IP Library › Granted Patent US 8,522,010
Granted Patent B2
US 8,522,010 · App. 12/254,115 · Granted Aug 27, 2013

Providing remote user authentication

Inventors: Raymond E. Ozzie (Seattle, WA); Jack E. Ozzie (North Bend, WA); Thomas A. Galvin (Amherst, NH); Eric M. Patey (Rockport, MA)
Assignee: Microsoft Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,522,010
App. No.
12/254,115
Granted
Aug 27, 2013
Kind
B2
Abstract

Providing a remote computer user authentication service involves providing a reference to a user authentication service in a host server's source code (e.g., website source code). Further, integration code that may be used in an application programming interface (API) on the host server for interaction with a user authentication service can be provided. Additionally, a user interface (UI) for user authentication on the host server, and an authentication-test message on the host server using the UI may be provided. Also, providing authentication can comprise sending an authentication-request message to a mobile device designated by the user; and/or can comprise the user responding with information from the authentication-test message. The host server can be notified of the user's authentication after a correct response is received by the user authentication service.

Claims (46)

1. A tangible computer readable storage medium comprising instructions that when executed perform a method, comprising:

providing a reference to a user authentication service for installation in source code of a host server, the reference associated with source code for an Iframe in a browser accessing the host server;

providing a user interface (UI) in the Iframe for user authentication on the host server;

providing integration code to the host server for use in an application programming interface for notifying the user authentication service to initiate user authentication upon a request from the UI;

providing an authentication-test message for display in the UI, the authentication-test message comprising a randomly generated challenge-response test specific to a user session in the host server;

performing at least one of:

sending a short message service (SMS)-based authentication-request message, requesting a response, to a mobile device designated by a user; or

receiving an SMS-based user response from the mobile device, the SMS-based user response comprising an authentication key from the authentication-test message; and

providing a notification to the host server of an authentication of the user after at least one of a desired user response to the SMS-based authentication-request message or the SMS-based user response is received by the user authentication service, at least one of the desired user response or the SMS-based user response comprising an activation of an event by the user which results in the notification, to the host server, of the authentication of the user.

2. The tangible computer readable storage medium of claim 1 , the reference associated with a domain.

3. The tangible computer readable storage medium of claim 2 , the domain associated with the user authentication service.

4. The tangible computer readable storage medium of claim 1 , the host server configured to host a website.

5. The tangible computer readable storage medium of claim 4 , the Iframe provided in the website.

6. The tangible computer readable storage medium of claim 1 , the method comprising determining whether the user is human based upon at least one of the desired user response or the SMS-based user response.

7. The tangible computer readable storage medium of claim 4 , the Iframe associated with a first domain, the first domain different than a second domain associated with the website.

8. A system, comprising:

one or more processing units; and

memory comprising instructions that when executed by at least some of the one or more processing units, perform a method comprising:

providing a reference to a user authentication service for installation in source code of a host server, the reference associated with source code for an Iframe in a browser accessing the host server;

providing a user interface (UI) in the Iframe for user authentication on the host server;

providing integration code to the host server for use in an application programming interface for notifying the user authentication service to initiate user authentication upon a request from the UI;

providing an authentication-test message for display in the UI, the authentication-test message comprising a randomly generated challenge-response test specific to a user session in the host server;

performing at least one of:

sending a short message service (SMS)-based authentication-request message, requesting a response, to a mobile device designated by a user; or

receiving an SMS-based user response from the mobile device, the SMS-based user response comprising an authentication key from the authentication-test message; and

providing a notification to the host server of an authentication of the user after at least one of a desired user response to the SMS-based authentication-request message or the SMS-based user response is received by the user authentication service, at least one of the desired user response or the SMS-based user response comprising an activation of an event.

9. The system of claim 8 , the reference associated with a domain.

10. The system of claim 9 , the domain associated with the user authentication service.

11. The system of claim 8 , the host server configured to host a website.

12. The system of claim 11 , the Iframe provided in the website.

13. The system of claim 8 , the method comprising determining whether the user is human based upon at least one of the desired user response or the SMS-based user response.

14. The system of claim 11 , the Iframe associated with a first domain, the first domain different than a second domain associated with the website.

15. A method, comprising:

providing a reference to a user authentication service for installation in source code of a host server, the reference associated with source code for an Iframe in a browser accessing the host server;

providing a user interface (UI) in the Iframe for user authentication on the host server;

providing integration code to the host server for use in an application programming interface for notifying the user authentication service to initiate user authentication upon a request from the UI;

providing an authentication-test message for display, the authentication-test message comprising a randomly generated challenge-response test specific to a user session in the host server;

performing at least one of:

sending a short message service (SMS)-based authentication-request message, requesting a response, to a mobile device designated by a user; or

receiving an SMS-based user response from the mobile device, the SMS-based user response comprising an authentication key from the authentication-test message; and

providing a notification to the host server of an authentication of the user after at least one of a desired user response to the SMS-based authentication-request message or the SMS-based user response is received by the user authentication service.

16. The method of claim 15 , the reference associated with a domain.

17. The method of claim 16 , the domain associated with the user authentication service.

18. The method of claim 15 , the host server configured to host a website.

19. The method of claim 18 , the Iframe provided in the website.

20. The method of claim 15 , comprising determining whether the user is human based upon at least one of the desired user response or the SMS-based user response.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034564/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2009
From: OZZIE, RAYMOND; OZZIE, JACK; GALVIN, THOMAS A.; PATEY, ERIC M.
To: MICROSOFT CORPORATION
Reel/Frame 022135/0982 →
Continuity (1)
Related Publication 20100100725A1 · Apr 22, 2010