IP Library Granted Patent US 8,296,562
Granted Patent B2
US 8,296,562 · App. 12/434,442 · Granted Oct 23, 2012

Out of band system and method for authentication

Assignee: Anakam, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,296,562
App. No.
12/434,442
Granted
Oct 23, 2012
Kind
B2
Abstract

A method and system for out of band authentication for ensuring a user is in possession of a device.

Claims (41)

1. A method for authentication of a user with a device who is attempting a first transaction comprising the steps of:

establishing the asserted identity of the user;

informing an authentication server that the user is attempting to conduct a transaction;

conducting a second transaction with the user's device and the authentication server to verify that the user is in possession of the device, wherein the second transaction comprises:

providing, via an out of band channel used for establishing the asserted identify of the user, an authentication notification message indicating that the transaction is being conducted and prompting entry of a token, and

receiving, via the out of band channel, the token;

in response to receiving the token, sending an out of band one-time passcode to the device registered to the user;

entering the one-time passcode into the dialogue;

validating the one-time passcode; and

authorizing the first transaction.

2. The method of claim 1 , further comprising providing, at the device, an application to verify that the user is in possession of the device.

3. The method of claim 2 , wherein conducting the second transaction further comprises receiving a secure message from the application verifying that the user is in possession of the device is in the authentication server.

4. The method of claim 1 wherein the transaction is authorized via the release of a symmetric key representative of the individual conducting the transaction.

5. The method of claim 4 wherein the key is representative of the server on which the transaction was conducted, and can be tied to the unique user through non-repudiatory log and audit capabilities.

6. The method of claim 1 wherein the transaction is authorized via the release of an asymmetric key representative of the individual conducting the transaction.

7. The method of claim 6 wherein the key is representative of the server on which the transaction was conducted, and can be tied to the unique user through non-repudiatory log and audit capabilities.

8. The method of claim 1 wherein the out of band passcode is distributed to the end-user's pre-registered device via SMS (text messaging).

9. The method of claim 1 wherein the out of band passcode is distributed to the end-user's pre-registered device via voice.

10. The method of claim 1 wherein the out of band passcode is retrieved by the end-user through the use of their pre-registered voice signature and voice biometrics.

11. A method for authentication of a user with a device who is attempting a transaction comprising the steps of:

establishing the asserted identity of the user;

receiving, via an out of band channel used for establishing the asserted identity of the user, a secure message from an application provided at the device verifying that the user is in possession of the device;

sending an out of band one-time passcode to the device registered to the user;

validating the one-time passcode; and

authorizing the transaction via the release of a key,

wherein the key (i) is symmetric or asymmetric, (ii) is representative of the individual conducting the transaction and the server on which the transaction was conducted, and (iii) can be tied to the unique user through non-repudiatory log and audit capabilities.

12. The method of claim 11 , further comprising providing the application at the device, wherein the application provides the secure message based on verifying a token.

13. The method of claim 11 , wherein the secure message is received a channel other than a second channel used for establishing the asserted identify of the user.

14. A method for authentication of a user with a device who is attempting a first transaction comprising the steps of:

establishing the asserted identity of the user;

conducting a second transaction with the user's device and the authentication server to verify that the user is in possession of the device, wherein the second transaction comprises

providing, via an out of band channel used for establishing the asserted identify of the user, an authentication notification message to the device indicating that the transaction is being conducted and prompting entry of a token,

receiving, via the out of band channel, the token, and

receiving a secure message from an application provided at the device verifying that the user is in possession of the device;

sending an out of band one-time passcode to the device registered to the user; and

entering the one-time passcode into the dialogue to authorize the transaction.

15. The method of claim 14 , further comprising providing the application at the device to verify that the user is in possession of the device.

16. The method of claim 14 wherein the transaction is authorized via the release of a symmetric key representative of the individual conducting the transaction.

17. The method of claim 16 wherein the key is representative of the server on which the transaction was conducted, and can be tied to the unique user through non-repudiatory log and audit capabilities.

18. The method of claim 14 wherein the transaction is authorized via the release of an asymmetric key representative of the individual conducting the transaction.

19. The method of claim 18 wherein the key is representative of the server on which the transaction was conducted, and can be tied to the unique user through non-repudiatory log and audit capabilities.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2010
From: WILLIAMS, JEFFREY B.; CAMAISA, ALLAN
To: ANAKAM, INC.
Reel/Frame 025058/0075 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2010
From: TORREY PINES BANK
To: ANAKAM, INC.; ANAKAM INFORMATION SOLUTIONS, LLC
Reel/Frame 024964/0831 →
SECURITY AGREEMENT Recorded Jul 14, 2009
From: ANAKAM, INC.; ANAKAM INFORMATION SOLUTIONS, LLC
To: TORREY PINES BANK
Reel/Frame 022955/0099 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2009
From: WILLIAMS, JEFFREY B.; CAMAISA, ALLAN
To: ANAKAM, INC.
Reel/Frame 022890/0920 →
Continuity (5)
Continuation In Part 11824694 · Jul 2, 2007
Continuation In Part 11257421 · Oct 24, 2005
Continuation In Part 11077948 · Mar 11, 2005
Continuation In Part 10892584 · Jul 15, 2004
Related Publication 20090259848A1 · Oct 15, 2009