System and method for authentication of a mobile device
Abstract
The security of a transaction conducted at a mobile device, using a one-time password to authenticate the mobile device user, is enhanced by requiring that the mobile device also be authenticated by providing a valid mobile device ID. A security server that provides the one-time password to the mobile device also provides a hyperlink that, when selected, causes a mobile device ID, such as an IMSI, to be retrieved from a SIM in the mobile device The retrieved mobile device ID is then sent to the security server. A database associated with the security server stores valid mobile device IDs, and compares the retrieved mobile device ID from the mobile device to the valid mobile device ID for that mobile device stored in the database. In alternative embodiments, the mobile device is authenticated without the use of a one-time password. In some cases the mobile device ID may be a phone number returned in an HTTP message header from the mobile device, and it is compared to a mobile device ID maintained by a bank or other entity managing the transaction.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A security server for authenticating a mobile device of a user conducting a transaction at a transaction server, wherein the security server is programmed to:
receive an authentication request message from the transaction server, the authentication request including a trusted unique mobile identifier associated with the mobile device; provide an SMS request message, to a mobile carrier network providing wireless service to the mobile device, to send an SMS message to the user mobile device, including an authentication link that, when activated at the mobile device, returns an HTTP device authentication request message through the mobile carrier network to the security server, the HTTP device authentication request message including an HTTP message header with a unique mobile ID of the mobile device; compare the trusted unique mobile identifier received from the transaction server with the unique mobile ID in the message header of the HTTP device authentication request message returned through the wireless carrier network from the mobile device; and authenticate the mobile device based on the comparison of the trusted unique mobile identifier and the unique mobile ID in the message header of the HTTP device authentication request message.
2 . The security server of claim 1 , wherein the trusted unique mobile identifier is a mobile phone number for the mobile device, provided during enrollment of a user for conducting transactions at the transaction server.
3 . The security server of claim 2 , wherein the trusted unique mobile identifier is provided during enrollment along with information from the user that authenticates the user at the transaction server during enrollment.
4 . The security server of claim 1 , wherein the unique mobile ID in the message header of the HTTP device authentication request message received through the wireless carrier network from the mobile device is inserted into an enriched HTTP header of the HTTP device authentication request message under the control of the wireless carrier network.
5 . The system of claim 1 , wherein the authentication link in the SMS text message includes metadata with an associated hyperlink active period.
6 . The system of claim 1 , wherein the authentication link in the SMS text message includes metadata with an associated hyperlink time limit.
7 . The system of claim 1 , wherein the mobile device of the user accesses the transaction server to initiate the transaction, using a website hosted at the transaction server and displayed at the mobile device, and in response to initiating the transaction, the transaction server identifies the user and sends the authentication request message to the security server.
8 . The system of claim 7 , wherein the transaction server identifies the user based on identifying information entered by the user at the website.
9 . The system of claim 7 , wherein the security server is further programmed to:
send, in response to the HTTP device authentication request message, a device authentication response message to the mobile device, for advancing the displayed website to a device authentication page indicating that the mobile device is in the process of being authenticated.
10 . The system of claim 7 , wherein the security server is further programmed to:
receive an authentication confirmation request message from the transaction server requesting that the security server provide the status of authentication; and in response, send an authentication confirmation response message, providing the status of the authentication.
11 . A method for authenticating, at a security server, a mobile device of a user conducting a transaction at a transaction server, the method comprising:
receiving, at the security server, an authentication request message from the transaction server, the authentication request including a trusted unique mobile identifier associated with the mobile device; providing, at the security server, an SMS request message to a mobile carrier network providing wireless service to the mobile device, to send an SMS message to the user mobile device, including an authentication link that, when activated at the mobile device, returns an HTTP device authentication request message through the mobile carrier network to the security server, the HTTP device authentication request message including an HTTP message header with a unique mobile ID of the mobile device; comparing, at the security server, the trusted unique mobile identifier received from the transaction server with the unique mobile ID in the message header of the HTTP device authentication request message returned through the wireless carrier network from the mobile device; and authenticating, at the security server, the mobile device based on the comparison of the trusted unique mobile identifier and the unique mobile ID in the message header of the HTTP device authentication request message.
12 . The method of claim 11 , wherein the trusted unique mobile identifier is a mobile phone number for the mobile device, provided during enrollment of a user for conducting transactions at the transaction server.
13 . The method of claim 12 , wherein the trusted unique mobile identifier is provided during enrollment along with information from the user that authenticates the user at the transaction server during enrollment.
14 . The method of claim 11 , wherein the unique mobile ID in the message header of the HTTP device authentication request message received through the wireless carrier network from the mobile device is inserted into an enriched HTTP header of the HTTP device authentication request message under the control of the wireless carrier network.
15 . The method of claim 11 , wherein the authentication link in the SMS text message includes metadata with an associated hyperlink active period.
16 . The method of claim 11 , wherein the authentication link in the SMS text message includes metadata with an associated hyperlink time limit.
17 . The method of claim 11 , wherein the mobile device of the user accesses the transaction server to initiate the transaction, using a website hosted at the transaction server and displayed at the mobile device, and in response to initiating the transaction, the transaction server identifies the user and sends the authentication request message to the security server.
18 . The method of claim 17 , wherein the transaction server identifies the user based on identifying information entered by the user at the website.
19 . The method of claim 17 , further comprising:
sending, from the security server and in response to the HTTP device authentication request message, a device authentication response message to the mobile device, for advancing the displayed website to a device authentication page indicating that the mobile device is in the process of being authenticated.
20 . The method of claim 17 , further comprising:
receiving, at the security server, an authentication confirmation request message from the transaction server requesting that the security server provide the status of authentication; and in response, sending, from the security server, an authentication confirmation response message, providing the status of the authentication.Join the waitlist — get patent alerts
Track US2020210988A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.