IP Library › Granted Patent US 11,374,927
Granted Patent B1
US 11,374,927 · App. 16/901,397 · Granted Jun 28, 2022

System and method for passwordless logins

Inventors: Jeffrey Howard Kaditz (San Francisco, CA); Andrew Gettings Stevens (Dundas, MN); Bradley N. Selby (San Francisco, CA); Aaron Ng Ligon (Palo Alto, CA); Manuel De Jesus Arias (San Francisco, CA)
Assignee: Affirm, Inc.
H04L63/0853G06F21/35H04L63/08H04L63/10H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,374,927
App. No.
16/901,397
Granted
Jun 28, 2022
Kind
B1
Abstract

A login system allows users to access computer systems without using a password. The passwordless system and method can use other information to securely and reliably identify true authorized system users. The identity of a user can be associated with their mobile device. The login can be based upon a minimal amount of information such as a name and a phone number which can be stored as an identification record for each of the users in a database.

Claims (38)

1. A method for a passwordless login to an internet based system comprising:

providing a server, a database and a smart phone in communication with the server through a network;

transmitting from the smart phone to the server, only the user name and a phone number for the smart phone associated with a user without any password;

recognizing by the server, the user name and the phone number for the smart phone during a login of the user;

transmitting by the server, a verification message that includes a unique randomly generated verification code that is part of a hyperlink for the passwordless login to the phone number of the smart phone;

displaying a webpage for the hyperlink for internet based system on the smart phone of the user during the passwordless login;

receiving by the server, a confirmation message transmitted through the hyperlink from the smart phone to authenticate the user during the passwordless login of the user;

binding by the server, identification information for the smart phone to the user during the passwordless login of the user; and

authorizing by the server, the user and the smart phone to interact with the server.

2. The method of claim 1 , wherein the verification message includes a push notification sent to the smartphone, and where in the push notification interacts with an app installed on the smart phone.

3. The method of claim 1 , wherein the verification message includes a CAPTCHA for a user to enter into a web form on the device being verified.

4. The method of claim 1 , wherein the verification message includes a phone call made to the phone that plays an audio signal of a verification code.

5. The method of claim 1 , wherein the verification message is a short message service (SMS).

6. The method of claim 1 wherein the unique randomly generated verification code is at least five alphanumeric characters long.

7. The method of claim 1 wherein the hyperlink includes the verification code that is a randomly generated sequence of characters that is at least five characters long.

8. The method of claim 1 wherein the verification code includes at least one upper case letter and at least one lower case letter.

9. The method of claim 1 wherein the receiving step is within a predetermined time from the transmitting step.

10. The method of claim 1 further comprising:

canceling by the server, the authorization of the user and the smart phone to interact with the server using the passwordless login when the receiving step is after the predetermined time from the transmitting step.

11. The method of claim 1 further comprising:

canceling by the server, the authorization of the user and the smart phone to interact with the server using the passwordless login when the phone number for the smart phone is no longer associated with the user.

12. A method for purchasing goods comprising:

providing a server, a database and a mobile device in communication with the server through a network;

transmitting from the mobile device to the server, the user name and the phone number for the mobile device associated with the user;

recognizing by the server, the user name, the phone number and the unique identifier for the mobile device to authenticate the user during a passwordless login of the user;

inputting identification information for the goods in a personal point of sales program running on a mobile computing device;

transmitting by the server, a verification message that includes a unique randomly generated verification code that is part of a hyperlink for the passwordless login to the phone number of the mobile device;

displaying a webpage for the hyperlink for purchasing the goods on the mobile device of the user during the passwordless login;

receiving by the server, a purchase acceptance response to the verification message transmitted through the hyperlink for accepting the purchasing the goods from the mobile device to authenticate the user during the passwordless login of the user;

binding by the server, identification information for the mobile device to the user; and authorizing by the server, the user and the mobile device to interact with the server using the passwordless login to complete the purchase of the goods.

13. The method of claim 12 wherein the verification code is a randomly generated sequence of characters that is at least five characters long.

14. The method of claim 12 wherein the hyperlink includes the unique randomly generated verification code that is at least five alphanumeric characters long.

15. The method of claim 12 wherein the unique randomly generated verification code includes at least one upper case letter and at least one lower case letter.

16. The method of claim 12 wherein the receiving step is within a predetermined time from the transmitting step.

17. The method of claim 12 further comprising:

canceling by the server, the authorization of the user and the mobile device to interact with the server using the passwordless login when the receiving step is after the predetermined time from the transmitting step.

18. The method of claim 12 further comprising:

canceling by the server, the authorization of the user and the mobile device to interact with the server using the passwordless login when the unique identifier for the mobile device is no longer associated with the user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2024
From: ARIAS, MANUEL
To: AFFIRM, INC.
Reel/Frame 066467/0876 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2021
From: KADITZ, JEFFREY HOWARD; STEVENS, ANDREW GETTINGS; SELBY, BRADLEY N.; LIGON, AARON NG
To: AFFIRM, INC.
Reel/Frame 058497/0568 →
Continuity (2)
Continuation 14578353 · Dec 20, 2014
Provisional Application 61920475 · Dec 24, 2013
Cited By (3)
US 12,323,410 US 12,481,734 US 12,627,982