises determining whether the user-authentication code received in the authentication request is valid. 
     
     
         9 . The system of  claim 8 , wherein determining whether the user-authentication code received in the authentication request is valid comprises:
 determining whether the user-authentication request is the first use of the user-authentication code to authenticate the user; and   determining whether a time of the first use is within the predetermined time.   
     
     
         10 . The system of  claim 9 , wherein the time of the first use is a current time. 
     
     
         11 . The system of  claim 8 , wherein after authenticating the user, the user-authentication code is invalid for all subsequent user-authentication requests. 
     
     
         12 . The system of  claim 8 , wherein the user-authentication code is valid for authenticating the user at the time the user receives the user-authentication code. 
     
     
         13 . The system of claim of  1 , wherein receiving the user-authentication request and providing the result occur during a real-time interaction between the user and the online system. 
     
     
         14 . The system of  claim 1 , wherein the online system is an online site. 
     
     
         15 . The system of  claim 1 , wherein:
 the result confirms authentication of the user if the user-authentication code is valid; and   the result denies authentication of the user if the user-authentication code is invalid.   
     
     
         16 . A method of online authentication of a user attempting to access an online system, the method comprising:
 receiving, by a computing device via a computer network, after the user attempts to access the online system, a request for a user-authentication code for the user;   providing, by the computing device via the computer network, the user-authentication code in response to the request for the user-authentication code, wherein:
 the user-authentication code is information generated by the authentication system for authenticating the user, 
 the user-authentication code is configured to be valid for a predetermined time, 
 the user-authentication code is configured to become invalid after the predetermined time, and 
 the user-authentication code is configured to become invalid after a first use to authenticate the user; 
   receiving, by the computing device via the computer network, a user-authentication request for authenticating the user from the online system, the user-authentication request comprising the user-authentication code and user-identification information of the user;   authenticating, by the computing device, the user using the user-authentication code and the user-identification information included in the authentication request; and   providing, by the computing device via the computer network, a result of the authenticating to the online system in response to the authentication request.   
     
     
         17 . The method of  claim 16 , wherein the user-authentication code is a SecureCode. 
     
     
         18 . The method of  claim 17 , wherein the SecureCode is comprised of alphabetic characters. 
     
     
         19 . The method of  claim 17 , wherein the SecureCode is comprised of numeric characters. 
     
     
         20 . The method of  claim 17 , wherein the SecureCode is a Personal Identification Number (PIN). 
     
     
         21 . The method of  claim 16 , wherein the computer network comprises a private network. 
     
     
         22 . The method of  claim 16 , wherein the user-authentication code is variable and has a different value each time the computing device provides it. 
     
     
         23 . The method of  claim 16 , wherein authenticating the user comprises determining whether the user-authentication code received in the authentication request is valid. 
     
     
         24 . The method of  claim 23 , wherein determining whether the user-authentication code received in the authentication request is valid comprises:
 determining whether the user-authentication request is the first use of the user-authentication code to authenticate the user; and   determining whether a time of the first use is within the predetermined time.   
     
     
         25 . The method of  claim 24 , wherein the time of the first use is a current time. 
     
     
         26 . The method of  claim 23 , wherein after authenticating the user, the user-authentication code is invalid for all subsequent user-authentication requests. 
     
     
         27 . The method of  claim 23 , wherein the user-authentication code is valid for authenticating the user at the time the user receives the user-authentication code. 
     
     
         28 . The method of claim of  16 , wherein receiving the user-authentication request and providing the result occur during a real-time interaction between the user and the online system. 
     
     
         29 . The method of  claim 16 , wherein the online system is an online site. 
     
     
         30 . The method of  claim 16 , wherein:
 the result confirms authentication of the user if the user-authentication code is valid; and   the result denies authentication of the user if the user-authentication code is invalid.

Join the waitlist — get patent alerts

Track US2019005212A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.