IP Library Granted Patent US 10,659,454
Granted Patent B2
US 10,659,454 · App. 15/490,324 · Granted May 19, 2020

Service authorization using auxiliary device

Inventor: Kai Cao (Hangzhou, CN)
Assignee: Alibaba Group Holding Limited
H04L63/0853G06F21/34G06F21/44H04L9/30H04L9/321H04L9/3226H04L9/3228H04L9/3234H04L63/04H04L63/083H04L63/10H04L63/123H04L63/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,659,454
App. No.
15/490,324
Granted
May 19, 2020
Kind
B2
Abstract

Implementations of the present disclosure relate to systems and methods for service authorization. A server terminal device may receive user authentication information that is stored on the auxiliary device for user authentication associated with an authentication device. Based on the user authentication information, the server terminal device may then determine whether the authentication device meets the authentication condition. The implementations further relate to methods and systems for requesting service authorization.

Claims (49)

1. A method for service authorization, the method comprising:

receiving, by one or more processors of a server terminal device, user authentication information that is stored on an auxiliary device for user authentication associated with a user terminal device, the user authentication information comprising an authentication token, wherein the authentication token includes encrypted information generated from a first system local time when the auxiliary device receives an auxiliary authentication request from the user terminal device and a random number seed;

determining that an auxiliary authentication function is enabled for the auxiliary device in response to determining that the authentication token is bound to the identifier of the user terminal device; and

determining whether the user terminal device meets an authorization condition based on the user authentication information, determining whether the user terminal device meets the authorization condition comprising determining whether the authentication token included in the user authentication information matches any one of a plurality of verification authentication tokens generated by the server terminal device, the plurality of verification authentication tokens being generated by encrypting the random number seed and a plurality of timing points associated with a second system local time when the server terminal device receives the user authentication token.

2. The method of claim 1 , further comprising:

receiving a request for user authentication prior to receiving the user authentication information, the user authentication request including identifier information of the user terminal device;

generating a service serial number based on the user authentication request, the service serial number having a mapping relationship with the user authentication request; and

wherein the determining whether the user terminal device meets the authorization condition further comprises:

determining the service serial number corresponding to the user authentication request;

identifying the user terminal device based on the identifier information of the user terminal device;

determining whether the user terminal device meets the authorization condition.

3. The method of claim 1 , wherein the user authentication information further comprises user identification information, and the method further comprises:

transmitting a private key to the user terminal device after verification of the user identification information; and

transmitting an authentication label to the auxiliary device for user authentication via the user terminal device after receiving a request for user authentication.

4. The method of claim 3 , wherein the user authentication information further comprises verification information, and determining whether the user terminal device meets the authorization condition further comprises:

identifying the user identification information corresponding to a public key;

decrypting the verification information using the public key to obtain information to be certified;

determining whether the information to be certified matches the authentication label based on the user authentication information;

determining that the user terminal device meets authorization conditions in response to a determination that the information to be certified matches the authentication label; and

determining that the user terminal device does not meet authorization conditions in response to a determination that the information to be certified does not match the authentication label.

5. The method of claim 1 , wherein the user authentication information is provided by the auxiliary device for user authentication to the server terminal device.

6. The method of claim 1 , wherein the user authentication information is obtained from the user terminal device or the auxiliary device for user authentication and transmitted by the user terminal device to the server terminal device.

7. The method of claim 1 , wherein the auxiliary device for user authentication comprises at least one of a mobile phone, a desktop computer, a laptop, or a tablet.

8. The method of claim 1 , wherein the auxiliary device for user authentication and user terminal device exchange information using sound waves.

9. The method of claim 1 , wherein the user authentication information further comprises a user name and a password.

10. A method for requesting authorization, the method comprising:

receiving, by one or more processors of an auxiliary device for user authentication, an auxiliary authentication request from a user terminal device associated with the auxiliary device for user authentication;

obtaining user authentication information that is stored on the auxiliary device for user authentication, the user authentication information comprising an authentication token, wherein the authentication token includes encrypted information generated from a first system local time when the auxiliary device receives the auxiliary authentication request from the user terminal device and a random number seed; and

transmitting the user authentication information to a server terminal device such that the server terminal device determines whether the user terminal device meets an authentication condition based on the user authentication information by determining whether the authentication token included in the user authentication information matches any one of a plurality of verification authentication tokens, the plurality of verification authentication tokens being generated by encrypting the random number seed and a plurality of timing points associated with a second system local time when the server terminal device receives the user authentication token.

11. The method of claim 10 , wherein the user authentication information that is stored on the auxiliary device for user authentication is transmitted directly to the server terminal device.

12. The method of claim 10 , wherein the user authentication information is transmitted from the auxiliary device for user authentication to the server terminal device via the user terminal device.

13. A system for service authorization, the system comprising:

a server terminal device, wherein the server terminal device comprises:

one or more processors; and

memory including instructions that, when executed by the one or more processors, cause the one or more processors to perform acts comprising:

receiving user authentication information that is stored on an auxiliary device for user authentication associated with a user terminal device, the user authentication information comprising an authentication token, wherein the authentication token includes encrypted information generated from a first system local time when the auxiliary device receives an auxiliary authentication request from the user terminal device and a random number seed;

determining that an auxiliary authentication function is enabled for the auxiliary device in response to determining that the authentication token is bound to the identifier of the user terminal device; and

determining whether the user terminal device meets an authorization condition based on the user authentication information, determining whether the user terminal device meets the authorization condition comprising determining whether the authentication token included in the user authentication information matches any one of a plurality of verification authentication tokens generated by the server terminal device, the plurality of verification authentication tokens being generated by encrypting the random number seed and a plurality of timing points associated with a second system local time when the server terminal device receives the user authentication token.

14. The system of claim 13 , wherein the acts further comprise:

receiving a request for user authentication prior to receiving the user authentication information, the user authentication request including identifier information of the user terminal device; and

generating a service serial number based on the user authentication request, the service serial number having a mapping relationship with the user authentication request; and

wherein the determining whether the user terminal device meets an authorization condition further comprises:

determining the service serial number corresponding to the user authentication request based on the user authentication information;

identifying the user terminal device based on the identifier information of the user terminal device; and

determining whether the user terminal device meets the authorization condition.

15. The system of claim 13 , wherein the user authentication information is provided by the auxiliary device for user authentication the server terminal device.

16. The system of claim 13 , wherein the user authentication information is obtained from the auxiliary device for user authentication and transmitted by the user terminal device to the server terminal device.

17. The system of claim 13 , wherein the auxiliary device for user authentication comprises at least one of a mobile phone, a desktop computer, a laptop, or a tablet.

18. The system of claim 13 , wherein the auxiliary device for user authentication and the user terminal device exchange information by implementing sound waves.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2020
From: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NEW TECHNOLOGIES CO., LTD.
Reel/Frame 054064/0610 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2020
From: ALIBABA GROUP HOLDING LIMITED
To: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053650/0816 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2017
From: CAO, KAI
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 042279/0178 →
Priority Claims (1)
CN 2014 1 0150396 · Apr 15, 2014 · national
Continuity (2)
Continuation 14685351 · Apr 13, 2015
Related Publication 20170223016A1 · Aug 3, 2017