US2019215314A1PendingUtilityA1

Second factor authorization via a hardware token device

Assignee: IBMPriority: Feb 27, 2017Filed: Mar 22, 2019Published: Jul 11, 2019
Est. expiryFeb 27, 2037(~10.6 yrs left)· nominal 20-yr term from priority
H04L 63/0853H04L 2463/082H04L 63/062H04L 63/0838
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A credential associated with a username is received from a user. The credential is verified. A key identification and a first one-time password are received from a hardware token device. In response to validating the first one-time password, the username is linked to the key identification. A first access token and a first refresh token are generated. The first access token and the first refresh token are sent to the user.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for providing second factor authorization using a hardware token device and a specific hardware token device, the method comprising:
 receiving, by one or more computer processors, a credential associated with a username from a user device, wherein the credential is selected from a group consisting of: a username, a password, an access token, a refresh token, an application program interface key, a client identification, a client username, and an authorization code;   verifying, by the one or more computer processors, the credential;   responsive to verifying the credential, receiving, by the one or more computer processors, a key identification and a first one-time password from the hardware token device, wherein   the key identification is specific to and identifies the hardware token device; and   the hardware token device connection is selected from a group consisting of connected to a computing device or not connected to a computing device;   validating, by the one or more computer processors, the received first one-time password;   responsive to determining that the first one-time password is invalid, notifying the user device;   responsive to determining that the first one-time password is valid, linking, by the one or more computer processors, the username to the key identification;   responsive to linking the username to the key identification, generating, by the one or more computer processors, a first access token and a first refresh token;   sending, by the one or more computer processors, the first access token and the first refresh token to the user device;   receiving, by the one or more computer processors, the first access token from the user device for access authorization;   determining, by the one or more computer processors, whether or not the first access token has expired;   responsive to determining that the first access token has expired, sending, by the one or more computer processors, a request to the user device to send the first refresh token;   receiving, by the one or more computer processors, the first refresh token from the user device and a second one-time password from the specific hardware token device;   validating, by the one or more computer processors, the first refresh token;   responsive to determining that the first refresh token is invalid, notifying, by the one or more computer processors, the user device;   responsive to determining that the first refresh token is valid, determining, by the one or more computer processors, the username associated with the first refresh token;   retrieving, by the one or more computer processors, the key identification from the linked username and key identification from the specific hardware token device;   determining, by the one or more computer processors, that the second one-time password is valid or invalid, wherein the determination is based on the first one-time password and a format of the key identification;   responsive to determining that the second one-time password is invalid, notifying, by the one or more computer processors, the user device, wherein the notification is selected from a group consisting of a text-based notice, an audible notice, a haptic notice, and a visual notice;   responsive to determining that the second one-time password is valid, generating, by the one or more computer processors, a second access token and a second refresh token; and   sending, by the one or more computer processors, the second access token and the second refresh token to the user device.

Join the waitlist — get patent alerts

Track US2019215314A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.