IP Library Granted Patent US 10,050,969
Granted Patent B2
US 10,050,969 · App. 15/237,520 · Granted Aug 14, 2018

Credential-free identification and authentication

Inventors: Robert Foster (San Juan Capistrano, CA); Scott Goldman (Carlsbad, CA); Mark Nielsen (San Juan Capistrano, CA)
Assignee: TEXTPOWER, INC.
H04L63/10G06F21/34G06F21/35G06F21/42G07F19/206H04L63/083H04L63/0876H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,050,969
App. No.
15/237,520
Granted
Aug 14, 2018
Kind
B2
Abstract

A method of authenticating a user so that the user can access a website without entering a unique user credential. A user accesses a target and is presented with an authentication code and an address, and the user sends a message containing the authentication code to that address. Alternatively, the user is pre-supplied with an address and is presented only with an authentication code when the user accesses the target. The user's identity is authenticated by comparing an aspect of the metadata of the message with known metadata aspects, and the user is authenticated by comparing the authentication key presented to the user with the one received in the message. Both the user and the user's identity are authenticated in a single step without requiring the user to input any unique user credential.

Claims (22)

1. A system for authenticate a user with respect to a target service via a user-operated device, comprising:

a database that stores user credentials associated with a plurality of users; and

an authentication engine comprising a processor and memory storing software instructions that when executed by the processor causing the process to perform the following steps:

instructing a target user interface associated with the target service to present an authentication passkey and an authentication address without first requiring the user to provide a unique user credential,

receiving, from the user-operated device, a message addressed to the authentication address, and comprising a test passkey and a device identifier,

detecting a similarity between the test passkey and the authentication passkey,

identifying the user-operated device as an authorized device by comparing the device identifier against a stored set of identifiers,

retrieving user credentials associated with the user by querying a user database using solely the device identifier, wherein the user credentials comprise at least a user identifier and a password, and

submitting the retrieved user credentials to the target user interface for accessing the target service.

2. The system of claim 1 , wherein the authentication engine is further programmed to perform a step of generating, upon receipt of a request, the authentication passkey without first requiring the user to provide a unique user credential.

3. The system of claim 2 , wherein the step of generating the authentication passkey comprises a step of generating an authentication passkey that is unique to the target user interface.

4. The system of claim 2 , wherein the request comprises a username associated with the user.

5. The system of claim 1 , wherein the authentication passkey is user agnostic.

6. The system of claim 1 , wherein the authentication engine is further programmed to perform a step of associating the target service with the user based on the device identifier.

7. The system of claim 1 , wherein the authentication engine is further programmed to perform a step of associating the target service with different users based on different device identifiers.

8. The system of claim 1 , wherein the target user interface comprises an ATM machine.

9. The system of claim 8 , wherein the step of authorizing the target user interface to access the target service comprises initiating a transaction with a bank account associated with the user.

10. The system of claim 1 , wherein the target service comprises at least one of a web service, a phone network, an appliance, and entry to an enclosed space.

11. The system of claim 1 , wherein the user-operated device comprises a cell phone.

12. The system of claim 1 , wherein the authenticating address comprises at least one of a URL, an SMS short code, and a phone number.

13. The system of claim 1 , wherein the authenticating address is rotated, and selected from a pool of available addresses.

14. The system of claim 1 , wherein the device identifier comprises at least one of a phone number, a MAC address, and a UDID number.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded May 28, 2025
From: ARES CAPITAL CORPORATION
To: TEXTPOWER, INC.
Reel/Frame 071232/0741 →
PATENT SECURITY AGREEMENT Recorded May 28, 2025
From: TEXTPOWER, INC.
To: BAIN CAPITAL SPECIAL SITUATIONS, LP, AS COLLATERAL AGENT
Reel/Frame 071431/0687 →
PATENT SECURITY AGREEMENT Recorded Aug 21, 2024
From: TEXTPOWER, INC.
To: ARES CAPITAL CORPORATION
Reel/Frame 068733/0860 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2016
From: FOSTER, ROBERT; GOLDMAN, SCOTT; NIELSEN, MARK
To: TEXTPOWER, INC.
Reel/Frame 039438/0591 →
Continuity (4)
Continuation 14815895 · Jul 31, 2015
Provisional Application 62190565 · Jul 9, 2015
Provisional Application 62031392 · Jul 31, 2014
Related Publication 20170041320A1 · Feb 9, 2017