IP Library Granted Patent US 9,325,702
Granted Patent B2
US 9,325,702 · App. 14/330,025 · Granted Apr 26, 2016

Method for secure user and transaction authentication and risk management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,325,702
App. No.
14/330,025
Granted
Apr 26, 2016
Kind
B2
Abstract

To provide a user signature on a network transaction, a security server receives transaction information representing a transaction between a network user and a network site, such as a website, directly from the network site. The security server calculates a one-time-password based on the received transaction information and a secret shared by the security server and the network site, but not by the user. The security server transmits the calculated one-time-password for application as the user's signature on the transaction. The one-time-password is independently calculable by the network site based on the shared secret.

Claims (15)

1. A method of providing a user signature on a network transaction, comprising: receiving, by a security server directly from a network site, transaction information representing a transaction between a network user and a network site; calculating, by the security server, a one-time-password based on (i) the received transaction information and (ii) a secret shared by the security server and the network site, but not by the user, wherein the one-time-password is independently calculable by the network site based on the shared secret and the transaction information; and transmitting, by the security server, the calculated one-time-password for application as the user's signature on the transaction and verification by the network site,

wherein the calculated one-time-password is transmitted, by the security server to a user network device for presentation on a window displayed by the user network device and entry by the user onto a network page associated with the network site and displayed on another user network device.

2. The method of claim 1 , wherein: the network site is a web site.

3. The method of claim 1 , further comprising: storing, at the security server, a log of transactions between the user and the network site.

4. The method of claim 3 , further comprising: computing, by the security server, a risk profile of the user based on the stored transactions log.

5. The method of claim 3 , further comprising: transmitting, by the security server to a third party, the stored transactions log for risk analysis.

6. The method of claim 1 , wherein the shared secret is not associated with any particular user.

7. A method of validating a user signature on a network transaction, comprising: receiving, by a network site from a user network device, transaction information representing a transaction between a user and the network site; transmitting, by the network site directly to a security server, the transaction information; receiving, by the network site from the user network device, a one-time-password as the user's signature on the transaction; calculating, by the network site, a one-time-password based on (i) the received transaction information and (ii) a secret shared by a security server and the network site, but not by the user;

transmitting, by the security server, the calculated one-time-password to a user network device for presentation on a window displayed by the user network device and entry by the user onto a network page associated with the network site and displayed on another user network device; and

verifying, by the network site, the signature based on a comparison of the received one-time-password and the calculated one-time-password.

8. The method of claim 7 , wherein the shared secret is not associated with any particular user.

9. A method of authenticating a user on a network, comprising: transmitting, by a network site directly to a security server, a request to have a user authenticated; receiving, by the network site from a network device of the user, a one-time-password; calculating, by the network site, a one-time-password based on a secret shared by the security server and the network site, but not by the user;

transmitting, by the security server, the calculated one-time-password to a user network device for presentation on a window displayed by the user network device and entry by the user onto a network page associated with the network site and displayed on another user network device; and

comparing, by the network site, the received one-time-password and the calculated one-time-password to authenticate the user.

10. The method of claim 9 , wherein the shared secret is not associated with any particular user.

Assignments (11)
CHANGE OF NAME Recorded Mar 20, 2025
From: PAYFONE, INC.
To: PROVE IDENTITY, INC.
Reel/Frame 070572/0570 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2020
From: EARLY WARNING SERVICES, LLC
To: PAYFONE, INC.
Reel/Frame 053148/0191 →
CONFIRMATORY GRANT OF SECURITY INTEREST IN PATENTS Recorded Jun 18, 2020
From: PAYFONE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 052984/0061 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME FROM AUTHENTIFY INC. TO AUTHENTIFY, INC. PREVIOUSLY RECORDED ON REEL 052380 FRAME 0134. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF ASSIGNORS INTEREST. Recorded Apr 20, 2020
From: HAWK AND SEAL INC.
To: AUTHENTIFY, INC.
Reel/Frame 052438/0930 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF THE RECEIVING PARTY ON THE RELEASE OF SECURITY INTEREST AGREEMENT FROM AUTHENTIFY INC. TO AUTHENTIFY, INC. PREVIOUSLY RECORDED ON REEL 037147 FRAME 0213. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Apr 20, 2020
From: JMI SERVICES, LLC
To: AUTHENTIFY, INC.
Reel/Frame 052448/0075 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2020
From: GANESAN, RAVI
To: HAWK AND SEAL INC.
Reel/Frame 052381/0878 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2020
From: HAWK AND SEAL INC.
To: AUTHENTIFY INC.
Reel/Frame 052380/0134 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR NAME PREVIOUSLY RECORDED AT REEL: 041610 FRAME: 0944. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Aug 23, 2017
From: AUTHENTIFY, LLC
To: EARLY WARNING SERVICES, LLC
Reel/Frame 043649/0549 →
MERGER AND CHANGE OF NAME Recorded Jul 25, 2017
From: AUTHENTIFY, INC.; AUTHENTIFY, LLC
To: AUTHENTIFY, LLC
Reel/Frame 043325/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2017
From: AUTHENTIFY, INC.
To: EARLY WARNING SERVICES, LLC
Reel/Frame 041610/0944 →
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2015
From: JMI SERVICES , LLC
To: AUTHENTIFY, INC.
Reel/Frame 037147/0213 →