IP Library Granted Patent US 12,355,899
Granted Patent B2
US 12,355,899 · App. 17/046,721 · Granted Jul 8, 2025

Deep link authentication

Inventor: Feng Chi Wang (Austin, TX)
Assignee: Visa International Service Association
H04L9/3271G06F21/31G06F40/134H04L63/0838H04L63/0853H04L67/02G06Q20/3821G06Q20/401
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,899
App. No.
17/046,721
Granted
Jul 8, 2025
Kind
B2
Abstract

A method and system for authentication through deep-links is provided. A communication device can provide a credential to a remote server computer as part of an authentication process. The remote server computer can challenge the communication device by transmitting a deep-link containing a one-time passcode to the communication device. The communication device can activate and parse the deep-link to determine the one-time passcode. The one-time passcode can be transmitted back to the remote server computer by the communication device. The remote server computer can verify that received one-time passcode matches the sent one-time passcode in order to complete the authentication process.

Claims (54)

1. A method comprising:

generating, by a remote server computer, a one-time passcode;

storing, by the remote server computer, the one-time passcode or a derivative of the one-time passcode as a stored one-time passcode;

generating, by the remote server computer, a link having the one-time passcode or the derivative embedded therein, the link being generated in response to receiving a credential from a communication device, wherein the link is generated based on characteristic information of the communication device;

transmitting, by the remote server computer, the link to a communications application executing on the communication device, wherein the communication device determines the one-time passcode by activating the link, wherein activating the link causes the communications application to: (i) determine, based on information included in the link, a host application of a plurality of host applications that is to be executed on the communication device, and (ii) change a display of the communication device by rendering a graphical user interface associated with the host application, the host application extracting the one-time passcode from the link;

receiving, by the remote server computer, the one-time passcode from the communication device;

verifying, by the remote server computer, that the one-time passcode received from the communication device or the derivative of the one-time passcode received from the communication device matches the stored one-time passcode or the derivative of the stored one-time passcode;

transmitting an authentication message to the communication device; and

providing, to the communication device, access to a resource based on authenticating the communication device, wherein the authentication message comprises an authentication cookie enabling the communication device to access the resource associated with the remote server computer.

2. The method of claim 1 , further comprising:

verifying, by the remote server computer, that the credential matches a corresponding credential in a credential database;

transmitting, by the remote server computer, a link confirmation message to the communication device; and

receiving a link confirmation response from the communication device, wherein the link confirmation response comprises an electronic address associated with the communication device, wherein the electronic address is an email address or telephone number.

3. The method of claim 2 , wherein the one-time passcode or the derivative of the one-time passcode is stored in association with the credential.

4. The method of claim 2 , wherein the link confirmation response additionally comprises a link format, wherein the link is generated based on the link format and the one-time passcode.

5. The method of claim 4 , wherein the link format corresponds to one or more communication device characteristics.

6. The method of claim 1 ,

wherein the credential comprises a username and password.

7. A remote server computer comprising:

a processor; and

a non-transitory computer readable medium coupled to the processor, the non-transitory computer readable medium comprising code executable by the processor for performing a method comprising:

generating a one-time passcode;

storing the one-time passcode or a derivative of the one-time passcode as a stored one-time passcode;

generating a link having the one-time passcode or the derivative embedded therein, the link being generated in response to receiving a credential from a communication device, wherein the link is generated based on characteristic information of the communication device;

transmitting the link to a communications application executing on the communication device, wherein the communication device determines the one-time passcode by activating the link, wherein activating the link causes the communications application to: (i) determine, based on information included in the link, a host application of a plurality of host applications that is to be executed on the communication device, and (ii) change a display of the communication device by rendering a graphical user interface associated with the host application, the host application extracting the one-time passcode from the link;

receiving the one-time passcode from the communication device;

verifying that the one-time passcode received from the communication device or the derivative of the one-time passcode received from the communication device matches the stored one-time passcode or the derivative of the stored one-time passcode;

transmitting an authentication message to the communication device; and

providing to the communication device, access to a resource based on authenticating the communication device, wherein the authentication message comprises an authentication cookie enabling the communication device to access the re source associated with the remote server computer.

8. A remote server computer of claim 7 , further comprising:

verifying, by the remote server computer, that the credential matches a corresponding credential in a credential database;

transmitting, by the remote server computer, a link confirmation message to the communication device; and

receiving a link confirmation response from the communication device, wherein the link confirmation response comprises an electronic address associated with the communication device, wherein the electronic address is an email address or telephone number.

9. The remote server computer of claim 8 ,

the one-time passcode or the derivative of the one-time passcode is stored in association with the credential.

10. The remote server computer of claim 8 ,

wherein the link confirmation response additionally comprises a link format, wherein the link is generated based on the link format and the one-time passcode.

11. The remote server computer of claim 10 ,

wherein the link format corresponds to one or more communication device characteristics.

12. One or more computer readable non-transitory media storing computer-executable instructions that, when executed by one or more processors, cause:

generating, by a remote server computer, a one-time passcode;

storing, by the remote server computer, the one-time passcode or a derivative of the one-time passcode as a stored one-time passcode;

generating, by the remote server computer, a link having the one-time passcode or the derivative embedded therein, the link being generated in response to receiving a credential from a communication device, wherein the link is generated based on characteristic information of the communication device;

transmitting, by the remote server computer, the link to a communications application executing on the communication device, wherein the communication device determines the one-time passcode by activating the link, wherein activating the link causes the communications application to: (i) determine, based on information included in the link, a host application of a plurality of host applications that is to be executed on the communication device, and (ii) change a display of the communication device by rendering a graphical user interface associated with the host application, the host application extracting the one-time passcode from the link;

receiving, by the remote server computer, the one-time passcode from the communication device;

verifying, by the remote server computer, that the one-time passcode received from the communication device or the derivative of the one-time passcode received from the communication device matches the stored one-time passcode or the derivative of the stored one-time passcode;

transmitting an authentication message to the communication device; and

providing, to the communication device, access to a resource based on authenticating the communication device, wherein the authentication message comprises an authentication cookie enabling the communication device to access the resource associated with the remote server computer.

13. The one or more computer readable non-transitory media storing computer-executable instructions of claim 12 ,

wherein a link confirmation response comprises a link format, the link format corresponding to one or more communication device characteristics.

14. The one or more computer readable non-transitory media storing computer-executable instructions of claim 12 ,

wherein the one-time passcode or the derivative of the one-time passcode is stored in association with the credential.

15. The one or more computer readable non-transitory media storing computer-executable instructions of claim 13 ,

wherein the link confirmation response additionally comprises a link format, wherein the link is generated based on the link format and the one-time passcode.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2020
From: WANG, FENG CHI
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 054021/0588 →
Continuity (1)
Related Publication 20210166226A1 · Jun 3, 2021
References Cited (70)
US 7107221B1 · Tracy · 2006 [cited by examiner]
US 7684835B1 · Vu · 2010 [cited by examiner]
US 8881129B1 · McKinnon · 2014 [cited by examiner]
US 8935762B2 · Moas et al. · 2015 [cited by applicant]
US 9350548B2 · Bagley · 2016 [cited by applicant]
US 10255589B1 · Petruzzi · 2019 [cited by examiner]
US 20030046551A1 · Brennan · 2003 [cited by applicant]
US 20040064478A1 · Canesi · 2004 [cited by examiner]
US 20050138409A1 · Sheriff · 2005 [cited by examiner]
US 20050143050A1 · Foll · 2005 [cited by examiner]
US 20050228899A1 · Wendkos · 2005 [cited by examiner]
US 20060094403A1 · Norefors · 2006 [cited by examiner]
US 20060136739A1 · Brock · 2006 [cited by examiner]
US 20070055867A1 · Kanungo · 2007 [cited by examiner]
US 20070233605A1 · Mueller · 2007 [cited by examiner]
US 20100046508A1 · Vogel · 2010 [cited by examiner]
US 20100251331A1 · Li · 2010 [cited by examiner]
US 20100274732A1 · Grinchenko · 2010 [cited by examiner]
US 20110088085A1 · Novak · 2011 [cited by examiner]
US 20120130714A1 · Zeljkovic · 2012 [cited by examiner]
US 20120284797A1 · Seleznev · 2012 [cited by examiner]
US 20130055368A1 · Bauckman · 2013 [cited by examiner]
US 20140041009A1 · Kousaka · 2014 [cited by examiner]
US 20150244706A1 · Grajek et al. · 2015 [cited by applicant]
US 20150293764A1 · Visvanathan · 2015 [cited by examiner]
US 20150326672A1 · Chandwani · 2015 [cited by examiner]
US 20150379626A1 · Choudhury · 2015 [cited by examiner]
US 20160043870A1 · Avanzi · 2016 [cited by examiner]
US 20160048828A1 · Lee · 2016 [cited by examiner]
US 20160127348A1 · Bradley et al. · 2016 [cited by applicant]
US 20170054789A1 · Jneid · 2017 [cited by examiner]
US 20170325089A1 · Sharma et al. · 2017 [cited by applicant]
US 20170331824A1 · Pender · 2017 [cited by examiner]
US 20170337542A1 · Kim · 2017 [cited by examiner]
US 20180063126A1 · Karapantelakis · 2018 [cited by examiner]
US 20180146374A1 · Golan · 2018 [cited by examiner]
US 20190097796A1 · Wang · 2019 [cited by examiner]
US 20190141041A1 · Bhabbur · 2019 [cited by examiner]
US 20190296913A1 · Verma · 2019 [cited by examiner]
US 20190306153A1 · Girdhar · 2019 [cited by examiner]
US 20190312861A1 · Kairi · 2019 [cited by examiner]
US 20200210988A1 · Woodward · 2020 [cited by examiner]
US 20220188914A1 · Choudhury · 2022 [cited by examiner]
US 20250016246A1 · Kouru · 2025 [cited by examiner]
CN 101662364A · 2010 [cited by applicant]
CN 102202067A · 2011 [cited by applicant]
CN 103440279A · 2013 [cited by examiner]
CN 105207777A · 2015 [cited by examiner]
CN 105357242A · 2016 [cited by applicant]
JP 2002207680A · 2002 [cited by examiner]
JP 2013239925A · 2013 [cited by examiner]
WO WO200708540A2 · 2007 [cited by examiner]
WO WO2008127340A1 · 2008 [cited by examiner]
WO WO2013047534A1 · 2013 [cited by examiner]
WO WO2014030487A1 · 2014 [cited by examiner]
WO WO2016096282A1 · 2016 [cited by examiner]
WO WO2018042321A1 · 2018 [cited by examiner]
WO WO2019199282A1 · 2019 [cited by examiner]
Almulhim, Maria, and Noor Zaman. “Proposing secure and lightweight authentication scheme for IoT based E-health applications.” In 2018 20th International Conference on advanced communication technology (ICACT), pp. 481-… [cited by examiner]
Mahmoud, Khaled W. “Elastic password: A new mechanism for strengthening passwords using time delays between keystrokes.” In 2017 8th International Conference on Information and Communication Systems (ICICS), pp. 316-321… [cited by examiner]
Violaris, George, and Ioanna Dionysiou. “Out-of-Band Authentication Model with Hashcash Brute-Force Prevention.”, 2014 IEEE 11th Intl Conf on Embedded Software and Syst (HPCC, CSS, ICESS), pp. 794-801. IEEE, 2014. (Year… [cited by examiner]
Sun, He, Kun Sun, Yuewu Wang, and Jiwu Jing. “Reliable and trustworthy memory acquisition on smartphones.” IEEE Transactions on Information Forensics and Security 10, No. 12 (2015): 2547-2561. (Year: 2015). [cited by examiner]
Neuman, B. Clifford, and Theodore Ts'o. “Kerberos: An authentication service for computer networks.” IEEE Communications magazine 32, No. 9 (1994): 33-38. (Year: 1994). [cited by examiner]
Tan, Chik How, and Joseph Chee Ming Teo. “Protection againstweb-based password phishing.” In Fourth International Conference on Information Technology (ITNG'07), pp. 754-759. IEEE, 2007. (Year: 2007). [cited by examiner]
EP18914896.8 , “Extended European Search Report”, Dec. 18, 2020, 8 pages. [cited by applicant]
EP18914896.8 , “Notice of Decision to Grant”, Sep. 15, 2022, 2 pages. [cited by applicant]
SG11202009985W , “Written Opinion”, Aug. 23, 2022, 9 pages. [cited by applicant]
CN201880093654.X , “Office Action”, Sep. 21, 2022, 17 pages. [cited by applicant]
Application No. PCT/US2018/026898, International Search Report and Written Opinion, Mailed On Dec. 10, 2018, 13 pages. [cited by applicant]
Application No. SG11202009985W, Notice of Decision to Grant, Mailed On Oct. 31, 2023, 4 pages. [cited by applicant]