IP Library Granted Patent US 12,212,560
Granted Patent B2
US 12,212,560 · App. 18/357,788 · Granted Jan 28, 2025

Method for authorizing a secure access from a local device to a remote server computer

Inventors: Nicolas Johannes Sebastian Bettenburg (Stittsville, CA); Randy Kuang (Ottawa, CA)
Assignee: INBAT TECHNOLOGIES INC.
H04L63/083G06F16/9554G06F21/34G06F21/36G06F21/42G06F21/57G06K7/1417H04L63/0428H04L63/0838H04L63/0853H04L63/0869G06F2221/2115G06F2221/2117G06F2221/2141H04L63/0281H04L63/105H04W12/77
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,212,560
App. No.
18/357,788
Granted
Jan 28, 2025
Kind
B2
Abstract

A method for authorizing a secure access from a local device to a remote server computer is disclosed. At the local device having a unique identifier (UID), processor, and memory, a security software obtains a personal identification number (PIN) of a user, and the UID of the local device. Authenticity of the PIN and the UID is verified without communication over a network, using a credential code generated using the PIN, the UID and the security software. Upon verifying the authenticity of the PIN and the UID, access credentials to the remote server computer are retrieved, and the secure access to the remote server computer is authorized using the retrieved access credentials. The remote server computer has a copy of the security software, the PIN, the UID and the credential code.

Claims (41)

1. A method for authorizing a secure access from a local device to a remote server computer, the method comprising:

at the local device, having a unique identifier (UID), a processor, and a memory:

causing a security software to obtain a personal identification number (PIN) of a user, and the UID of the local device;

verifying an authenticity of the PIN and the UID, without communicating over a network, using a credential code generated using the PIN, the UID and the security software;

retrieving access credentials to the remote server computer upon verifying the authenticity of the PIN and the UID; and

authorizing the secure access to the remote server computer using the retrieved access credentials, the remote server computer having a copy of the security software, the PIN, the UID and the credential code.

2. The method of claim 1 further comprising:

obtaining a Quick Response, QR, code from the remote server computer; and

scanning the QR code into the local device.

3. The method of claim 1 wherein the authorizing secure access comprises authorizing access to an email server.

4. The method of claim 1 , comprising choosing the local device as one of the following:

a computing device, comprising a processor; or

a portable device having a memory, the portable device being different from the computing device, and being operably coupled to the computing device.

5. The method of claim 1 , comprising choosing a mobile wireless device as the local device.

6. The method of claim 1 , wherein the retrieving further comprises forwarding the retrieved access credentials to the remote server computer.

7. The method of claim 1 , wherein the authorizing the secure access further comprises performing a transaction authorization.

8. The method of claim 7 , wherein the performing a transaction authorization further comprises:

sending a transaction authorization request including the credential code from an authorization server to the local device;

at the local device, generating a transaction authorization response using the credential code; and

sending the transaction authorization response from the local device to a transaction server.

9. The method of claim 8 , wherein the sending comprises sending the transaction authorization response from the local device to the transaction server over a transaction authorization channel.

10. The method of claim 8 , wherein the sending further comprises:

sending the transaction authorization response from the local device to the authorization server; and

sending the transaction authorization response from the authorization server to the transaction server.

11. The method of claim 8 , wherein the sending further comprises sending the transaction authorization response from the local device to the authorization server over a transaction authorization channel.

12. The method of claim 8 wherein the sending further comprises sending the transaction authorization response from the authorization server to the transaction server over a service channel.

13. The method of claim 8 , further comprising sending a transaction request from a user terminal to the transaction server; and sending the transaction authorization response from the transaction server to the user terminal.

14. The method of claim 13 , wherein the sending the transaction request comprises sending the transaction request over a transaction channel.

15. The method of claim 13 , wherein the sending the transaction authorization response comprises sending the transaction authorization response over a transaction channel.

16. The method of claim 8 , further comprising sending a pre-authorization condition from the local device to the authorization server.

17. The method of claim 1 , further comprising:

establishing a connection to an authorization server comprising:

establishing a transaction channel, and

establishing a transaction notification channel; and

authorizing a user to access a service on a transaction server, using a client program executing on the local device and a server program executing on the authorization server.

18. The method of claim 17 , further comprising:

authorizing a transaction using the local device;

performing the transaction; and

closing the connection to the authorization server.

19. The method of claim 1 , wherein the remote server computer is a third party server computer.

20. The method of claim 1 , further comprising storing the UID of the local device in a database.

Assignments (2)
CHANGE OF ADDRESS Recorded Oct 10, 2023
From: INBAY TECHNOLOGIES INC.
To: INBAY TECHNOLOGIES INC.
Reel/Frame 065200/0106 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2023
From: BETTENBURG, NICOLAS; KUANG, RANDY
To: INBAY TECHNOLOGIES INC.
Reel/Frame 065209/0827 →
Continuity (22)
Continuation 17339844 · Jun 4, 2021
Continuation 16429777 · Jun 3, 2019
Continuation 15676872 · Aug 14, 2017
Continuation 15168850 · May 31, 2016
Continuation 14722002 · May 26, 2015
Continuation 14721996 · May 26, 2015
Continuation 14309369 · Jun 19, 2014
Continuation 14231545 · Mar 31, 2014
Continuation 13913399 · Jun 8, 2013
Continuation 13765049 · Feb 12, 2013
Continuation 13035830 · Feb 25, 2011
Continuation 12639464 · Dec 16, 2009
Provisional Application 62168905 · May 31, 2015
Provisional Application 62003160 · May 27, 2014
Provisional Application 61839218 · Jun 25, 2013
Provisional Application 61599556 · Feb 16, 2012
Provisional Application 61416270 · Nov 22, 2010
Provisional Application 61248047 · Oct 2, 2009
Provisional Application 61247223 · Sep 30, 2009
Provisional Application 61183830 · Jun 3, 2009
Provisional Application 61149501 · Feb 3, 2009
Related Publication 20240031357A1 · Jan 25, 2024
References Cited (88)
US 7363494B2 · Brainard et al. · 2008 [cited by applicant]
US 7475247B2 · Bade et al. · 2009 [cited by applicant]
US 7502933B2 · Jakobsson et al. · 2009 [cited by applicant]
US 7516483B2 · Brennan · 2009 [cited by applicant]
US 7562385B2 · Thione et al. · 2009 [cited by applicant]
US 7565536B2 · Vassilev et al. · 2009 [cited by applicant]
US 7805489B2 · Roberts · 2010 [cited by applicant]
US 7912916B2 · Rakowski et al. · 2011 [cited by applicant]
US 7925556B1 · Duncan et al. · 2011 [cited by applicant]
US 8201237B1 · Doane et al. · 2012 [cited by applicant]
US 8209381B2 · Sinn et al. · 2012 [cited by applicant]
US 8745699B2 · Ganesan · 2014 [cited by applicant]
US 9009814B1 · Wertz et al. · 2015 [cited by applicant]
US 9830445B1 · Machani · 2017 [cited by applicant]
US 20020023960A1 · Knowles · 2002 [cited by applicant]
US 20020033418A1 · Knowles · 2002 [cited by applicant]
US 20020115457A1 · Koscal · 2002 [cited by applicant]
US 20030009693A1 · Brock · 2003 [cited by applicant]
US 20030037261A1 · Meffert et al. · 2003 [cited by applicant]
US 20040046031A1 · Knowles · 2004 [cited by applicant]
US 20040073797A1 · Fascenda · 2004 [cited by examiner]
US 20040128547A1 · Laidlaw et al. · 2004 [cited by applicant]
US 20040243835A1 · Terzis et al. · 2004 [cited by applicant]
US 20050198501A1 · Andreev · 2005 [cited by applicant]
US 20050262083A1 · Brown · 2005 [cited by applicant]
US 20060041933A1 · Yakov · 2006 [cited by examiner]
US 20060198517A1 · Cameron · 2006 [cited by applicant]
US 20060206918A1 · McLean · 2006 [cited by applicant]
US 20060282662A1 · Whitcomb · 2006 [cited by applicant]
US 20060288228A1 · Botz · 2006 [cited by applicant]
US 20070022469A1 · Cooper · 2007 [cited by applicant]
US 20070056025A1 · Sachdeva et al. · 2007 [cited by applicant]
US 20070199054A1 · Florencio · 2007 [cited by applicant]
US 20070250920A1 · Lindsay · 2007 [cited by applicant]
US 20080028206A1 · Sicard et al. · 2008 [cited by applicant]
US 20080040783A1 · Larson et al. · 2008 [cited by applicant]
US 20080059804A1 · Shah · 2008 [cited by examiner]
US 20080075096A1 · Wagner · 2008 [cited by applicant]
US 20080162928A1 · Okaya · 2008 [cited by applicant]
US 20080209221A1 · Vennelakanti et al. · 2008 [cited by applicant]
US 20080212771A1 · Hauser · 2008 [cited by examiner]
US 20080222299A1 · Boodaei · 2008 [cited by applicant]
US 20080229402A1 · Smetters et al. · 2008 [cited by applicant]
US 20090125993A1 · Delia et al. · 2009 [cited by applicant]
US 20090132808A1 · Baentsch et al. · 2009 [cited by applicant]
US 20090158005A1 · Carmichael · 2009 [cited by applicant]
US 20090165121A1 · Kumar · 2009 [cited by applicant]
US 20090185687A1 · Wankmueller et al. · 2009 [cited by applicant]
US 20090198618A1 · Chan et al. · 2009 [cited by applicant]
US 20090203355A1 · Clark · 2009 [cited by applicant]
US 20090222910A1 · Le Bihan et al. · 2009 [cited by applicant]
US 20090225981A1 · Motohashi · 2009 [cited by applicant]
US 20090235339A1 · Mennes · 2009 [cited by applicant]
US 20090259839A1 · Jung et al. · 2009 [cited by applicant]
US 20090276840A1 · Cao et al. · 2009 [cited by applicant]
US 20090300721A1 · Schneider · 2009 [cited by applicant]
US 20090313691A1 · Chien · 2009 [cited by examiner]
US 20100180328A1 · Moas · 2010 [cited by applicant]
US 20100199098A1 · King · 2010 [cited by applicant]
US 20100229227A1 · Andre · 2010 [cited by examiner]
US 20100287070A1 · Santeufemia et al. · 2010 [cited by applicant]
US 20110296486A1 · Burch et al. · 2011 [cited by applicant]
US 20120033811A1 · Hawkes · 2012 [cited by applicant]
US 20120155358A1 · Hao · 2012 [cited by examiner]
US 20120174204A1 · Sturm · 2012 [cited by applicant]
US 20120235912A1 · Lauback · 2012 [cited by applicant]
US 20120260324A1 · Lenon et al. · 2012 [cited by applicant]
US 20130173484A1 · Wesby · 2013 [cited by applicant]
US 20130205404A1 · King · 2013 [cited by applicant]
US 20130227661A1 · Gupta · 2013 [cited by applicant]
WO 2007026228 · 2007 [cited by applicant]
WO 2008024454 · 2008 [cited by applicant]
Hayes et al., “Policy-based authentication and authorization: secure access to the network infrastructure”, Proceedings 16th Annual Computer Security Applications Conference (ACSAC'00), Date of Conference: Dec. 11-15, 2… [cited by examiner]
http://www.asseco-see.com/nbv5/images/stories/presentations/NBV%20Authentication.pdf, presented during “New Banking Vision 5”, from May 25-28 in Hotel “Sol Coral” Umag, Croatia, 2010. [cited by applicant]
Hegt, Stan “Analysis of Current and Future Phishing Attacks on Internet Banking Services”, May 2008. [cited by applicant]
Naumann, Ingo “Privacy and Security Risks When Authenticating on the Internet with European eID Cards”, Nov. 2009. [cited by applicant]
Schneier, Bruce “Schneier on Security”, A blog covering security and security technology, Nov. 23, 2004. [cited by applicant]
European Payments Council “Customer to Bank Security Good Practices Guide”, http://europeanpaymentscouncil.eu/documents, Mar. 15, 2009. [cited by applicant]
Cavoukian, Ann “Privacy by Design . . . Take the Challenge”, Aug. 2008. [cited by applicant]
Zhang, Dawei “Network Security Middleware Based on USB Key” 5th IEEE International Symposium on Embedded Computing, IEEE Computer Society, pp. 77-81, 2008. [cited by applicant]
http://www.sestus.com/vt/, Sestus, “Virtual Token Real Authentication”, 2008. [cited by applicant]
Menezes, et al., “Handbook of Applied Cryptography”, CRC Press LLC, 1997, pp. 359-363, pp. 388-391, pp. 394-399, pp. 490-491, pp. 548-549, XP002702416, USA. [cited by applicant]
International Search Report and Written Opinion dated May 18, 2010, International Application No. PCT/CA2010/000127. [cited by applicant]
Pashalidis, Andreas; Mitchell, Chris J., “Single Sign-on Using Trusted Platforms”, Royal Holloway, University of London, Egham, Surrey, TW20 0EX, United Kingdom, http://www.isg.rhul.ac.uk, pp. 1-15, 2003. [cited by applicant]
Boyd, David, “Single-On to the Web with an EMV Card”, International Symposium on Collaborative Technologies and Systems, May 2008, pp. 112-120. [cited by applicant]
MacKenzie et al., “Networked Cryptographic Devices Resilient to Capture”, Proceedings of the IEEE Symposium on Security and Privacy, May 2001, pp. 12-25. [cited by applicant]
Cavoukian, Ann, http://www.privacybydesign.ca/publications.htm, “Privacy by Design . . . Take the Challenge”, 2009. [cited by applicant]
Gao et al., “P2P-Paid: A Peer-to-Peer Wireless Payment System”, Second IEEE International Workshop on Mobile Commerce and Services, Date of Conference: Jul. 19-19, 2005. [cited by applicant]