IP Library Granted Patent US 8,560,457
Granted Patent B2
US 8,560,457 · App. 11/541,279 · Granted Oct 15, 2013

Enhanced network server authentication using a physical out-of-band channel

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,560,457
App. No.
11/541,279
Granted
Oct 15, 2013
Kind
B2
Abstract

Systems and methods for increasing user trust by authenticating an electronic commerce server over an electronic communications channel using information received through an out-of-band communication in a physical communications channel are described. In one configuration, a paper bill is sent to a user by physical mail delivery and it includes challenge and response data used to authenticate the electronic commerce server over the electronic communications channel.

Claims (20)

1. A computer implemented for authenticating a web site by a user using an in-band electronic communications channel and authentication comprising:

receiving a physical communication including web site authentication data including challenge data and response data through an out-of-band physical delivery communications channel;

then connecting a user client running on the computer to the web site; then, by using the user client, sending the challenge data to the web site using the in-band electronic communications channel, wherein the user does not provide authentication information to the web site before sending the challenge data; then receiving reply response data from the web site using the user client and the in-band electronic communications channel; and

displaying by the user client the reply response data for authenticating the website.

2. The method of claim 1 wherein the out-of-band physical delivery channel is the United States Postal Service system, and wherein the challenge data comprises the delivery location of the physical communication.

3. The method of claim 1 wherein the web site is controlled by an entity and the communication is a statement from the web site controlling entity and wherein the challenge data comprises the delivery date of the physical communication.

4. The method of claim 1 wherein the web site is controlled by a first entity and the physical communication is a statement from a financial institution including a charge from the web site controlling entity, wherein the physical communication response data is printed near the charge, and

wherein the communication further includes second challenge data and second response data associated with a second entity having a second website and wherein the financial institution is a third entity.

5. The method of claim 1 wherein the communication includes communication authentication indications.

6. A computer implemented method for providing web site authentication data to a user in response to a challenge from the user using an in-band electronic communications channel comprising:

sending a physical communication including web site authentication data including challenge data and response data through an out-of-band physical delivery communications channel to the user;

then receiving a challenge selected from the challenge data from the user through the in-band communications channel using the computer, wherein the user does not provide authentication information to the web site before sending the challenge data;

then determining, using the computer, the appropriate response data associated with the challenge authentication data received from the user; and

then sending, using the computer, the determined reply response data to the user using the in-band electronic communications channel.

7. The method of claim 6 wherein the out-of-band delivery channel is the United States Postal Service system, and wherein the challenge data comprises the delivery location of the physical communication.

8. The method of claim 6 wherein the web site is controlled by an entity and the communication is a statement from the web site controlling entity, and wherein the challenge data comprises the delivery date of the physical communication.

9. The method of claim 6 wherein the web site is controlled by a first entity and the physical communication is a statement from a financial institution including a charge from the web site controlling entity, wherein the physical communication response data is printed near the charge, and wherein the communication further includes second challenge data and second response data associated with a second entity having a second website and wherein the financial institution is a third entity.

10. The method of claim 6 further comprising:

obtaining pre-computed response data associated the challenge from a third party for use in providing reply response data in response to the challenge.

11. The method of claim 6 , further comprising, then authenticating the user wherein the user is authenticated to the web site.

Assignments (3)
RELEASE OF PATENT SECURITY AGREEMENT Recorded Feb 19, 2025
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: PITNEY BOWES, INC.
Reel/Frame 070256/0396 →
SECURITY INTEREST Recorded Nov 1, 2019
From: PITNEY BOWES INC.; NEWGISTICS, INC.; BORDERFREE, INC.; TACIT KNOWLEDGE, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 050905/0640 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2006
From: OBREA, ANDREI; PARKOS, ARTHUR J.; HANSEN, GARY G.; CAMPAGNA, MATTHEW J.; MACDONALD, GEORGE M.
To: PITNEY BOWES INC.
Reel/Frame 018719/0252 →