IP Library Granted Patent US 10,084,773
Granted Patent B2
US 10,084,773 · App. 15/138,521 · Granted Sep 25, 2018

Time-based one time password (TOTP) for network authentication

Inventors: Lloyd Leon Burch (Payson, UT); Duane Fredrick Buss (West Mountain, UT); Larry Hal Henderson (Orem, UT)
Assignee: NetIQ Corporation
H04L63/0838G06F21/45H04L9/3228H04L63/0846H04W12/06H04L63/0815H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,084,773
App. No.
15/138,521
Granted
Sep 25, 2018
Kind
B2
Abstract

A Time-based One-Time Password (TOTP) validator is interposed between a principal and a network service. The validator interacts with a mobile application (app) on the mobile device associated with the principal to dynamically supply a validator secret. The secret and, perhaps, other information are processed by the app to generate a TOTP when the principal attempts to access a protected resource of the network service. The validator independently generates the TOTP and compares the app generated TOTP, and on a successful match, a principal's access device is redirected for access to the protected resource.

Claims (17)

1. A method, comprising:

providing, by a mobile device, an invitation token to a Time-based One-Time Only Password (TOTP) manager that processes on a server;

obtaining, by the mobile device, a TOTP secret that is generated by the TOTP manager, and removed by the TOTP manager once the TOTP secret is provided by the TOTP manager to the mobile device;

storing, by the mobile device, the TOTP secret in a key store on the mobile device;

acquiring, by the mobile device, a request to generate a TOTP from a principal;

processing, by the mobile device, a first factor authentication of the principal attempting to access a protected resource and responsive to the processing obtaining a globally-unique identifier (GUID) for the principal;

generating, by the mobile device, the TOTP by hashing the TOTP secret, the GUID, and current Time-Of-Day (TOD); and

providing, by the mobile device, the TOTP as a second factor authentication for authenticating and accessing the protected resource.

2. The method of claim 1 further comprising, presenting, by the mobile device, the TOTP on a display of the mobile device for access by the principal and accessing the protected resource.

3. The method of claim 1 , wherein providing further includes obtaining the invitation token through an input supplied by the principal on the mobile device.

4. The method of claim 1 , wherein providing further includes obtaining the invitation token through processing of an automated application that interacts with the mobile device.

5. The method of claim 1 , wherein providing further includes periodically receiving a new invitation token to replace the invitation token.

6. The method of claim 1 , wherein providing further includes supplying the invitation token to the TOTP manager when processing for the method is initiated for execution on the mobile device.

7. The method of claim 1 , wherein providing further includes obtaining the invitation token in an email delivered to the mobile device.

8. The method of claim 1 , wherein providing further includes including in the invitation token social identity data for the principal.

9. The method of claim 1 , wherein obtaining further includes periodically obtaining a new TOTP secret from the TOTP manager replacing the TOTP secret.

10. The method of claim 1 , wherein generating further includes adding a random number to a hash value when generating the TOTP based on instructions embedded in the TOTP secret and processed.

Assignments (2)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
Continuity (2)
Continuation 14228413 · Mar 28, 2014
Related Publication 20160241550A1 · Aug 18, 2016
Cited By (1)
US 12,437,040