IP Library Granted Patent US 11,050,567
Granted Patent B2
US 11,050,567 · App. 16/689,612 · Granted Jun 29, 2021

Security authentification system for membership login of online website and method thereof

Inventor: Jin Yong Lee (Seongnam-si, KR)
Assignee: eBay Inc.
H04L9/3228G06F21/36G06F21/42G06Q20/3274G06Q20/3276G06Q20/385G06Q20/3827G06Q20/4014G06Q20/425H04L9/08H04L9/32H04L9/3236H04L63/0838H04L63/18H04W12/068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,050,567
App. No.
16/689,612
Granted
Jun 29, 2021
Kind
B2
Abstract

Disclosed is a security authentication system for a membership login of an online website capable of ensuring a safe membership login without having to directly entering a membership ID and a password for a membership login of a certain online website on a user terminal being used in association with a smartphone for a private or public purpose, and a method thereof.

Claims (43)

1. A method at an authentication server, the method comprising:

providing, to a first device, one-time use authentication information for a website prior to receiving user login authentication information for the website;

receiving, from a second device, an authentication request based on the one-time use authentication information and the user login authentication information;

in response to verifying the authentication request, providing, to the second device, one-time password (OTP) information for the website; and

receiving, from the first device, a login request based on the OTP information.

2. The method of claim 1 , wherein the login request comprises the OTP information and the one-time use authentication information for the website.

3. The method of claim 1 , wherein the first device is configured to present a QR code based on the one-time user authentication information; and wherein the second device is configured to scan the QR code and identify the one-time user authentication information based on the QR code.

4. The method of claim 1 , wherein the method further comprises:

receiving, from the first device, a request to log in to the website; and

in response to the request, generating the one-time use authentication information.

5. The method of claim 4 , wherein the one-time use authentication information is generated based at least in part on an IP address of the first device and/or a time stamp corresponding to a time of issuance of the one-time use authentication information.

6. The method of claim 1 , wherein the method further comprises:

in response to verifying the authentication request, generating the OTP information.

7. The method of claim 6 , wherein the OTP information is generated based at least in part on an IP address of the second device, the one-time use authentication information, the user login authentication information, and/or an IP address of the first device.

8. A computing apparatus, the computing apparatus comprising:

a processor; and

a memory storing instructions that, when executed by the processor, configure the apparatus to perform operations comprising:

providing, to a first device, one-time use authentication information for a website prior to receiving user login authentication information for the website;

receiving, from a second device, an authentication request based on the one-time use authentication information and the user login authentication information;

in response to verifying the authentication request, providing, to the second device, one-time password (OTP) information for the website; and

receiving, from the first device, a login request based on the OTP information.

9. The computing apparatus of claim 8 , wherein the login request comprises the OTP information and the one-time use authentication information for the website.

10. The computing apparatus of claim 8 , wherein the first device is configured to present a QR code based on the one-time user authentication information; and wherein the second device is configured to scan the QR code and identify the one-time user authentication information based on the QR code.

11. The computing apparatus of claim 8 , wherein the operations further comprise:

receiving, from the first device, a request to log in to the website; and

in response to the request, generating the one-time use authentication information.

12. The computing apparatus of claim 11 , wherein the one-time use authentication information is generated based at least in part on an IP address of the first device and/or a time stamp corresponding to a time of issuance of the one-time use authentication information.

13. The computing apparatus of claim 8 , wherein the operations further comprise:

in response to verifying the authentication request, generating the OTP information.

14. The computing apparatus of claim 13 , wherein the OTP information is generated based at least in part on an IP address of the second device, the one-time use authentication information, the user login authentication information, and/or an IP address of the first device.

15. A non-transitory computer-readable storage medium including instructions that when executed by a computer, cause the computer to perform operations comprising:

providing, to a first device, one-time use authentication information for a website prior to receiving user login authentication information for the website;

receiving, from a second device, an authentication request based on the one-time use authentication information and the user login authentication information;

in response to verifying the authentication request, providing, to the second device, one-time password (OTP) information for the website; and

receiving, from the first device, a login request based on the OTP information.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the login request comprises the OTP information and the one-time use authentication information for the website.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the operations further comprise:

receiving, from the first device, a request to log in to the website; and

in response to the request, generating the one-time use authentication information.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the one-time use authentication information is generated based at least in part on an IP address of the first device and/or a time stamp corresponding to a time of issuance of the one-time use authentication information.

19. The non-transitory computer-readable storage medium of claim 15 , wherein the operations further comprise:

in response to verifying the authentication request, generating the OTP information.

20. The non-transitory computer-readable storage medium of claim 19 , wherein the OTP information is generated based at least in part on an IP address of the second device, the one-time use authentication information, the user login authentication information, and/or an IP address of the first device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2021
From: EBAY KOREA CO. LTD.
To: EBAY INC.
Reel/Frame 057865/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2020
From: LEE, JIN YONG
To: EBAY KOREA CO., LTD.
Reel/Frame 051770/0487 →