IP Library Granted Patent US 10,411,901
Granted Patent B2
US 10,411,901 · App. 16/235,359 · Granted Sep 10, 2019

Multi-user strong authentication token

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,411,901
App. No.
16/235,359
Granted
Sep 10, 2019
Kind
B2
Abstract

Apparatus, methods and systems to secure remotely accessible applications using authentication devices are disclosed. More in particular apparatus, methods and systems are disclosed for thwarting overlay attacks against authentication applications for displaying transaction data and for generating signatures over these transaction data.

Claims (27)

1. A method to secure a user's interaction with a remotely accessible computer-based application, the method comprising performing at a personal computing device the steps of:

obtaining transaction data;

displaying the obtained transaction data on a display of the personal computing device for review by the user, wherein an authentication application that is running on the personal computing device displays the obtained transaction data in a transaction data presentation area of the display of the personal computing device;

obtaining a dynamic credential associated with the transaction data; and

ensuring at the personal computing device that no window of another application that is running on the personal computing device can partially or entirely hide or obscure the authentication application's transaction data presentation area while the transaction data are being displayed or until the authentication application has received an indication of the user's approval or rejection of the displayed transaction data by calling one or more operating system functions of an operating system of the personal computing device.

2. The method of claim 1 , wherein the transaction data presentation area comprises the entirety or a part of a transaction data displaying window of the authentication application on the display of the personal computing device, the method further comprising the step of ensuring at the personal computing device that no other window of another application that is running on the personal computing device can partially or entirely hide or obscure the authentication application's transaction data displaying window.

3. The method of claim 2 , wherein the step of ensuring at the personal computing device that no other window of another application that is running on the personal computing device can partially or entirely hide or obscure the transaction data displaying window comprises the authentication application ensuring or enforcing that the transaction data displaying window remains on top.

4. The method of claim 3 , wherein the step of the authentication application ensuring or enforcing that the transaction data displaying window remains on top, comprises the authentication application calling the one or more operating system functions to ensure or enforce that the transaction data displaying window remains on top.

5. The method of claim 1 , wherein the step of obtaining the dynamic credential associated with the transaction data comprises generating the dynamic credential by cryptographically combining the transaction data with a cryptographic key that comprises or is derived from a secret stored in the personal computing device.

6. A personal computing device to secure a user's interaction with a remotely accessible computer-based application, the personal computing device comprising a display for displaying information to the user, a user input interface for receiving inputs from the user, a memory component storing an operating system software and an authentication application software, and a data processing component for running the operating system software and the authentication application; wherein the authentication application is configured to cause the personal computing device to:

obtain transaction data;

display the obtained transaction data on the display for review by the user in a transaction data presentation area of the display;

obtain a dynamic credential associated with the transaction data; and

ensure that no window of another application that is running on the personal computing device can partially or entirely hide or obscure the authentication application's transaction data presentation area while the transaction data are being displayed or until the authentication application has received an indication of the user's approval or rejection of the displayed transaction data by calling one or more operating system functions of an operating system of the personal computing device.

7. The personal computing device of claim 6 , wherein the transaction data presentation area comprises the entirety or a part of a transaction data displaying window of the authentication application on the display of the personal computing device, and wherein the authentication application is further configured to cause the personal computing device to ensure that no other window of another application that is running on the personal computing device can partially or entirely hide or obscure the authentication application's transaction data displaying window.

8. The personal computing device of claim 7 , wherein the ensuring that no other window of another application that is running on the personal computing device can partially or entirely hide or obscure the transaction data displaying window comprises the authentication application ensuring or enforcing that the transaction data displaying window remains on top.

9. The personal computing device of claim 8 , wherein the authentication application ensuring or enforcing that the transaction data displaying window remains on top, comprises the authentication application calling the one or more operating system functions to ensure or enforce that the transaction data displaying window remains on top.

10. The personal computing device of claim 6 , wherein obtaining the dynamic credential associated with the transaction data comprises generating the dynamic credential by cryptographically combining the transaction data with a cryptographic key that comprises or is derived from a secret stored in the personal computing device.

11. A system to secure a user's interaction with a remotely accessible computer-based application, the system comprising: a remote application server for hosting the remotely accessible computer-based application, an access device for allowing said user's interaction with a remotely accessible computer-based application, a credential verification server for verifying validity of a dynamic credential associated with transaction data of the remotely accessible computer-based application, and a personal computing device comprising a display for displaying information to the user, a user input interface for receiving inputs from the user, a memory component storing an operating system software and an authentication application software, and a data processing component for running the operating system software and the authentication application; wherein the authentication application is configured to cause the personal computing device to:

obtain the transaction data;

display the obtained transaction data on the display for review by the user in a transaction data presentation area of the display;

obtain the dynamic credential associated with the transaction data; and

ensure that no window of another application that is running on the personal computing device can partially or entirely hide or obscure the authentication application's transaction data presentation area while the transaction data are being displayed or until the authentication application has received an indication of the user's approval or rejection of the displayed transaction data by calling one or more operating system functions of an operating system of the personal computing device.

12. The system of claim 11 , wherein the transaction data presentation area comprises the entirety or a part of a transaction data displaying window of the authentication application on the display of the personal computing device, and wherein the authentication application is further configured to cause the personal computing device to ensure that no other window of another application that is running on the personal computing device can partially or entirely hide or obscure the authentication application's transaction data displaying window.

13. The system of claim 12 , wherein the ensuring that no other window of another application that is running on the personal computing device can partially or entirely hide or obscure the transaction data displaying window comprises the authentication application ensuring or enforcing that the transaction data displaying window remains on top.

14. The system of claim 13 , wherein the authentication application ensuring or enforcing that the transaction data displaying window remains on top, comprises the authentication application calling the one or more operating system functions to ensure or enforce that the transaction data displaying window remains on top.

15. The system of claim 11 , wherein obtaining the dynamic credential associated with the transaction data comprises generating the dynamic credential by cryptographically combining the transaction data with a cryptographic key that comprises or is derived from a secret stored in the personal computing device.

Assignments (6)
AMENDED AND RESTATED NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Nov 18, 2025
From: ONESPAN NORTH AMERICA INC.
To: MUFG BANK, LTD.
Reel/Frame 073609/0989 →
CHANGE OF ADDRESS Recorded Aug 20, 2025
From: ONESPAN NORTH AMERICA INC.
To: ONESPAN NORTH AMERICA INC.
Reel/Frame 072501/0598 →
SECURITY INTEREST Recorded Jul 1, 2025
From: ONESPAN NORTH AMERICA INC.
To: MUFG BANK, LTD.
Reel/Frame 071573/0590 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF THE 1ST NAME OF THE 3RD-NAMED INVENTOR PREVIOUSLY RECORDED ON REEL 048844 FRAME 0038. ASSIGNOR(S) HEREBY CONFIRMS THE SPELLING OF THE 3RD INVENTOR'S 1ST NAME SHOULD BE "FREDERIK". Recorded Jul 2, 2019
From: FORT, NICOLAS; JOLY, LUDOVIC; MENNES, FREDERIK; TEIXERON, GUILLAUME
To: VASCO DATA SECURITY, INC.
Reel/Frame 049670/0878 →
CHANGE OF NAME Recorded Apr 10, 2019
From: VASCO DATA SECURITY, INC.
To: ONESPAN NORTH AMERICA INC.
Reel/Frame 049500/0920 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2019
From: FORT, NICOLAS; JOLY, LUDOVIC; MENNES, FREDERICK; TEIXERON, GUILLAUME
To: VASCO DATA SECURITY, INC.
Reel/Frame 048844/0038 →