IP Library Granted Patent US 10,404,685
Granted Patent B2
US 10,404,685 · App. 15/109,615 · Granted Sep 3, 2019

User security authentication system in internet and method thereof

Inventor: Jun Ho Cho (Seoul, KR)
Assignee: eBay Inc.
H04L63/083G06F3/0482G06F16/9535G06F21/31G06F21/46H04L9/3226H04L63/04G06F2221/2117
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,404,685
App. No.
15/109,615
Granted
Sep 3, 2019
Kind
B2
Abstract

The present invention relates to a user security authentication system in an Internet environment and a method therefor, which generate encrypted member authentication data by combining a member ID and a password selected when a user subscribes, as a member, to an arbitrary web service provider system with a unique code value of a security code selection module such that code complexity in a step of accessing the arbitrary web service provider system can be increased, and security can be simplified and reinforced.

Claims (50)

1. A system for user security authentication in an Internet environment, the system comprising:

one or more servers having one or more processing circuits and a non-transitory storage medium, the non-transitory storage medium having computer code that is executable by the one or more processing circuits to cause the system to:

receive a web service request from a device;

transmit, after receiving the web service request, a member authentication object, the member authentication object comprising:

a member identifier (ID) module, a password module, and a security code selection module, the security code selection module comprising a plurality of code selection display objects displayable on a webpage of the device, each code selection display object of the plurality of code selection display objects having a unique code value comprising at least two characters, at least one of the plurality of code selection display objects being preselected by a user of the device and associated with stored member authentication data of the user;

receive, after transmitting the member authentication object, encoded member authentication data, the encoded member authentication data comprising data encoded by combining a member ID, a password, and the unique code value of the at least one of the plurality of code selection display objects;

decode the received encoded member authentication data, and analytically compare the decoded member authentication data with the stored member authentication data to determine whether the user is authenticated as a member; and

provide, after determining that the user is authenticated as a member, the web service to the device.

2. The system of claim 1 , wherein the unique code value of the at least one of the plurality of code selection display objects does not provide an indication of a rendered indicator of the at least one code selection display objects.

3. The system of claim 1 , wherein the plurality of code selection display objects includes at least one of a number, a character, a figure, an image, a color, or a keyword or a combination thereof.

4. The system of claim 1 , wherein the computer code is executable by the one or more processing circuits to further cause the system to:

provide, based on the plurality of code selection display objects being displayed the web page of the device, a service to display the plurality of code selection display objects in a random order of arrangement.

5. The system of claim 1 , wherein the computer code is executable by the one or more processing circuits to further cause the system to:

compare, based on receiving data indicating a user selection of at least two of the plurality of code selection display objects in the decoded member authentication data, a sequence of selecting the at least two code selection display objects in the decoded member authentication data and a sequence of selecting code selection display objects in the stored member authentication data to determine whether the user is authenticated as a member.

6. The system of claim 1 , wherein the computer code is executable by the one or more processing circuits to further cause the system to:

configure the member authentication object to insert, at predetermined intervals, a predetermined delimiter character into received member authentication data used to generate the encoded member authentication data; and

insert the predetermined delimiter character into the stored member authentication data at the predetermined intervals.

7. A method for user security authentication in an Internet environment, the method comprising:

receiving a web service request from a device;

transmitting, after receiving the web service request, a member authentication object, the member authentication object comprising:

a member identifier (ID) module, a password module, and a security code selection module, the security code selection module comprising a plurality of code selection display objects displayable on a webpage of the device, each code selection display object of the plurality of code selection display objects having a unique code value comprising at least two characters, at least one of the plurality of code selection display objects being preselected by a user of the device and stored with stored member authentication data of the user;

receiving, after transmitting the member authentication object, encoded member authentication data, the encoded member authentication data comprising data encoded by combining a member ID, a password, and the unique code value of the at least one of the plurality of code selection display objects;

decoding the received encoded member authentication data, and analytically comparing the decoded member authentication data with the stored member authentication data to determine whether the user is authenticated as a member; and

providing, after determining that the user is authenticated as a member, the web service to the device.

8. The method of claim 7 , further comprising configuring the security code selection module as a single-dimensional or multidimensional table, the plurality of code selection display objects being arranged in the table to be selected by the user.

9. The method of claim 7 , wherein the plurality of code selection display objects includes at least one of a number, a character, a figure, an image, a color, or a keyword or a combination thereof.

10. The method of claim 7 , further comprising:

providing, based on the plurality of code selection display objects being displayed the web page of the device, a service to display the plurality of code selection display objects in a random order of arrangement.

11. The method of claim 7 , further comprising:

comparing, based on receiving data indicating a user selection of at least two of the plurality of code selection display objects in the decoded member authentication data, a sequence of selecting the at least two code selection display objects in the decoded member authentication data and a sequence of selecting code selection display objects in the stored member authentication data to determine whether the user is authenticated as a member.

12. The method of claim 7 , further comprising:

configuring the member authentication object to insert, at predetermined intervals, a predetermined delimiter character into received member authentication data used to generate the encoded member authentication data; and

inserting the predetermined delimiter character into the stored member authentication data at the predetermined intervals.

13. A non-transitory computer-readable storage medium storing a set of computer executable instructions, the instructions, when executed by one or more processors of the computer, cause the computer to perform operations comprising:

receiving a web service request from a device;

transmitting, after receiving the web service request, a member authentication object, the member authentication object comprising:

a member identifier (ID) module, a password module, and a security code selection module, the security code selection module comprising a plurality of code selection display objects displayable on a webpage of the device, each code selection display object of the plurality of code selection display objects having a unique code value comprising at least two characters, at least one of the plurality of code selection display objects being preselected by a user of the device, a unique code value of the at least one of the plurality of the code selection display objects stored with stored member authentication data of the user;

receiving, after transmitting the member authentication object, encoded member authentication data, the encoded member authentication data comprising data encoded by combining a member ID, a password, and the unique code value of the at least one of the plurality of code selection display objects;

decoding the received encoded member authentication data, and analytically comparing the decoded member authentication data with the stored member authentication data to determine whether the user is authenticated as a member; and

providing, after determining that the user is authenticated as a member, the web service to the device.

14. The non-transitory computer-readable storage medium of claim 13 , the operations further comprising:

configuring the security code selection module as a single-dimensional or multidimensional table, the plurality of code selection display objects being arranged in the table to be selected by the user.

15. The non-transitory computer-readable storage medium of claim 13 , wherein the plurality of code selection display objects includes at least one of a number, a character, a figure, an image, a color, or a keyword or a combination thereof.

16. The non-transitory computer-readable storage medium of claim 13 , the operations further comprising:

providing, based on the plurality of code selection display objects being displayed the web page of the device, a service to display the plurality of code selection display objects in a random order of arrangement.

17. The non-transitory computer-readable storage medium of claim 13 , the operations further comprising:

comparing, based on receiving data indicating a user selection of at least two of the plurality of code selection display objects in the decoded member authentication data, a sequence of selecting the at least two code selection display objects in the decoded member authentication data and a sequence of selecting code selection display objects in the stored member authentication data to determine whether the user is authenticated as a member.

18. The non-transitory computer-readable storage medium of claim 13 , the operations further comprising:

configuring the member authentication object to insert, at predetermined intervals, a predetermined delimiter character into received member authentication data used to generate the encoded member authentication data; and

inserting the predetermined delimiter character into the stored member authentication data at the predetermined intervals.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2021
From: EBAY KOREA CO. LTD.
To: EBAY INC.
Reel/Frame 057865/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2016
From: CHO, JUN HO
To: EBAY KOREA CO., LTD.
Reel/Frame 040727/0607 →
Priority Claims (1)
KR 10-2014-0000300 · Jan 2, 2014 · national
Continuity (1)
Related Publication 20160330190A1 · Nov 10, 2016