IP Library Granted Patent US 9,130,929
Granted Patent B2
US 9,130,929 · App. 13/840,839 · Granted Sep 8, 2015

Systems and methods for using imaging to authenticate online users

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,130,929
App. No.
13/840,839
Granted
Sep 8, 2015
Kind
B2
Abstract

Systems and methods are disclosed for authenticating an identity of an online user. One method includes receiving from the user, through a first device, a request to access a web page associated with the user's online account; transmitting to the user an image that contains a unique ID and a URL of an authentication server; and receiving from the user, through the first device, an authentication request containing the unique ID. The method also includes receiving from the user, through a second device, a log-in ID associated with the user and the unique ID; and authenticating the identity of the user to grant the user access, through the first device, to the web page associated with the user's online account.

Claims (63)

1. A method for authenticating an identity of an online user, the method including:

receiving registration data of an online user, the registration data used to access a web page associated with the online user;

receiving, from a registration device, a request to access the web page associated with the online user;

transmitting, in response to the request to access the web page from the registration device, an image that contains a unique identifier (“ID”) and a uniform resource locator (“URL”) of an authentication server;

storing, by the authentication server, the unique ID in association with a session identifier (“ID”) and the registration data of the online user;

receiving, at the authentication server from the online user through a first device, an authentication request containing a digital certificate, the unique ID and a log-in identifier (“ID”);

authenticating, by the authentication server, the first device of the online user based on the digital certificate, the unique ID and the log-in ID;

associating the first device of the online user with the session ID stored in association with the registration data of the online user when the first user device is authenticated;

transmitting the web page associated with the online user to the first user device when the first user device is authenticated, the requested web page including an access number and a unique authentication code associated with the registration data of the online user;

receiving, at a voice recognition server associated with the access number, the unique authentication code associated with the registration data of the online user;

receiving, at the voice recognition server, a voice sample of the online user for authenticating the online user based on biometric matching; and

associating the voice sample of the online user with the registration data of the online user.

2. The method of claim 1 , wherein the registration device is one of a personal computer, a public computer, and a public kiosk, and the first device is a mobile device.

3. The method of claim 1 , wherein the image is a two-dimensional barcode or a quick response code.

4. The method of claim 1 , wherein the authentication request containing the unique ID is received upon the online user requesting the URL of the authentication server, and includes a request for notice of completed log-in for the unique ID.

5. The method of claim 1 , further comprising:

providing the online user with a mobile application enabling the online user to extract the unique ID from the image, by taking a picture of a display of the registration device using a camera of the first device.

6. The method of claim 1 , further comprising:

storing, upon receiving the authentication request containing the unique ID, the unique ID in relation to a browser session ID of the registration device.

7. The method of claim 6 , further comprising:

looking up the browser session ID of the registration device based on the unique ID received from the user through the first device.

8. The method of claim 1 , further comprising:

sending the first device one of the digital certificate and access token storing a log-in ID of the online user.

9. The method of claim 8 , wherein the log-in ID of the online user and the unique ID are received from the online user within one of the digital certificate and access token.

10. The method of claim 1 , wherein the voice sample of the online user for authenticating the user based on biometric matching is received through one of an Internet connection and a public switched telephone network connection.

11. A system for authenticating an identity of an online user, the system including:

a data storage device for storing instructions for authenticating an identity of an online user; and

a processor configured to execute the instructions to perform a method including:

receiving registration data of an online user, the registration data used to access a web page associated with the online user;

receiving, from a registration device, a request to access the web page associated with the online user;

transmitting, in response to the request to access the web page from the registration device, an image that contains a unique identifier (“ID”) and a uniform resource locator (“URL”) of an authentication server;

storing, by the authentication server, the unique ID in association with a session identifier (“ID”) and the registration data of the online user;

receiving, at the authentication server from the online user through a first device, an authentication request containing a digital certificate, the unique ID and a log-in identifier (“ID”);

authenticating, by the authentication server, the first device of the online user based on the digital certificate, the unique ID and the log-in ID;

associating the first device of the online user with the session ID stored in association with the registration data of the online user when the first user device is authenticated;

transmitting the web page associated with the online user to the first user device when the first user device is authenticated, the requested web page including an access number and a unique authentication code associated with the registration data of the online user;

receiving, at a voice recognition server associated with the access number, the unique authentication code associated with the registration data of the online user;

receiving, at the voice recognition server, a voice sample of the online user for authenticating the online user based on biometric matching; and

associating the voice sample of the online user with the registration data of the online user.

12. The system of claim 11 , wherein the registration device is one of a personal computer, a public computer, and a public kiosk, and the first device is a mobile device.

13. The system of claim 11 , wherein the image is a two-dimensional barcode or a quick response code.

14. The system of claim 11 , wherein the authentication request containing the unique ID is received upon the online user requesting the URL of the authentication server, and includes a request for notice of completed log-in for the unique ID.

15. The system of claim 11 , wherein the processor is further configured to execute the instructions to perform the method including:

providing the online user with a mobile application enabling the online user to extract the unique ID from the image, by taking a picture of a display of the registration device using a camera of the first device.

16. The system of claim 11 , wherein the processor is further configured to execute the instructions to perform the method including:

storing, upon receiving the authentication request containing the unique ID, the unique ID in relation to a browser session ID of the registration device.

17. The system of claim 16 , wherein the processor is further configured to execute the instructions to perform the method including:

looking up the browser session ID of the registration device based on the unique ID received from the user through the first device.

18. The system of claim 11 , wherein the processor is further configured to execute the instructions to perform the method including:

sending the first device one of the digital certificate and access token storing a log-in ID of the online user.

19. The system of claim 18 , wherein the log-in ID of the online user and the unique ID are received from the online user within one of the digital certificate and access token.

20. A non-transitory computer-readable storage medium that, when executed by a computer system, cause the computer system to perform a method for authenticating an identity of an online user, the method including:

receiving registration data of an online user, the registration data used to access a web page associated with the online user;

receiving, from a registration device, a request to access the web page associated with the online user;

transmitting, in response to the request to access the web page from the registration device, an image that contains a unique identifier (“ID”) and a uniform resource locator (“URL”) of an authentication server;

storing, by the authentication server, the unique ID in association with a session identifier (“ID”) and the registration data of the online user;

receiving, at the authentication server from the online user through a first device, an authentication request containing a digital certificate, the unique ID and a log-in identifier (“ID”);

authenticating, by the authentication server, the first device of the online user based on the digital certificate, authentication request the unique ID and the log-in ID;

associating the first device of the online user with the session ID stored in association with the registration data of the online user when the first user device is authenticated;

transmitting the web page associated with the online user to the first user device when the first user device is authenticated, the requested web page including an access number and a unique authentication code associated with the registration data of the online user;

receiving, at a voice recognition server associated with the access number, the unique authentication code associated with the registration data of the online user;

receiving, at the voice recognition server, a voice sample of the online user for authenticating the online user based on biometric matching; and

associating the voice sample of the online user with the registration data of the online user.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2024
From: OATH INC.
To: VERIZON MEDIA INC.
Reel/Frame 066700/0001 →
CHANGE OF NAME Recorded Feb 28, 2024
From: AOL INC.
To: OATH INC.
Reel/Frame 066701/0736 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2021
From: VERIZON MEDIA INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 057453/0431 →
CHANGE OF NAME Recorded Feb 24, 2020
From: OATH (AMERICAS) INC.
To: VERIZON MEDIA INC.
Reel/Frame 051999/0720 →
CHANGE OF NAME Recorded Jun 30, 2017
From: AOL ADVERTISING INC.
To: OATH (AMERICAS) INC.
Reel/Frame 043072/0066 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS -RELEASE OF 030936/0011 Recorded Jul 1, 2015
From: JPMORGAN CHASE BANK, N.A.
To: AOL ADVERTISING INC.; AOL INC.; BUYSIGHT, INC.; MAPQUEST, INC.; PICTELA, INC.
Reel/Frame 036042/0053 →
SECURITY AGREEMENT Recorded Aug 2, 2013
From: AOL INC.; AOL ADVERTISING INC.; BUYSIGHT, INC.; MAPQUEST, INC.; PICTELA, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 030936/0011 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2013
From: DORFMAN, SCOTT; SENGPIEHL, DONALD P.
To: AOL INC.
Reel/Frame 030721/0126 →