IP Library Granted Patent US 10,447,484
Granted Patent B2
US 10,447,484 · App. 16/235,308 · Granted Oct 15, 2019

Multi-user strong authentication token

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,447,484
App. No.
16/235,308
Granted
Oct 15, 2019
Kind
B2
Abstract

Apparatus, methods and systems to secure remotely accessible applications using authentication devices are disclosed. More in particular apparatus, methods and systems are disclosed for thwarting overlay attacks against authentication applications for displaying transaction data and for generating signatures over these transaction data.

Claims (51)

1. A method to secure an interaction session of a user with a remotely accessible computer-based application, the method comprising performing at a personal computing device the steps of:

obtaining transaction data related to said interaction session;

displaying, by an authentication application running on the personal computing device, the obtained transaction data on a first area of a display of the personal computing device for review by the user;

obtaining a dynamic credential associated with the transaction data;

making, by the authentication application, the dynamic credential available for verification using a second area of the display of the personal computing device; and

creating a visually perceptible continuity between the first area and the second area by giving a first visually perceptible element of the first area and a second visually perceptible element of the second area the same common specific value, such that the presence of an overlay window that is not displayed by the authentication application and that partially or entirely hides or obscures the first area and that doesn't have a third visually perceptible element with the same value as said common specific value for said first and second visually perceptible elements causes a visually perceptible discontinuity between the overlay window and the second area alerting the user to the presence of said overlay windows;

wherein said common specific value for said first and second visually perceptible elements has an unpredictable element; or

wherein said common specific value for said first and second visually perceptible elements varies in time; or

wherein said common specific value for said first and second visually perceptible elements varies from one interaction session to another; or

wherein said common specific value for said first and second visually perceptible elements varies from one personal computing device to another; or

wherein said common specific value for said first and second visually perceptible elements varies from one user to another.

2. The method of claim 1 , wherein the step of making, by the authentication application, the dynamic credential available for verification using a second area of the display of the personal computing device, comprises displaying the dynamic credential on said second area.

3. The method of claim 1 , wherein the step of making the dynamic credential available for verification using a second area of the display of the personal computing device comprises providing at the personal computing device an approval indication mechanism for the user to indicate an approval or rejection by the user and obtaining by using this mechanism from the user an indication of the user's approval or rejection, whereby the approval indication mechanism comprises a visual approval activation element on the display of the personal computing device that the user must activate to indicate the user's approval whereby the visual approval activation element has an activation area that is responsive to an action of the user and whereby the activation area of the visual approval activation element is a part of the second area.

4. The method of claim 3 , wherein the step of making the dynamic credential available for verification using a second area of the display of the personal computing device further comprises displaying the dynamic credential on the display of the personal computing device if said user's approval has been obtained.

5. The method of claim 3 , wherein the step of making the dynamic credential available for verification using a second area of the display of the personal computing device further comprises sending over a data communication network the dynamic credential to a server computer if said user's approval has been obtained.

6. The method of claim 1 , wherein said first area is adjacent to said second area.

7. The method of claim 1 , wherein said first and second visually perceptible elements comprise characters of texts displayed in said first and second areas and wherein said common specific value comprises a visual characteristic of said characters.

8. The method of claim 7 , wherein said common specific value comprises font size, font type or font color of said characters.

9. The method of claim 1 , wherein said first visually perceptible element comprises a first background of said first area and said second visually perceptible element comprises a second background of said second area and said common specific value comprises a visual characteristic of said first and second backgrounds.

10. The method of claim 9 , wherein said common specific value comprises a color of said first and second backgrounds, or

wherein said common specific value comprises a pattern of said first and second backgrounds.

11. The method of claim 9 , wherein said first and second background are non-uniform and wherein said first visually perceptible element comprises a first distortion of said first background and said second visually perceptible element comprises a second distortion of said second background and wherein said common specific value comprises a common characteristic of said first and second distortions.

12. The method of claim 9 , wherein said first background comprises a first picture and said second background comprises a second picture whereby the common specific value comprises the fact that the first and second pictures are both part of a single source picture.

13. The method of claim 1 , wherein the common specific value changes in time.

14. The method of claim 13 , wherein the common specific value changes in time in an unpredictable way.

15. The method of claim 1 , wherein said first and second visually perceptible elements of said first and second areas vary in time and wherein said common specific value comprises a common value for an aspect of a variation in time of said first and second visually perceptible elements.

16. The method of claim 15 , wherein said first visually perceptible element comprises a first movement of a first background of said first area and said second visually perceptible element comprises a second movement of a second background of said second area and said common specific value comprises a common characteristic of said first and second movements.

17. The method of claim 16 , wherein said common specific value comprises a common speed of said first and second movements, or

wherein said common specific value comprises a common direction of said first and second movements.

18. A personal computing device to secure an interaction session of a user of the personal computing device with a remotely accessible computer-based application, the personal computing device comprising a display for displaying information to the user, a user input interface for receiving inputs from the user, a memory component storing an operating system software and an authentication application software, and a data processing component for running the operating system software and the authentication application; wherein the authentication application is configured to cause the personal computing device to:

obtain transaction data related to said interaction session;

display the obtained transaction data on a first area of a display of the personal computing device for review by the user;

obtain a dynamic credential associated with the transaction data;

make the dynamic credential available for verification using a second area of the display of the personal computing device; and

create a visually perceptible continuity between the first area and the second area by giving a first visually perceptible element of the first area and a second visually perceptible element of the second area the same common specific value, such that the presence of an overlay window that is not displayed by the authentication application and that partially or entirely hides or obscures the first area and that doesn't have a third visually perceptible element with the same value as said common specific value for said first and second visually perceptible elements causes a visually perceptible discontinuity between the overlay window and the second area alerting the user to the presence of said overlay window;

wherein said common specific value for said first and second visually perceptible elements has an unpredictable element; or

wherein said common specific value for said first and second visually perceptible elements varies in time; or

wherein said common specific value for said first and second visually perceptible elements varies from one interaction session to another; or

wherein said common specific value for said first and second visually perceptible elements varies from one personal computing device to another; or

wherein said common specific value for said first and second visually perceptible elements varies from one user to another.

19. A system to secure a user's interaction session with a remotely accessible computer-based application, the system comprising: a remote application server for hosting the remotely accessible computer-based application, an access device for allowing said user's interaction session with a remotely accessible computer-based application, a credential verification server for verifying the validity of a dynamic credential associated with transaction data of the remotely accessible computer-based application, and a personal computing device comprising a display for displaying information to the user, a user input interface for receiving inputs from the user, a memory component storing an operating system software and an authentication application software, and a data processing component for running the operating system software and the authentication application; wherein the authentication application is configured to cause the personal computing device to:

obtain transaction data related to said interaction session;

display the obtained transaction data on a first area of a display of the personal computing device for review by the user;

obtain a dynamic credential associated with the transaction data;

make the dynamic credential available for verification using a second area of the display of the personal computing device; and

create a visually perceptible continuity between the first area and the second area by giving a first visually perceptible element of the first area and a second visually perceptible element of the second area the same common specific value, such that the presence of an overlay window that is not displayed by the authentication application and that partially or entirely hides or obscures the first area and that doesn't have a third visually perceptible element with the same value as said common specific value for said first and second visually perceptible elements causes a visually perceptible discontinuity between the overlay window and the second area alerting the user to the presence of said overlay window;

wherein said common specific value for said first and second visually perceptible elements has an unpredictable element; or

wherein said common specific value for said first and second visually perceptible elements varies in time; or

wherein said common specific value for said first and second visually perceptible elements varies from one interaction session to another; or

wherein said common specific value for said first and second visually perceptible elements varies from one personal computing device to another; or

wherein said common specific value for said first and second visually perceptible elements varies from one user to another.

Assignments (6)
AMENDED AND RESTATED NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Nov 18, 2025
From: ONESPAN NORTH AMERICA INC.
To: MUFG BANK, LTD.
Reel/Frame 073609/0989 →
CHANGE OF ADDRESS Recorded Aug 20, 2025
From: ONESPAN NORTH AMERICA INC.
To: ONESPAN NORTH AMERICA INC.
Reel/Frame 072501/0598 →
SECURITY INTEREST Recorded Jul 1, 2025
From: ONESPAN NORTH AMERICA INC.
To: MUFG BANK, LTD.
Reel/Frame 071573/0590 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF THE 1ST NAME OF THE 3RD-NAMED INVENTOR PREVIOUSLY RECORDED ON REEL 048844 FRAME 0038. ASSIGNOR(S) HEREBY CONFIRMS THE SPELLING OF THE 3RD INVENTOR'S 1ST NAME SHOULD BE "FREDERIK". Recorded Jul 2, 2019
From: FORT, NICOLAS; JOLY, LUDOVIC; MENNES, FREDERIK; TEIXERON, GUILLAUME
To: VASCO DATA SECURITY, INC.
Reel/Frame 049670/0878 →
CHANGE OF NAME Recorded Apr 10, 2019
From: VASCO DATA SECURITY, INC.
To: ONESPAN NORTH AMERICA INC.
Reel/Frame 049500/0920 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2019
From: FORT, NICOLAS; JOLY, LUDOVIC; MENNES, FREDERICK; TEIXERON, GUILLAUME
To: VASCO DATA SECURITY, INC.
Reel/Frame 048844/0038 →