IP Library › Patent Application 16578366
Patent Application
App. No. 16/578,366

DIRECT AUTHENTICATION SYSTEM AND METHOD VIA TRUSTED AUTHENTICATORS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/578,366
Abstract

Systems and methods are provided for enabling online entities to determine whether a user is truly the person who he says using a “two-factor” authentication technique and authenticating customer's identity utilizing a trusted authenticator.

Claims (46)

1 . A system for enhancing online authentication of a user attempting to access an online system, the authentication system comprising one or more computing devices configured to perform operations comprising:

receiving, via a computer network, after the user attempts to access the online system, a request for a user-authentication code for the user;

providing, via the computer network, the user-authentication code in response to the request for the user-authentication code, wherein:

the user-authentication code is information generated by the authentication system for authenticating the user,

the user-authentication code is configured to be valid for a predetermined time,

the user-authentication code is configured to become invalid after the predetermined time, and

the user-authentication code is configured to become invalid after a first use to authenticate the user;

receiving, via the computer network, a user-authentication request for authenticating the user from the online system, the user-authentication request comprising the user-authentication code and user-identification information of the user;

authenticating the user based on at least the user-authentication code and the user-identification information included in the authentication request; and

providing, via the computer network, a result of the authenticating to the online system in response to the authentication request, wherein:

the result confirms authentication of the user if the user-authentication code is valid; and

the result denies authentication of the user if the user-authentication code is invalid.

2 . The system of claim 1 , wherein the user-authentication code is a SecureCode.

3 . The system of claim 2 , wherein the SecureCode is comprised of alphabetic characters, numeric characters, or a Personal Identification Number (PIN).

4 . The system of claim 1 , wherein the user-authentication code is variable and has a different value each time the system provides it.

5 . The system of claim 1 , wherein authenticating the user comprises determining whether the user-authentication code received in the authentication request is valid.

6 . The system of claim 5 , wherein determining whether the user-authentication code received in the authentication request is valid comprises:

determining whether the user-authentication request is the first use of the user-authentication code to authenticate the user; and

determining whether a time of the first use is within the predetermined time.

7 . The system of claim 6 , wherein the time of the first use is a current time.

8 . The system of claim 5 , wherein after authenticating the user, the user-authentication code is invalid for all subsequent user-authentication requests.

9 . The system of claim 5 , wherein the user-authentication code is valid for authenticating the user at the time the user receives the user-authentication code.

10 . The system of claim of 1 , wherein receiving the user-authentication request and providing the result occur during a real-time interaction between the user and the online system.

11 . A method of online authentication of a user attempting to access an online system, the method comprising:

receiving, by a computing device via a computer network, after the user attempts to access the online system, a request for a user-authentication code for the user;

providing, by the computing device via the computer network, the user-authentication code in response to the request for the user-authentication code, wherein:

the user-authentication code is information generated by the authentication system for authenticating the user,

the user-authentication code is configured to be valid for a predetermined time,

the user-authentication code is configured to become invalid after the predetermined time, and

the user-authentication code is configured to become invalid after a first use to authenticate the user;

receiving, by the computing device via the computer network, a user-authentication request for authenticating the user from the online system, the user-authentication request comprising the user-authentication code and user-identification information of the user;

authenticating, by the computing device, the user using the user-authentication code and the user-identification information included in the authentication request; and

providing, by the computing device via the computer network, a result of the authenticating to the online system in response to the authentication request; wherein:

the result confirms authentication of the user if the user-authentication code is valid; and

the result denies authentication of the user if the user-authentication code is invalid.

12 . The method of claim 11 , wherein the user-authentication code is a SecureCode.

13 . The method of claim 12 , wherein the SecureCode is comprised of alphabetic characters, numeric characters; or a Personal Identification Number (PIN).

14 . The method of claim 11 , wherein the user-authentication code is variable and has a different value each time the computing device provides it.

15 . The method of claim 11 , wherein authenticating the user comprises determining whether the user-authentication code received in the authentication request is valid.

16 . The method of claim 15 , wherein determining whether the user-authentication code received in the authentication request is valid comprises:

determining whether the user-authentication request is the first use of the user-authentication code to authenticate the user; and

determining whether a time of the first use is within the predetermined time.

17 . The method of claim 16 , wherein the time of the first use is a current time.

18 . The method of claim 15 , wherein after authenticating the user, the user-authentication code is invalid for all subsequent user-authentication requests.

19 . The method of claim 15 , wherein the user-authentication code is valid for authenticating the user at the time the user receives the user-authentication code.

20 . The method of claim of 11 , wherein receiving the user-authentication request and providing the result occur during a real-time interaction between the user and the online system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2021
From: ASGHARI-KAMRANI, KAMRAN; ASGHARI-KAMRANI, NADER
To: AMERITECH SOLUTIONS, INC.
Reel/Frame 055367/0694 →