IP Library Granted Patent US 9,338,156
Granted Patent B2
US 9,338,156 · App. 14/188,480 · Granted May 10, 2016

System and method for integrating two-factor authentication in a device

Inventors: Jon Oberheide (Ann Arbor, MI); Douglas Song (Ann Arbor, MI)
Assignee: Duo Security, Inc.
H04L63/08G06F21/40H04L63/18H04W12/06H04L63/0853H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,338,156
App. No.
14/188,480
Granted
May 10, 2016
Kind
B2
Abstract

A system and method for providing secondary-factor authentication with a third party application that can include enrolling a device application instance of an account into a secondary-factor authentication service on behalf of a service provider that includes at the secondary-factor authentication service, receiving a secondary factor of authentication enrollment request of an account, the request received from the service provider, transmitting an activation code, and pairing the device application instance with the account through the activation code; receiving an authentication request identifying the account; transmitting an authentication request to the device application instance paired with the account; validating a response to the application request; and transmitting an assessment to the service provider.

Claims (29)

1. A method for providing secondary-factor authentication with a third party application, the method comprising:

enrolling a device application instance of an account into a secondary-factor authentication service on behalf of a service provider comprising:

at server of the secondary-factor authentication service, receiving a secondary factor of authentication enrollment request of an account, the request received from the service provider,

the secondary-factor authentication service transmitting an activation code to the service provider, and

at a database of the secondary-factor authentication service, pairing the device application instance with the account in response to device application processing of the activation code;

receiving an authentication request identifying the account;

transmitting an authentication request to the device application instance paired with the account;

validating a response to the application request; and

transmitting an assessment to the service provider;

wherein the activation code is an activation universal resource identifier (URI); and wherein pairing the device application instance with the account through the activation code comprises pairing the device application instance with the account in response to the device application instance accessing the activation URI.

2. The method of claim 1 , further comprising encoding the activation URI into a computer recognizable code and transmitting the computer recognizable code to the service provider.

3. The method of claim 1 , further comprising providing a secondary-factor authentication software development kit; at the secondary-factor authentication software development kit, enrolling a coupled device application instance and processing an authentication request received from the secondary-factor authentication service.

4. The method of claim 3 , further comprising configuring the service provider with software development kit credentials; and in the secondary-factor authentication software development kit, cryptographically securing the response to the authentication request.

5. The method of claim 3 , further comprising providing a background device application, wherein the secondary-factor authentication software development kit is configured to direct authentication request processing operations to the background device application, and at the background device application, validating the authentication request and transmitting the response to the secondary-authentication service.

6. The method of claim 1 , further comprising providing a secondary device application; receiving the authentication request at the secondary application from the device application; and at the secondary device application, validating the authentication request, rendering an interface according to customization directives of the device application, transmitting the response to the secondary-authentication service, and redirecting application focus in a modular operating system to the device application.

7. A method for using an authentication service comprising:

enrolling a device application instance of an account into an authentication service on behalf of a service provider, the method comprising:

at a server of the service platform, receiving an activation code of an authentication enrollment request,

facilitating transfer of the activation code to the device application instance, and

at the device application instance, communicating to the authentication service by processing the activation code, wherein processing the activation code successfully pairs the device application instance with an account on the authentication service;

at the service platform, completing a primary authentication of the account and transmitting an authentication request to a factor authentication service, wherein the authentication request identifies the account;

at the device application instance, receiving the authentication request;

at the device application instance, validating the authentication;

at the device application instance, rendering an authentication interface and receiving a user selected response option;

at the device application, transmitting a response to the authentication service according to the user selected response option;

at the service platform, receiving an assessment of the service providers;

wherein the activation code is an activation universal resource identifier (URI); and wherein communicating to the authentication service comprises communicating device addressing information to the activation URI.

8. The method of claim 7 , wherein at the device application, validating the authentication comprises validating the authentication request through a software development kit of the authentication service.

9. The method of claim 7 , wherein the activation URI is a computer recognizable code; and further comprising at the device application, reading the computer recognizable code.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2021
From: DUO SECURITY LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056208/0504 →
CHANGE OF NAME Recorded May 11, 2021
From: DUO SECURITY, INC.
To: DUO SECURITY LLC
Reel/Frame 056210/0008 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2016
From: OBERHEIDE, JON; SONG, DOUGLAS
To: DUO SECURITY, INC.
Reel/Frame 038223/0147 →
Continuity (2)
Provisional Application 61768248 · Feb 22, 2013
Related Publication 20140245396A1 · Aug 28, 2014