IP Library Granted Patent US 12,003,502
Granted Patent B2
US 12,003,502 · App. 17/446,023 · Granted Jun 4, 2024

Method, apparatus, and computer program product for secure two-factor authentication

Inventors: Patrick G. Traynor (Gainesville, FL); Christian Peeters (Gainesville, FL); Christopher Patton (San Francisco, CA); Imani Sherman (Cincinnati, OH); Daniel Olszewski (Gainesville, FL); Thomas Shrimpton (Gainesville, FL)
Assignee: UNIVERSITY OF FLORIDA RESEARCH FOUNDATION, INCORPORATED
H04L63/0838H04L63/0435H04L63/166H04W4/14H04W12/0431H04W12/069H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,003,502
App. No.
17/446,023
Granted
Jun 4, 2024
Kind
B2
Abstract

Various methods are provided for secure two-factor authentication, and more specifically, for incorporating a layer of security to two-factor authentication using Short Message Service in a manner virtually transparent to the end-user. Methods may include receiving a request for registration for two-factor authentication from a client including a username and password; providing a request for a mobile device number; receiving the mobile device number and a pre-shared key; sending to a mobile device an identity of the client and a server key share; receiving from the mobile device a mobile device key share; sending information corresponding to an exchange with the mobile device and a challenge derived from the pre-shared key to the client in response to the device key share corresponding to the server key share; receiving confirmation of registration with the mobile device; and establishing a shared key in response to verification of the confirmation.

Claims (57)

1. An apparatus comprising at least one processor and at least one non-transitory memory including computer program code instructions, the computer program code instructions configured to, when executed, cause the apparatus to at least:

receive a request for registration for two-factor authentication from a client;

receive a username and password;

provide a request for a mobile device number in response to the username and password corresponding to an account;

receive the mobile device number and a pre-shared key;

send, to a mobile device corresponding to the mobile device number, an identity of the client and a server key share;

receive, from the mobile device, a device key share;

send information corresponding to an exchange with the mobile device and a challenge derived from the pre-shared key to the client in response to the device key share corresponding to the server key share;

receive, from the client, confirmation of registration with the mobile device;

establish a shared key in response to verification of the confirmation;

receive an access request including the username and password;

select a random string;

transmit the random string to the mobile device via short message service (SMS);

receive a one-time password from the mobile device derived from the random string, wherein the one-time password is derived by computing a Media Access Control (MAC) address and truncating the MAC address to obtain the one-time password; and

allow the access request in response to the one-time password corresponding to the random string based on the shared key.

2. The apparatus of claim 1 , wherein the mobile device number and the pre-shared key are received over a transport layer security (TLS) encrypted channel.

3. The apparatus of claim 1 , wherein the shared key is used for two-factor authentication of the username and password for subsequent login.

4. The apparatus of claim 1 , wherein the apparatus is further caused to provide information to the client encrypted with the shared key.

5. The apparatus of claim 1 , wherein the MAC address is computed from the shared key.

6. A computer program product comprising at least one non-transitory computer-readable storage medium having computer-executable program code instructions stored therein, the computer-executable program code instructions comprising program code instructions to:

receive a request for registration for two-factor authentication from a client;

receive a username and password;

provide a request for a mobile device number in response to the username and password corresponding to an account;

receive the mobile device number and a pre-shared key;

send, to a mobile device corresponding to the mobile device number, an identity of the client and a server key share;

receive, from the mobile device, a device key share;

send information corresponding to an exchange with the mobile device and a challenge derived from the pre-shared key to the client in response to the device key share corresponding to the server key share;

receive from the client, confirmation of registration with the mobile device;

establish a shared key in response to verification of the confirmation;

receive an access request including the username and password;

select a random string;

transmit the random string to the mobile device via short message service (SMS);

receive a one-time password from the mobile device derived from the random string, wherein the one-time password is derived by computing a Media Access Control (MAC) address and truncating the MAC address to obtain the one-time password; and

allow the access request in response to the one-time password corresponding to the random string based on the shared key.

7. The computer program product of claim 6 , wherein the mobile device number and the pre-shared key are received over a transport layer security (TLS) encrypted channel.

8. The computer program product of claim 6 , wherein the shared key is used for two-factor authentication of the username and password for subsequent login.

9. The computer program product of claim 6 , further comprising program code instructions to provide information to the client encrypted with the shared key.

10. The computer program product of claim 6 , wherein the MAC address is computed from the shared key.

11. A method for registering two-factor authentication comprising:

receiving a request for registration for two-factor authentication from a client;

receiving a username and password;

providing a request for a mobile device number in response to the username and password corresponding to an account;

receiving the mobile device number and a pre-shared key;

sending, to a mobile device corresponding to the mobile device number, an identity of the client and a server key share;

receiving, from the mobile device, a device key share;

sending information corresponding to an exchange with the mobile device and a challenge derived from the pre-shared key to the client in response to the device key share corresponding to the server key share;

receiving from the client, confirmation of registration with the mobile device;

establishing shared key in response to verification of the confirmation;

receiving an access request including the username and password;

selecting a random string;

transmitting the random string to the mobile device via short message service (SMS);

receiving a one-time password from the mobile device derived from the random string, wherein the one-time password is derived by computing a Media Access Control (MAC) address and truncating the MAC address to obtain the one-time password; and

allowing the access request in response to the one-time password corresponding to the random string based on the shared key.

12. The method of claim 11 , wherein the mobile device number and the pre-shared key are received over a transport layer security (TLS) encrypted channel.

13. The method of claim 11 , wherein the shared key is used for two-factor authentication of the username and password for subsequent login.

14. The method of claim 11 , further comprising providing information to the client encrypted with the shared key.

15. The method of claim 11 , wherein the MAC address is computed from the shared key.

Assignments (2)
CONFIRMATORY LICENSE Recorded Apr 4, 2025
From: UNIVERSITY OF FLORIDA
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 070743/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2021
From: TRAYNOR, PATRICK G.; PEETERS, CHRISTIAN; PATTON, CHRISTOPHER; SHERMAN, IMANI; OLSZEWSKI, DANIEL; SHRIMPTON, THOMAS
To: UNIVERSITY OF FLORIDA RESEARCH FOUNDATION, INCORPORATED
Reel/Frame 057301/0856 →
Continuity (2)
Provisional Application 63076131 · Sep 9, 2020
Related Publication 20220078184A1 · Mar 10, 2022