IP Library › Granted Patent US 11,627,463
Granted Patent B2
US 11,627,463 · App. 16/940,037 · Granted Apr 11, 2023

Authentication via unstructured supplementary service data

Inventors: Patrick Nelson Triest (Brooklyn, NY); Maijid Moujaled (San Francisco, CA)
Assignee: Critical Ideas, Inc.
H04W12/068H04L63/0838H04L63/0846H04L63/0853H04W4/20H04W8/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,627,463
App. No.
16/940,037
Granted
Apr 11, 2023
Kind
B2
Abstract

A system and a method are disclosed for authenticating a user of a mobile device using Unstructured Supplementary Service Data (“USSD”) protocol. The mobile device generates a One-Time Password (“OTP”) code and sends that OTP code to a telecommunications server that forwards the content of the USSD message to the application server using an included short code. The OTP code is also sent out to the application server outside of the USSD protocol. When the application server receives both transmissions, the application server compares the OTP codes of these transmissions and determines whether the codes match. If the OTP codes match, the application server determines that authentication is successful and transmits an authentication token to the mobile device that is used to secure communications between the mobile device and the application server.

Claims (80)

1. A method for providing authentication for mobile devices, the method comprising:

generating, on a mobile device, a one-time password for authentication of an application, wherein the one-time password expires after a first use or after a predetermined period of time;

retrieving a short code associated with an application server, wherein the application server corresponds to the application;

transmitting, to a telecommunications server, an Unstructured Supplementary Service Data (“USSD”) message, wherein the USSD message comprises the one-time password, a telephone number associated with the mobile device, and the short code;

transmitting, to the application server, an authentication request, wherein the authentication request comprises the one-time password and the telephone number associated with the mobile device;

receiving, in response to determining that the telephone number, the one-time password, and a current date within the authentication request match a telephone number, a one-time password and an updated date in a database entry, an authentication token for the mobile device, wherein the authentication token maintains a connection for the mobile device and the application server to securely send and receive data; and

transmitting, from the mobile device to the application server, a request for data, the request comprising the authentication token that is used by the application server to authenticate the request.

2. The method of claim 1 , further comprising:

determining a number of telephone numbers associated with the mobile device;

enabling for display on the mobile device, in response to determining that more than one telephone number is associated with the mobile device, a prompt for selecting one of the telephone numbers to transmit to the telecommunications server.

3. The method of claim 1 , wherein transmitting, the authentication request to the application server comprises transmitting a request for the authentication token.

4. The method of claim 1 , wherein retrieving the short code associated with the application server comprises:

retrieving the telephone number associated with the mobile device;

determining, based on the telephone number associated with the mobile device a region associated with the mobile device; and

selecting the short code based on the region associated with the mobile device.

5. The method of claim 1 , further comprising receiving, in response to the authentication request being unsuccessful, a failure indication.

6. A method for authenticating mobile devices, the method comprising:

receiving, from a telecommunications server, a USSD message generated on a mobile device, wherein the USSD message comprises a one-time password and a telephone number associated with the mobile device, and a short code associated with an application server corresponding to an application;

storing a database entry in a database, wherein the database entry comprises a one-time password, a telephone number, and an updated date corresponding to a date when the one-time password was received in the USSD message;

receiving, from the mobile device, an authentication request, wherein the authentication request comprises the one-time password and the telephone number;

determining, whether 1) the telephone number within the authentication request matches the telephone number in the database entry, 2) the one-time password in the authentication request matches the one-time password in the database entry, and 3) a current date corresponding to when the authentication request was transmitted matches the updated date in the database entry; and

generating, in response to determining that 1) the telephone number within the authentication request matches the telephone number in the database entry, 2) the one-time password in the authentication request matches the one-time password that in the database entry, and 3) the updated date in the database entry matches the current date, an authentication token for the mobile device, wherein the authentication token maintains a connection for the mobile device and the application server to securely send and receive data; and

transmitting the authentication token to the mobile device, wherein the applications server receives requests for data from the mobile device, the requests for data comprising the authentication token.

7. The method of claim 6 , wherein storing the database entry further comprises:

storing a timestamp for a time when the one-time password was generated; and

storing a value in the database entry indicating whether the one-time password was used for authentication.

8. The method of claim 7 , further comprising:

determining, based on the timestamp, whether the one-time password is expired,

determining based on the value in the database entry, whether the one-time password has been already used; and

in response to determining, based on the timestamp, that the one-time password is expired, or determining, based on the value in the database entry, that the one-time password has been already used, transmitting a response to the mobile device that authentication has failed.

9. A non-transitory computer readable storage medium comprising stored instructions, the instructions when executed by one or more processors cause the one or more processors to:

generate, on a mobile device, a one-time password for authentication of an application, wherein the one-time password expires after a first use or after a predetermined period of time;

retrieve a short code associated with an application server, wherein the application server corresponds to the application;

transmit, to a telecommunications server, an Unstructured Supplementary Service Data (“USSD”) message, wherein the USSD message comprises the one-time password, a telephone number associated with the mobile device, and the short code;

transmit, to the application server, an authentication request, wherein the authentication request comprises the one-time password and the telephone number associated with the mobile device;

receive, in response to determining that the telephone number, the one-time password, and a current date within the authentication request match a telephone number, a one-time password and an updated date in a database entry, an authentication token for the mobile device, wherein the authentication token maintains a connection for the mobile device and the application server to securely send and receive data; and

transmit, from the mobile device to the application server, a request for data, the request comprising the authentication token that is used by the application server to authenticate the request.

10. The non-transitory computer readable storage medium of claim 9 , further comprising stored instructions that cause the one or more processors to:

determine a number of telephone numbers associated with the mobile device;

enable for display on the mobile device, in response to determining that more than one telephone number is associated with the mobile device, a prompt for selecting one of the telephone numbers to transmit to the telecommunications server.

11. The non-transitory computer readable storage medium of claim 9 , wherein the instructions that cause the one or more processors to transmit the authentication request to the application server further comprises instructions that cause the one or more processors to transmit a request for the authentication token.

12. The non-transitory computer readable storage medium of claim 9 , wherein the instructions that cause the one or more processors to retrieve the short code associated with the application server further comprises instructions that cause the one or more processors to:

retrieve the telephone number associated with the mobile device;

determine, based on the telephone number associated with the mobile device a region associated with the mobile device; and

select the short code based on the region associated with the mobile device.

13. A non-transitory computer readable medium comprising stored instructions, the instructions when executed by one or more processors cause the one or more processors to:

receive, from a telecommunications server, a USSD message generated on a mobile device, wherein the USSD message comprises a one-time password and a telephone number associated with the mobile device, and a short code associated with an application server corresponding to an application;

store a database entry in a database, wherein the database entry comprises a one-time password, a telephone number, and an updated date corresponding to a date when the one-time password was received in the USSD message;

receive, from the mobile device, an authentication request, wherein the authentication request comprises the one-time password and the telephone number;

determine, whether 1) the telephone number within the authentication request matches the telephone number in the database entry, 2) the one-time password in the authentication request matches the one-time password in the database entry, and 3) a current date corresponding to when the authentication request was transmitted matches the updated date in the database entry; and

generate, in response to determining that 1) the telephone number within the authentication request matches the telephone number in the database entry, 2) the one-time password in the authentication request matches the one-time password that in the database entry, and 3) the updated date in the database entry matches the current date, an authentication token for the mobile device, wherein the authentication token maintains a connection for the mobile device and the application server to securely send and receive data; and

transmit the authentication token to the mobile device, wherein the applications server receives requests for data from the mobile device, the requests for data comprising the authentication token.

14. The non-transitory computer readable storage medium of claim 13 , wherein the instructions that cause the one or more processors to store the database entry further comprises instructions that cause the one or more processors to:

store a timestamp for a time when the one-time password was generated; and

store a value in the database entry indicating whether the one-time password was used for authentication.

15. The non-transitory computer readable storage of claim 14 , further comprises stored instructions that cause the one or more processors to:

determine, based on the timestamp, whether the one-time password is expired,

determining based on the value in the database entry whether the one-time password has been already used; and

transmit, in response to the determination, based on the timestamp, that the one-time password is expired, or determination, based on the value in the database entry, that the one-time password has been already used, transmit a response to the mobile device that authentication has failed.

16. The non-transitory computer readable storage of claim 13 , further comprises stored instructions that cause the processor to receive a failure indication in response to the authentication request being unsuccessful.

17. A system for providing authentication for mobile devices, the system comprising a mobile device configured to:

generate, on the mobile device, a one-time password for authentication of an application, wherein the one-time password expires after a first use or after a predetermined period of time;

retrieve a short code associated with an application server, wherein the application server corresponds to the application;

transmit, to a telecommunications server, an Unstructured Supplementary Service Data (“USSD”) message, wherein the USSD message comprises the one-time password, a telephone number associated with the mobile device, and the short code;

transmit, to the application server, an authentication request, wherein the authentication request comprises the one-time password and the telephone number associated with the mobile device;

receive, in response to determining that the telephone number, the one-time password, and a current date within the authentication request match a telephone number, a one-time password and an updated date in a database entry, an authentication token for the mobile device, wherein the authentication token maintains a connection for the mobile device and the application server to securely send and receive data; and

transmit, from the mobile device to the application server, a request for data, the request comprising the authentication token that is used by the application server to authenticate the request.

18. The system of claim 17 , wherein the mobile device is further configured to:

determine a number of telephone numbers associated with the mobile device;

enable for display on the mobile device, in response to determining that more than one telephone number is associated with the mobile device, a prompt for selecting one of the telephone numbers to transmit to the telecommunications server.

19. A system for authenticating mobile devices, the system comprising an application server configured to:

receive, from a telecommunications server, a USSD message generated on a mobile device, wherein the USSD message comprises a one-time password and a telephone number associated with the mobile device, and a short code associated with an application server corresponding to an application;

storing a database entry in a database, wherein the database entry comprises a one-time password, a telephone number, and an updated date corresponding to a date when the one-time password was received in the USSD message;

receive, from the mobile device, an authentication request, wherein the authentication request comprises the one-time password and the telephone number;

determine, whether 1) the telephone number within the authentication request matches the telephone number in the database entry, 2) the one-time password in the authentication request matches the one-time password in the database entry, and 3) a current date corresponding to when the authentication request was transmitted matches the updated date in the database entry; and

generate, in response to determining that 1) the telephone number within the authentication request matches the telephone number in the database entry, 2) the one-time password in the authentication request matches the one-time password that in the database entry, and 3) the updated date in the database entry matches the current date, an authentication token for the mobile device, wherein the authentication token maintains a connection for the mobile device and the application server to securely send and receive data; and

transmitting the authentication token to the mobile device, wherein the applications server receives requests for data from the mobile device, the requests for data comprising the authentication token.

20. The system of claim 19 , wherein storing the database entry further comprises:

storing a timestamp for a time when the one-time password was generated; and

storing a value in the database entry indicating whether the one-time password was used for authentication.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2020
From: TRIEST, PATRICK NELSON; MOUJALED, MAIJID
To: CRITICAL IDEAS, INC.
Reel/Frame 053409/0219 →
Continuity (2)
Provisional Application 62885083 · Aug 9, 2019
Related Publication 20210044975A1 · Feb 11, 2021