IP Library Granted Patent US 11,706,031
Granted Patent B2
US 11,706,031 · App. 17/343,276 · Granted Jul 18, 2023

Security authentication system for membership login of online website and method thereof

Inventor: Jin Yong Lee (Seongnam-si Gyeonggi-do, KR)
Assignee: eBay Korea Co., Ltd.
H04L9/3228G06F21/36G06F21/42G06Q20/3274G06Q20/3276G06Q20/385G06Q20/3827G06Q20/4014G06Q20/425H04L9/08H04L9/32H04L9/3236H04L63/0838H04L63/18H04W12/068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,706,031
App. No.
17/343,276
Granted
Jul 18, 2023
Kind
B2
Abstract

A security authentication system for a website provides a safe login without having to directly enter an ID and a password on a user device requesting login to the website. A first user device receives one-time use authentication information from a second user device after the second user device received the one-time use authentication information from an authentication server without the authentication server receiving user login authentication information from the second user device. A request is transmitted to the authentication server based on the one-time use authentication information and the user login authentication information. In response to the request, one-time password (OTP) information is received from the authentication server. The OTP information is presented by the first user device, such that the OTP information can be entered into the second user device and used in a request to log in to the website.

Claims (40)

1. A computer system for a first user device comprising:

one or more processors; and

one or more machine-readable media storing computer-useable instructions that cause the processors to:

receive one-time use authentication information for a website, the one-time use authentication information being received from a second user device after the second user device received the one-time use authentication information from an authentication server without the authentication server receiving user login authentication information for the website from the second user device;

cause transmission, to the authentication server, of a request based on the one-time use authentication information and the user login authentication information;

receive, in response to the request, one-time password (OTP) information for the website provided by the authentication server; and

cause presentation of the OTP information.

2. The computer system of claim 1 , wherein the one-time use authentication information is received by:

scanning a QR code presented by the second user device; and

identifying the one-time user authentication information based on the QR code.

3. The computer system of claim 1 , wherein the one-time use authentication information is generated by the authentication server in response to a request, from the second user device, to log in to the website.

4. The computer system of claim 3 , wherein the one-time use authentication information is generated by the authentication server based at least in part on an IP address of the second user device and/or a time stamp corresponding to a time of issuance of the one-time use authentication information.

5. The computer system of claim 1 , wherein transmission of the request to the authentication server causes the authentication server to generate the OTP information in response to verifying the request.

6. The computer system of claim 1 , wherein the OTP information is generated based at least in part on an IP address of the first user device, the one-time use authentication information, the user login authentication information, and/or an IP address of the second user device.

7. The computer system of claim 1 , wherein the second user device submits a login request to the authentication server based on the OTP information.

8. A computer-implemented method comprising:

receiving, at a first user device, one-time use authentication information for a website, the one-time use authentication information being received from a second user device after the second user device received the one-time use authentication information from an authentication server without the authentication server receiving user login authentication information for the website from the second user device;

causing transmission, to the authentication server, of a request based on the one-time use authentication information and the user login authentication information;

receiving, in response to the request, one-time password (OTP) information for the website provided by the authentication server; and

causing presentation of the OTP information.

9. The computer-implemented method of claim 8 , wherein receiving the one-time use authentication information comprises:

scanning a QR code presented by the second user device; and

identifying the one-time user authentication information based on the QR code.

10. The computer-implemented method of claim 8 , wherein the one-time use authentication information is generated by the authentication server in response to a request, from the second user device, to log in to the website.

11. The computer-implemented method of claim 10 , wherein the one-time use authentication information is generated by the authentication server based at least in part on an IP address of the second user device and/or a time stamp corresponding to a time of issuance of the one-time use authentication information.

12. The computer-implemented method of claim 8 , wherein transmission of the request to the authentication server causes the authentication server to generate the OTP information in response to verifying the request.

13. The computer-implemented method of claim 8 , wherein the OTP information is generated based at least in part on an IP address of the first user device, the one-time use authentication information, the user login authentication information, and/or an IP address of the second user device.

14. The computer-implemented method of claim 8 , wherein the second user device submits a login request to the authentication server based on the OTP information.

15. One or more machine-readable media storing computer-useable instructions that, when used by one or more processors, cause a first user device to perform operations, the operations comprising:

receiving one-time use authentication information for a website, the one-time use authentication information being received from a second user device after the second user device received the one-time use authentication information from an authentication server without the authentication server receiving user login authentication information for the website from the second user device;

causing transmission, to the authentication server, of a request based on the one-time use authentication information and the user login authentication information;

receiving, in response to the request, one-time password (OTP) information for the website provided by the authentication server; and

causing presentation of the OTP information.

16. The one or more machine-readable media of claim 15 , wherein receiving the one-time use authentication information comprises:

scanning a QR code presented by the second user device; and

identifying the one-time user authentication information based on the QR code.

17. The one or more machine-readable media of claim 15 , wherein the one-time use authentication information is generated by the authentication server in response to a request, from the second user device, to log in to the website.

18. The one or more machine-readable media of claim 17 , wherein the one-time use authentication information is generated by the authentication server based at least in part on an IP address of the second user device and/or a time stamp corresponding to a time of issuance of the one-time use authentication information.

19. The one or more machine-readable media of claim 15 , wherein transmission of the request to the authentication server causes the authentication server to generate the OTP information in response to verifying the request.

20. The one or more machine-readable media of claim 15 , wherein the OTP information is generated based at least in part on an IP address of the first user device, the one-time use authentication information, the user login authentication information, and/or an IP address of the second user device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2021
From: EBAY KOREA CO. LTD.
To: EBAY INC.
Reel/Frame 057865/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2021
From: LEE, JIN YONG
To: EBAY KOREA CO., LTD.
Reel/Frame 056489/0671 →