IP Library Granted Patent US 8,893,237
Granted Patent B2
US 8,893,237 · App. 14/268,280 · Granted Nov 18, 2014

Secure and efficient login and transaction authentication using iphones# and other smart mobile communication devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,893,237
App. No.
14/268,280
Granted
Nov 18, 2014
Kind
B2
Abstract

To authenticate a user of a mobile communication device for login or transaction authorization, a first application on the device directs transmission of a request for authentication of the user to a security server. A second application on the device receives the request for authentication from the security server and directs presentation of the received request for authentication to the user by the device. The second application receives a user input to the device indicating that the requested authentication should proceed and in response directs transmission of an indication that the requested authorization should proceed, to the security server. In response to this latter transmission, the second application receives a PIN from the authentication server. The first application directs transmission of the PIN received by the second application to the network site, which validates the transmitted PIN, in order to authenticate the user or the transaction to the network site.

Claims (78)

1. A method of authenticating a user of a mobile communication device, comprising:

directing, by a first program executing on the mobile communication device, transmission, from the mobile communication device to a security server, of a request for authentication of the user in connection with either (i) the user logging into or (ii) the user entering into a transaction with a network site;

receiving, by a second program executing on the mobile communication device, the request for authentication from the security server;

directing, by the second program, presentation by the mobile communication device of the received request for authentication to the user;

receiving, by the second program, a user input to the mobile communication device indicating that the requested authentication should proceed;

directing, by the second program in response to the received user input, transmission, from the mobile communication device to the security server, of an indication that the requested authorization should proceed;

receiving, by the second program from the security server, a personal identification number (PIN), in response to the transmission of the indication that the requested authorization should proceed;

automatically storing, by the second program, the received PIN in a public data store within the mobile communications device;

automatically retrieving, by the first program, the stored PIN from the public data store; and

directing, by the first program, transmission, from the mobile communications device to the network site, of the retrieved PIN, to authenticate the user or transaction to the network site.

2. The method according to claim 1 , wherein:

the mobile communication device is a smart phone.

3. The method according to claim 1 , further comprising:

storing, by the second program in the public data store, information indicating either that an active session exist or does not exist between the second program and the security server;

receiving, by the first program, a request of the user to access the network site or to enter into a transaction with the network site; and

determining, by the first program based on the stored active session information, whether or not an active session exist;

wherein the first program directs transmission, from the mobile communications device to a security server, of the request for authentication of the user only if it is determined that an active session exist.

4. The method according to claim 3 , wherein the stored information indicating either that an active session exists or does not exist includes a random number and a time-to-live (TTL), and further comprising:

receiving, by the second program from the security server, a new random number and a new TTL with the PIN, in response to the transmission of the indication that the requested authorization should proceed; and

storing, by the second program in the public data store, the new random number and the new TTL as current information indicating either that an active session exist or does not exist between the second program and the security server.

5. The method according to claim 1 , wherein the PIN corresponds to a secret shared only by the security server and the network site, and not by the user.

6. The method according to claim 1 , further comprising:

receiving, by the second program, a request of the user to login to the security server;

directing, by the second program, transmission of the request and a user identifier from the mobile communication device to the security server;

receiving, by a third program executing on the mobile communication device from the security server, a message including another PIN, in response to the transmitted request;

directing, by the third program, display, by the mobile communication device, of the other PIN;

receiving, by the second program, another user input including the displayed other PIN;

directing, by the second program, transmission, from the mobile communication device to the security server, of the received input other PIN;

receiving, by the second program from the security server, a session cookie and active session information indicating a period of time during which the session between the second program and the security server will remain active, in response to the transmission of the other PIN; and

storing, by the second program, (i) the session cookie in a private data store accessible only to the second program and (ii) the active session information in the public data store so as to be accessible to the first and the second programs.

7. An article of manufacture for authenticating a user of a mobile communication device, comprising:

non-transitory processor readable storage medium; and

a program stored on the storage medium, wherein the stored program is configured to be readable by a processor and thereby cause the processor to operate so as to:

receive, from a security server, a request for authentication of the user in connection with either (i) the user logging into or (ii) the user entering into a transaction with a network site;

direct a display, by the mobile communication device, of the received request for authentication;

receive a user input to the mobile communication device indicating that the requested authentication should proceed;

direct, in response to the received user input, transmission, from the mobile communication device to the security server, of an indication that the requested authorization should proceed;

receive, from the security server, a personal identification number (PIN), in response to the transmission of the indication that the requested authorization should proceed; and

automatically store the received PIN in a public data store within the mobile communications device so as to be available to another program executable by the mobile communications device, to thereby facilitate transmission of the received PIN from the mobile communication device to the network site to thereby authenticate the user or the transaction to the network site.

8. The article of manufacture according to claim 7 , wherein the stored program is further configured to cause the processor to operate so as to:

store, in the public data store, information indicating either that an active session exist or does not exist between the stored program and the security server;

wherein the request for authentication is only received from the security server if the stored information indicates that an active session exist.

9. The article of manufacture according to claim 8 , wherein the stored information indicating either that an active session exist or does not exist includes a random number and a time-to-live (TTL), and the stored program is further configured to cause the processor to operate so as to:

receive, from the security server, a new random number and a new TTL with the PIN; and

store, in the public data store, the new random number and the new TTL as current information indicating either that an active session exist or does not exist between the stored program and the security server.

10. The article of manufacture according to claim 7 , wherein the PIN corresponds to a secret shared only by the security server and the network site, and not by the user.

11. The article of manufacture according to claim 7 , wherein the stored program is further configured to cause the processor to operate so as to:

receive a request of the user to login to the security server;

direct transmission of the request and a user identifier from the mobile communication device to the security server;

receive another user input including another PIN;

direct transmission, from the mobile communication device to the security server, of the received other PIN;

receive, from the security server, a session cookie and active session information indicating a period of time during which the session between the program and the security server will remain active, in response to the transmission of the received other PIN; and

store (i) the received session cookie in a private data store accessible only to the program and (ii) the active session information in the public data store so as to be accessible to other programs executable by the mobile communication device.

12. A mobile communication device for authenticating a user, comprising:

a security program;

another program;

a public data store;

a display;

a user input device; and

a processor configured to (1) execute the other program to direct transmission, from the mobile communication device to a security server, of a request for authentication of the user in connection with either (i) the user logging into or (ii) the user entering into a transaction with a network site, (2) execute the security program to (a) receive the request for authentication from the security server, (b) direct presentation of the received request for authentication on the display, (c) receive a user input from the user input device indicating that the requested authentication should proceed, (d) direct, to the security server in response to the received user input, transmission of an indication that the requested authorization should proceed, (e) receive, from the security server in response to the transmission of the indication that the requested authorization should proceed, a personal identification number (PIN), and (f) automatically store the received PIN in the public data store, and (3) execute the other program to (a) automatically retrieve the stored PIN from the public data store, and (b) direct transmission, to the network site, of the retrieved PIN to authenticate the user or transaction to the network site.

13. The mobile communications device according to claim 12 , wherein:

the processor is further configured to (1) execute the security program to store, in the public data store, information indicating either that an active session exist or does not exist between the security program and the security server, (2) execute the other program to (a) direct transmission of a request of the user to access the network site or to enter into a transaction with the network site, and (b) determine based on the stored active session information, whether or not an active session exist;

the process executes the other program to direct transmission, to a security server, of the request for authentication of the user only if it is determined that an active session exist.

14. The mobile communications device according to claim 13 , wherein:

the stored information indicating either that an active session exists or does not exist includes a random number and a time-to-live (TTL);

the processor is further configured to execute security program to (a) receive, from the security server in response to the transmission of the indication that the requested authorization should proceed, a new random number and a new TTL with the PIN, and (b) store, in the public data store, the new random number and the new TTL as current information indicating either that an active session exist or does not exist between the security program and the security server.

15. The mobile communications device according to claim 12 , wherein the PIN corresponds to a secret shared only by the security server and the network site, and not by the user.

16. The mobile communications device according to claim 12 , further comprising:

at least one of a voice, mail or text messaging program; and

a private data store;

wherein the processor is further configured to execute (1) the security program to (a) received a user input to the user input device representing request of the user to login to the security server, and (b) direct transmission of the received request and a user identifier to the security server, (2) execute the at least one program to (a) receive, from the security server, a message including another PIN, in response to the transmitted request, and (b) direct presentation to the user on the display, of the other PIN, and (3) execute the security program to (a) receive another user input to the user input device representing the displayed other PIN, (b) direct transmission, to the security server, of the other PIN represented in the received other user input, (c) receive, from the security server in response to the transmission of the other PIN, a session cookie and active session information indicating a period of time during which the session between the security program and the security server will remain active, and (d) store (i) the session cookie in the private data store accessible only to the security program and (ii) the active session information in the public data store so as to be accessible to the security program and the other program.

17. A security server for authenticating a user of a mobile communications device, comprising:

a communications port; and

a processor configured to (1) receive, from a first program executing on the mobile communication device via the communications port, a request for authentication of the user in connection with either (i) the user logging into or (ii) the user entering into a transaction with the network site, (2) direct transmission, to a second program executing on the mobile communication device via the communications port, of the received request for authentication (3) receive, from the second program via the communications port, an indication that the requested authorization should proceed, and (4) direct transmission, to the second program via the communications port, of a personal identification number (PIN), in response to the received indication that the requested authorization should proceed and to authenticate the user to the network site.

18. The security server according to claim 17 , wherein the security server is further configured to receive the request for authentication of the user from the first program only if an active session exist between the second program and the security server.

19. The security server according to claim 17 , wherein the PIN corresponds to a secret shared only by the security server and the network site, and not by the user.

20. The security server according to claim 17 , wherein:

the processor is further configured to (1) receive, from the second program via the communications port, a request of the user to login to the security server, (2) direct transmission, to a third program executing on the mobile communication device, of a message including another PIN, in response to the received login request, (3) receive, from the second program via the communications port, the transmitted other PIN, (4) authenticate the user based on the received other PIN, and (5) direct transmission, to the second program via the communications port, of a session cookie and active session information indicating a period of time during which the session will remain active, based on the authentication of the user.

Assignments (10)
CHANGE OF NAME Recorded Mar 13, 2025
From: PAYFONE, INC.
To: PROVE IDENTITY, INC.
Reel/Frame 070499/0580 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2020
From: EARLY WARNING SERVICES, LLC
To: PAYFONE, INC.
Reel/Frame 053148/0191 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME FROM AUTHENTIFY INC. TO AUTHENTIFY, INC. PREVIOUSLY RECORDED ON REEL 052380 FRAME 0134. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF ASSIGNORS INTEREST. Recorded Apr 20, 2020
From: HAWK AND SEAL INC.
To: AUTHENTIFY, INC.
Reel/Frame 052438/0930 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF THE RECEIVING PARTY ON THE RELEASE OF SECURITY INTEREST AGREEMENT FROM AUTHENTIFY INC. TO AUTHENTIFY, INC. PREVIOUSLY RECORDED ON REEL 037147 FRAME 0213. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Apr 20, 2020
From: JMI SERVICES, LLC
To: AUTHENTIFY, INC.
Reel/Frame 052448/0075 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2020
From: HAWK AND SEAL INC.
To: AUTHENTIFY INC.
Reel/Frame 052380/0134 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2020
From: GANESAN, RAVI
To: HAWK AND SEAL INC.
Reel/Frame 052378/0653 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR NAME PREVIOUSLY RECORDED AT REEL: 041610 FRAME: 0944. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Aug 23, 2017
From: AUTHENTIFY, LLC
To: EARLY WARNING SERVICES, LLC
Reel/Frame 043649/0549 →
MERGER AND CHANGE OF NAME Recorded Jul 25, 2017
From: AUTHENTIFY, INC.; AUTHENTIFY, LLC
To: AUTHENTIFY, LLC
Reel/Frame 043325/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2017
From: AUTHENTIFY, INC.
To: EARLY WARNING SERVICES, LLC
Reel/Frame 041610/0944 →
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2015
From: JMI SERVICES , LLC
To: AUTHENTIFY, INC.
Reel/Frame 037147/0213 →