IP Library Granted Patent US 11,386,194
Granted Patent B1
US 11,386,194 · App. 17/372,393 · Granted Jul 12, 2022

Generating and validating activation codes without data persistence

Inventor: Kazimieras Celiesius (Vilnius, LT)
Assignee: Oversec, UAB
G06F21/44H04L9/0643H04L63/0876G06F21/31G06F2221/2129H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,386,194
App. No.
17/372,393
Granted
Jul 12, 2022
Kind
B1
Abstract

The current embodiments offer a method to generate, send, and authenticate users through validations codes without the need for data retention. Codes are generated each time they are sent and received based on original and identifiable inputs. They are then compared to authenticate a user. Eliminating the need for data retention or persistence removes the risks associated with keeping data on the service provider's storage as can be maliciously accessed.

Claims (61)

1. A method for authenticating a user device at a service provider server, the method comprising:

receiving, at the service provider server, from the user device, an identifier and a first timestamp, wherein the user device is remote to the service provider server;

validating, at the service provider server, the first timestamp;

generating, at the service provider server, a first validation code;

sending, from the service provider server, the first validation code to the user device;

receiving, at the service provider server from the user device, the first validation code and the first timestamp to the user device;

validating, at the service provider server, the first timestamp;

generating, at the service provider server, the second validation code by same procedure as used to generate the first validation code;

comparing, at the service provider server, the first validation code and the second validation code; and

authenticating, at the service provider server, the user device, if the first validation code and the second validation code are a match within a predefined time threshold,

wherein the user device comprises at least two distinct devices, at least one of which authenticates with the service provider server and the other is used to open an email message.

2. The method of claim 1 , wherein the match of the first validation code and the second validation code results in the authentication of the user device.

3. The method of claim 1 , wherein the first validation code consists of at least one hash function and at least one cryptographic server secret.

4. The method of claim 1 , wherein the generation of the first validation code includes a numeric upper limit.

5. The method of claim 1 , wherein a failed match of the first validation code and the second validation code results in the failed authentication of the user device.

6. The method of claim 1 , wherein the identifier includes at least one of the following:

an email address,

a Hardware ID,

a Software Generated ID, or

a Network ID.

7. An apparatus for authenticating a user device, at a service provider server, the apparatus comprising the service provider server, the service provider server comprising:

a least one processor; and

a memory communicably coupled to the at least one processor, the memory comprising computer-executable instructions, which when executed by the at least one processor perform a method comprising:

receiving, at the service provider server, from the user device, an identifier and a first timestamp, wherein the user device is remote to the service provider server,

validating, at the service provider server, the first timestamp,

generating, at the service provider server, a first validation code,

sending, from the service provider server, the first validation code to the user device,

receiving, at the service provider server from the user device, the first validation code and the first timestamp to the user device,

validating, at the service provider server, the first timestamp,

generating, at the service provider server, the second validation code by same procedure as used to generate the first validation code,

comparing, at the service provider server, the first validation code and the second validation code, and

authenticating, at the service provider server, the user device, if the first validation code and the second validation code are a match within a predefined time threshold,

wherein the user device comprises at least two distinct devices, at least one of which authenticates with the service provider server and the other is used to open an email message.

8. The apparatus of claim 7 , wherein the match of the first validation code and the second validation code results in the authentication of the user device.

9. The apparatus of claim 7 , wherein the first validation code consists of at least one hash function and at least one cryptographic server secret.

10. The apparatus of claim 7 , wherein the generation of the first validation code includes a numeric upper limit.

11. The apparatus of claim 7 , wherein a failed match of the first validation code and the second validation code results in the failed authentication of the user device.

12. The apparatus of claim 7 , wherein the identifier includes at least one of the following:

an email address,

a Hardware ID,

a Software Generated ID, or

a Network ID.

13. An non-transitory computer readable storage medium comprising computer-executable instructions, which when executed by at least one processor, are configured to perform a method comprising:

receiving, at the service provider server, from the user device, an identifier and a first timestamp, wherein the user device is remote to the service provider server;

validating, at the service provider server, the first timestamp;

generating, at the service provider server, a first validation code;

sending, from the service provider server, the first validation code to the user device;

receiving, at the service provider server from the user device, the first validation code and the first timestamp to the user device;

validating, at the service provider server, the first timestamp;

generating, at the service provider server, the second validation code by same procedure as used to generate the first validation code,

comparing, at the service provider server, the first validation code and the second validation code, and

authenticating, at the service provider server, the user device, if the first validation code and the second validation code are a match within a predefined time threshold,

wherein the user device comprises at least two distinct devices, at least one of which authenticates with the service provider server and the other is used to open an email message.

14. The non-transitory computer readable storage medium of claim 13 , wherein the match of the first validation code and the second validation code results in the authentication of the user device.

15. The non-transitory computer readable storage medium of claim 13 , wherein the first validation code consists of at least one hash function and at least one cryptographic server secret.

16. The non-transitory computer readable storage medium of claim 13 , wherein a failed match of the first validation code and the second validation code results in the failed authentication of the user device.

17. The non-transitory computer readable storage medium of claim 13 , wherein the identifier includes at least one of the following:

an email address,

a Hardware ID,

a Software Generated ID, or

a Network ID.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2025
From: OVERSEC, UAB
To: UAB 360 IT
Reel/Frame 070202/0565 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2022
From: CELIESIUS, KAZIMIERAS
To: OVERSEC, UAB
Reel/Frame 059879/0893 →