US2021320913A1PendingUtilityA1

Applying a function to a password to determine an expected response

Assignee: AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INCPriority: Sep 21, 2015Filed: Jun 23, 2021Published: Oct 14, 2021
Est. expirySep 21, 2035(~9.1 yrs left)· nominal 20-yr term from priority
H04L 63/10H04L 63/0838G06Q 20/385G06Q 20/00H04L 63/0876
66
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system may perform operations including transmitting a service request to a service provider, wherein the service request includes a device identifier of the computer-based system or a device fingerprint of the computer-based system; receiving a seed one-time password (OTP) to the computer-based system from the service provider, wherein the seed OTP comprises a random number that is valid for a predetermined time period and is discarded after first use; calculating a one-time password (OTP) by applying a hash function to the seed OTP, wherein the hash function is based on the device identifier of the computer-based system or the device fingerprint of the computer-based system; transmitting a response OTP to the service provider for validation by the service provider, wherein the response OTP is different from the seed OTP; and receiving a validation result from the service provider.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A method comprising:
 transmitting, by a processor, a service request to a service provider, wherein the service request includes a device identifier of a user device or a device fingerprint of the user device;   receiving, by the processor, a seed one-time password (OTP) to the user device from the service provider, wherein the seed OTP comprises a random number that is valid for a predetermined time period and is discarded after first use;   calculating, by the processor, a one-time password (OTP) by applying a hash function to the seed OTP, wherein the hash function is based on the device identifier of the user device or the device fingerprint of the user device;   transmitting, by the processor, a response OTP generated by the user device to the service provider for validation by the service provider, wherein the response OTP is different from the seed OTP; and   receiving, by the processor, a validation result from the service provider, wherein the seed OTP is discarded after receipt of the validation result.   
     
     
         2 . The method of  claim 1 , further comprising displaying, by the processor, an authorization screen with service details before transmitting of the response OTP to the service provider. 
     
     
         3 . The method of  claim 1 , wherein the response OTP is generated in response to an integrity module confirming that the user device is in good health based on the seed OTP being passed to a security utilities software development kit (SDK) on the user device. 
     
     
         4 . The method of  claim 1 , further comprising displaying, by the processor, a notification screen in response to receiving the validation result, wherein the notification screen indicates an outcome of the validation result. 
     
     
         5 . The method of  claim 4 , wherein the notification screen is displayed along with at least one of a service name request, a purpose, a time, a merchant, a merchant locator, or an amount for the requested service. 
     
     
         6 . The method of  claim 1 , wherein the seed OTP is received with an authorization payload including at least one of a service identifier, a purpose, a time, a date, a merchant identifier, or an amount for the requested service. 
     
     
         7 . The method of  claim 1 , wherein the response OTP is transmitted from the user device via a text message. 
     
     
         8 . The method of  claim 1 , wherein the service request is transmitted over a first communication channel to the service provider and the seed OTP is received over a second communication channel from the service provider. 
     
     
         9 . The method of  claim 1 , wherein the seed OTP comprises a random number of at least 128 bytes in length. 
     
     
         10 . A computer-based system, comprising:
 a processor; and   a tangible, non-transitory memory configured to communicate with the processor, the tangible, non-transitory memory having instructions stored thereon that, in response to execution by the processor, cause the processor to perform operations comprising:
 transmitting, by the processor, a service request to a service provider, wherein the service request includes a device identifier of a user device or a device fingerprint of the user device; 
 receiving, by the processor, a seed one-time password (OTP) to the user device from the service provider, wherein the seed OTP comprises a random number that is valid for a predetermined time period and is discarded after first use; 
 calculating, by the processor, a one-time password (OTP) by applying a hash function to the seed OTP, wherein the hash function is based on the device identifier of the user device or the device fingerprint of the user device; 
 transmitting, by the processor, a response OTP generated by the user device to the service provider for validation by the service provider, wherein the response OTP is different from the seed OTP; and 
 receiving, by the processor, a validation result from the service provider, wherein the seed OTP is discarded after receipt of the validation result. 
   
     
     
         11 . The system of  claim 10 , wherein the response OTP is generated in response to an integrity module confirming that the user device is in good health based on the seed OTP being passed to a security utilities software development kit (SDK) on the user device. 
     
     
         12 . The system of  claim 10 , wherein the operations further comprise displaying, by the processor, a notification screen in response to receiving the validation result, wherein the notification screen indicates an outcome of the validation result. 
     
     
         13 . The system of  claim 10 , wherein the seed OTP is received with an authorization payload including at least one of a service identifier, a purpose, a time, a date, a merchant identifier, or an amount for the requested service. 
     
     
         14 . The system of  claim 10 , wherein the response OTP is transmitted from the user device via a text message. 
     
     
         15 . The system of  claim 10 , wherein the service request is transmitted over a first communication channel to the service provider and the seed OTP is received over a second communication channel from the service provider. 
     
     
         16 . The system of  claim 10 , wherein the seed OTP comprises a random number of at least 128 bytes in length. 
     
     
         17 . A non-transitory computer-readable medium having instructions stored thereon that, in response to execution by a computer-based system, cause the computer-based system to perform operations comprising:
 transmitting, by the computer-based system, a service request to a service provider, wherein the service request includes a device identifier of the computer-based system or a device fingerprint of the computer-based system;   receiving, by the computer-based system, a seed one-time password (OTP) to the computer-based system from the service provider, wherein the seed OTP comprises a random number that is valid for a predetermined time period and is discarded after first use;   calculating, by the computer-based system, a one-time password (OTP) by applying a hash function to the seed OTP, wherein the hash function is based on the device identifier of the computer-based system or the device fingerprint of the computer-based system;   transmitting, by the computer-based system, a response OTP generated by the computer-based system to the service provider for validation by the service provider, wherein the response OTP is different from the seed OTP; and   receiving, by the computer-based system, a validation result from the service provider, wherein the seed OTP is discarded after receipt of the validation result.   
     
     
         18 . The non-transitory computer-readable medium of  claim 17 , wherein the response OTP is generated in response to an integrity module confirming that the computer-based system is in good health based on the seed OTP being passed to a security utilities software development kit (SDK) on the user device. 
     
     
         19 . The non-transitory computer-readable medium of  claim 17 , wherein the seed OTP is received with an authorization payload including at least one of a service identifier, a purpose, a time, a date, a merchant identifier, or an amount for the requested service. 
     
     
         20 . The non-transitory computer-readable medium of  claim 17 , wherein the service request is transmitted over a first communication channel to the service provider and the seed OTP is received over a second communication channel from the service provider.

Join the waitlist — get patent alerts

Track US2021320913A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.