Applying a function to a password to determine an expected response
Abstract
A system may perform operations including transmitting a service request to a service provider, wherein the service request includes a device identifier of the computer-based system or a device fingerprint of the computer-based system; receiving a seed one-time password (OTP) to the computer-based system from the service provider, wherein the seed OTP comprises a random number that is valid for a predetermined time period and is discarded after first use; calculating a one-time password (OTP) by applying a hash function to the seed OTP, wherein the hash function is based on the device identifier of the computer-based system or the device fingerprint of the computer-based system; transmitting a response OTP to the service provider for validation by the service provider, wherein the response OTP is different from the seed OTP; and receiving a validation result from the service provider.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method comprising:
transmitting, by a processor, a service request to a service provider, wherein the service request includes a device identifier of a user device or a device fingerprint of the user device; receiving, by the processor, a seed one-time password (OTP) to the user device from the service provider, wherein the seed OTP comprises a random number that is valid for a predetermined time period and is discarded after first use; calculating, by the processor, a one-time password (OTP) by applying a hash function to the seed OTP, wherein the hash function is based on the device identifier of the user device or the device fingerprint of the user device; transmitting, by the processor, a response OTP generated by the user device to the service provider for validation by the service provider, wherein the response OTP is different from the seed OTP; and receiving, by the processor, a validation result from the service provider, wherein the seed OTP is discarded after receipt of the validation result.
2 . The method of claim 1 , further comprising displaying, by the processor, an authorization screen with service details before transmitting of the response OTP to the service provider.
3 . The method of claim 1 , wherein the response OTP is generated in response to an integrity module confirming that the user device is in good health based on the seed OTP being passed to a security utilities software development kit (SDK) on the user device.
4 . The method of claim 1 , further comprising displaying, by the processor, a notification screen in response to receiving the validation result, wherein the notification screen indicates an outcome of the validation result.
5 . The method of claim 4 , wherein the notification screen is displayed along with at least one of a service name request, a purpose, a time, a merchant, a merchant locator, or an amount for the requested service.
6 . The method of claim 1 , wherein the seed OTP is received with an authorization payload including at least one of a service identifier, a purpose, a time, a date, a merchant identifier, or an amount for the requested service.
7 . The method of claim 1 , wherein the response OTP is transmitted from the user device via a text message.
8 . The method of claim 1 , wherein the service request is transmitted over a first communication channel to the service provider and the seed OTP is received over a second communication channel from the service provider.
9 . The method of claim 1 , wherein the seed OTP comprises a random number of at least 128 bytes in length.
10 . A computer-based system, comprising:
a processor; and a tangible, non-transitory memory configured to communicate with the processor, the tangible, non-transitory memory having instructions stored thereon that, in response to execution by the processor, cause the processor to perform operations comprising:
transmitting, by the processor, a service request to a service provider, wherein the service request includes a device identifier of a user device or a device fingerprint of the user device;
receiving, by the processor, a seed one-time password (OTP) to the user device from the service provider, wherein the seed OTP comprises a random number that is valid for a predetermined time period and is discarded after first use;
calculating, by the processor, a one-time password (OTP) by applying a hash function to the seed OTP, wherein the hash function is based on the device identifier of the user device or the device fingerprint of the user device;
transmitting, by the processor, a response OTP generated by the user device to the service provider for validation by the service provider, wherein the response OTP is different from the seed OTP; and
receiving, by the processor, a validation result from the service provider, wherein the seed OTP is discarded after receipt of the validation result.
11 . The system of claim 10 , wherein the response OTP is generated in response to an integrity module confirming that the user device is in good health based on the seed OTP being passed to a security utilities software development kit (SDK) on the user device.
12 . The system of claim 10 , wherein the operations further comprise displaying, by the processor, a notification screen in response to receiving the validation result, wherein the notification screen indicates an outcome of the validation result.
13 . The system of claim 10 , wherein the seed OTP is received with an authorization payload including at least one of a service identifier, a purpose, a time, a date, a merchant identifier, or an amount for the requested service.
14 . The system of claim 10 , wherein the response OTP is transmitted from the user device via a text message.
15 . The system of claim 10 , wherein the service request is transmitted over a first communication channel to the service provider and the seed OTP is received over a second communication channel from the service provider.
16 . The system of claim 10 , wherein the seed OTP comprises a random number of at least 128 bytes in length.
17 . A non-transitory computer-readable medium having instructions stored thereon that, in response to execution by a computer-based system, cause the computer-based system to perform operations comprising:
transmitting, by the computer-based system, a service request to a service provider, wherein the service request includes a device identifier of the computer-based system or a device fingerprint of the computer-based system; receiving, by the computer-based system, a seed one-time password (OTP) to the computer-based system from the service provider, wherein the seed OTP comprises a random number that is valid for a predetermined time period and is discarded after first use; calculating, by the computer-based system, a one-time password (OTP) by applying a hash function to the seed OTP, wherein the hash function is based on the device identifier of the computer-based system or the device fingerprint of the computer-based system; transmitting, by the computer-based system, a response OTP generated by the computer-based system to the service provider for validation by the service provider, wherein the response OTP is different from the seed OTP; and receiving, by the computer-based system, a validation result from the service provider, wherein the seed OTP is discarded after receipt of the validation result.
18 . The non-transitory computer-readable medium of claim 17 , wherein the response OTP is generated in response to an integrity module confirming that the computer-based system is in good health based on the seed OTP being passed to a security utilities software development kit (SDK) on the user device.
19 . The non-transitory computer-readable medium of claim 17 , wherein the seed OTP is received with an authorization payload including at least one of a service identifier, a purpose, a time, a date, a merchant identifier, or an amount for the requested service.
20 . The non-transitory computer-readable medium of claim 17 , wherein the service request is transmitted over a first communication channel to the service provider and the seed OTP is received over a second communication channel from the service provider.Join the waitlist — get patent alerts
Track US2021320913A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.