IP Library Granted Patent US 8,751,801
Granted Patent B2
US 8,751,801 · App. 11/112,938 · Granted Jun 10, 2014

System and method for authenticating users using two or more factors

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,751,801
App. No.
11/112,938
Granted
Jun 10, 2014
Kind
B2
Abstract

A method for authenticating a user based on a plurality of authentication factors includes a step of receiving a first authentication factor from a first communication device of the user. The first authentication factor includes a password. The method includes a step of receiving a second authentication factor. The second authentication factor comprises at least one of at least one device identifier of the first communication device of the user and data transmitted to or received from a second communication device of the user. The method also includes a step of authenticating the user based on at least the received plurality of authentication factors.

Claims (43)

1. A method for authenticating a user by a system based on a plurality of authentication factors, the method comprising the steps of:

receiving by the system a first authentication factor from a first communication device of the user, the first authentication factor comprising a password;

receiving by the system a second authentication factor, the second authentication factor comprising data transmitted to or received from a second communication device of the user; and

authenticating the user based on at least the received plurality of authentication factors;

wherein the second authentication factor comprises at least one of:

data transmitted by the system to the first communication device of the user and received by the system from the second communication device of the user; and

data transmitted by the system to the second communication device of the user and received by the system from the first communication device of the user.

2. The method of claim 1 , wherein the second authentication factor comprises data transmitted by the system to the first communication device of the user and received by the system from the second communication device of the user.

3. The method of claim 1 , wherein the second authentication factor comprises data transmitted by the system to the second communication device of the user and received by the system from the first communication device of the user.

4. The method of claim 1 , wherein the second authentication factor comprises data transmitted in a text message to the second communication device of the user.

5. The method of claim 1 , wherein the second authentication factor comprises data received in a text message from the second communication device of the user.

6. The method of claim 1 , wherein the second authentication factor comprises data transmitted in a voice message to the second communication device of the user.

7. The method of claim 1 , wherein the second authentication factor comprises data received in a voice message from the second communication device of the user.

8. The method of claim 1 , wherein the data comprises a uniform resource locator.

9. The method of claim 2 , wherein the second authentication factor comprises data output to the user by the first communication device of the user and input by the user into the second communication device of the user.

10. The method of claim 3 , wherein the second authentication factor comprises data output to the user by the second communication device of the user and input by the user into the first communication device of the user.

11. The method of claim 8 , wherein the uniform resource locator is uniquely associated with the user.

12. The method of claim 7 , further comprising the step of obtaining a third authentication factor by performing voice recognition on the voice message.

13. The method of claim 1 , wherein the second authentication factor comprises a generated shared secret.

14. A method for authenticating a user based on a plurality of authentication factors, the method comprising the steps of:

receiving a first authentication factor from a first communication device of the user, the first authentication factor comprising a password;

receiving a second authentication factor from the user, the second authentication factor comprising a device identifier of the first communication device of the user; and

authenticating the user based on at least the received plurality of authentication factors;

wherein the step of receiving a second authentication factor from the user comprises the steps of:

determining whether the first communication device has a device identifier stored therein;

if the first communication device has a device identifier stored therein, receiving the device identifier of the first communication device; and

if the first communication device does not have a device identifier stored therein:

transmitting data to the second communication device of the user, and

receiving back the data transmitted to the second communication device of the user.

15. The method of claim 14 , wherein at least a portion of the device identifier is stored on the first communication device of the user as at least one of a secure cookie or a Flash shared object.

16. The method of claim 15 , wherein the stored portion of the device identifier is modified upon each authentication of the user.

17. An apparatus for authenticating a user based on a plurality of authentication factors, the apparatus comprising:

a memory; and

a processor coupled to the memory and operative to control the apparatus:

to receive a first authentication factor from a first communication device of the user, the first authentication factor comprising a password;

to receive a second authentication factor, the second authentication factor comprising data transmitted to or received from a second communication device of the user; and

to authenticate the user based on at least the received plurality of authentication factors;

wherein the second authentication factor comprises at least one of:

data transmitted by the system to the first communication device of the user and received by the system from the second communication device of the user; and

data transmitted by the system to the second communication device of the user and received by the system from the first communication device of the user.

18. The apparatus of claim 17 , wherein said apparatus comprises a web server.

19. The apparatus of claim 17 , wherein the second authentication factor comprises data transmitted to the first communication device of the user and received from the second communication device of the user.

20. The apparatus of claim 17 , wherein the second authentication factor comprises data transmitted to the second communication device of the user and received from the first communication device of the user.

Assignments (14)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023975/0453 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023975/0151 →
MERGER Recorded Jan 27, 2010
From: RSA SECURITY INC
To: RSA SECURITY LLC
Reel/Frame 023852/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023824/0729 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023825/0109 →
MERGER Recorded Nov 2, 2006
From: PASSMARK SECURITY, INC., A DELAWARE CORPORATION
To: RSA SECURITY INC.
Reel/Frame 018481/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2005
From: HARRIS, WILLIAM H.; GASPARINI, LOUIS A.
To: PASSMARK SECURITY, INC.
Reel/Frame 016880/0420 →