IP Library › Granted Patent US 12,556,370
Granted Patent B2
US 12,556,370 · App. 18/581,850 · Granted Feb 17, 2026

Systems and methods of cloud-based multifactor authentication

Inventor: Ryan McMillen (Modesto, CA)
Assignee: McMillen Holdings, Inc
H04L9/0656H04L9/0863H04L9/0866
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,370
App. No.
18/581,850
Granted
Feb 17, 2026
Kind
B2
Abstract

A method may include receiving, by a multifactor authentication (MFA) service instantiated on a computing system, a token generated by a cloud services provider and associated with a user device. The MFA service may be instantiated within a tenancy of the cloud services provider. The method may include determining, by the computing system, an authorized cloud service instantiated within the tenancy. The method may include receiving, by the computing system, a request to access the authorized cloud service by the user device, where the request may include a multi-factor authentication request. The method may include generating, by the MFA service instantiated on the computing system, a one-time pad (OTP). The method may include providing, by the MFA service instantiated on the computing system, the OTP to the user device such that the user device accesses the authorized cloud service.

Claims (43)

1 . A method, comprising:

receiving, by a multifactor authentication (MFA) service instantiated on a computing system, a token generated by a cloud services provider and associated with a user device, the MFA service instantiated within a tenancy of the cloud services provider;

determining, by the computing system, an authorized cloud service instantiated within the tenancy;

receiving, by the computing system, a request to access the authorized cloud service by the user device, wherein the request comprises a multi-factor authentication request;

generating, by the MFA service instantiated on the computing system, an one-time pad (OTP); and

providing, by the MFA service instantiated on the computing system, the OTP to the user device such that the user device accesses the authorized cloud service.

2 . The method of claim 1 , wherein the request to access the authorized cloud service includes a set of credentials used to validate the user device with the MFA service.

3 . The method of claim 1 , wherein the OTP comprises a temporary access pass (TAP).

4 . The method of claim 1 , wherein the OTP comprises a time-based one-time password.

5 . The method of claim 1 , wherein generating, by the MFA service instantiated on the computing system, the OTP further comprises:

accessing, by the MFA service instantiated on the computing system, a database comprising a key associated with the authorized cloud service; and

generating, by the MFA service instantiated on the computing system, the OTP utilizing hash with the key associated with the authorized cloud service.

6 . The method of claim 5 , wherein the database is a multitenant database comprising a plurality of keys associated with respective cloud services.

7 . The method of claim 1 , wherein the OTP is provided to the user device via a browser plugin.

8 . A system, comprising:

one or more processors; and

a non-transitory computer memory, comprising instructions that, when executed by the one or more processors, cause the system to perform operations to:

receive, by an MFA service instantiated on a computing system, a token generated by a cloud services provider and associated with a user device, the MFA service instantiated within a tenancy of the cloud services provider;

determine, by the computing system, an authorized cloud service instantiated within the tenancy;

receive, by the computing system, a request to access the authorized cloud service by the user device, wherein the request comprises a multi-factor authentication request;

generate, by the MFA service instantiated on the computing system, a one-time pad (OTP); and

provide, by the MFA service instantiated on the computing system, the OTP to the user device such that the user device accesses the authorized cloud service.

9 . The system of claim 8 , wherein the request to access the authorized cloud service includes a set of credentials used to validate the user device with the MFA service.

10 . The system of claim 8 , wherein the OTP comprises a temporary access pass (TAP).

11 . The system of claim 8 , wherein the OTP comprises a time-based one-time password.

12 . The system of claim 8 , wherein to generate, by the MFA service instantiated on the computing system, the OTP, the operations further cause the system to:

access, by the MFA service instantiated on the computing system, a database comprising a key associated with the authorized cloud service; and

generate, by the MFA service instantiated on the computing system, the OTP utilizing a hash and the key associated with the authorized cloud service.

13 . The system of claim 12 , wherein the database is a multitenant database comprising a plurality of keys associated with respective cloud services.

14 . The system of claim 8 , wherein the OTP is provided to the user device via a browser plugin.

15 . A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving, by a multifactor authentication (MFA) service instantiated on a computing system, a token generated by a cloud services provider and associated with a user device, the MFA service instantiated within a tenancy of the cloud services provider;

determining, by the computing system, an authorized cloud service instantiated within the tenancy;

receiving, by the computing system, a request to access the authorized cloud service by the user device, wherein the request comprises a multi-factor authentication request;

generating, by the MFA service instantiated on the computing system, an one-time pad (OTP); and

providing, by the MFA service instantiated on the computing system, the OTP to the user device such that the user device accesses the authorized cloud service.

16 . The non-transitory computer-readable medium of claim 15 , wherein the request to access the authorized cloud service includes a set of credentials used to validate the user device with the MFA service.

17 . The non-transitory computer-readable medium of claim 15 , wherein the OTP comprises a temporary access pass (TAP).

18 . The non-transitory computer-readable medium of claim 15 , wherein the OTP comprises a time-based one-time password.

19 . The non-transitory computer-readable medium of claim 15 , wherein generating, by the MFA service instantiated on the computing system, the OTP further comprises:

accessing, by the MFA service instantiated on the computing system, a database comprising a key associated with the authorized cloud service; and

generating, by the MFA service instantiated on the computing system, the OTP utilizing a hash and the key associated with the authorized cloud service.

20 . The non-transitory computer-readable medium of claim 19 , wherein the database is a multitenant database comprising a plurality of keys associated with respective cloud services.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2024
From: MCMILLEN, RYAN
To: MCMILLEN HOLDINGS, INC: DBA RYANTECH
Reel/Frame 066501/0770 →
Continuity (1)
Related Publication 20250266985A1 · Aug 21, 2025
References Cited (16)
US 11570180B1 · Fitzpatrick · 2023 [cited by examiner]
US 12267431B2 · Sutherland · 2025 [cited by examiner]
US 20160171492A1 · Carrott · 2016 [cited by examiner]
US 20190043045A1 · Wilson · 2019 [cited by examiner]
US 20190222424A1 · Lindemann · 2019 [cited by examiner]
US 20190295074A1 · Carrott · 2019 [cited by examiner]
US 20190306156A1 · Agarwal · 2019 [cited by examiner]
US 20220078005A1 · Lanc · 2022 [cited by examiner]
US 20230208644A1 · Fitzpatrick · 2023 [cited by examiner]
US 20250124438A1 · Lindemann · 2025 [cited by examiner]
US 20250266985A1 · McMillen · 2025 [cited by examiner]
US 20250300963A1 · Sutherland · 2025 [cited by examiner]
Konwar, Rajashree et al. A Two-Factor Authentication Mechanism Using a Novel OTP Generation Algorithm for Cloud Applications. 2024 14th International Conference on Cloud Computing, Data Science & Engineering (Confluence… [cited by examiner]
Hassan, Md Arif; Shukur, Zarina. A Secure Multi Factor User Authentication Framework for Electronic Payment System. 2021 3rd International Cyber Resilience Conference (CRC). https://ieeexplore.ieee.org/stamp/stamp.jsp?t… [cited by examiner]
Soares, Liliana F.B. et al. Secure user authentication in cloud computing management interfaces. 2013 IEEE 32nd International Performance Computing and Communications Conference (IPCCC). https://ieeexplore.ieee.org/stam… [cited by examiner]
Ahmed, Abdulghani Ali et al. Dynamic Reciprocal Authentication Protocol for Mobile Cloud Computing. IEEE Systems Journal, vol. 15, Issue: 1. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9180352 (Year: 2021). [cited by examiner]