IP Library Granted Patent US 9,313,198
Granted Patent B2
US 9,313,198 · App. 13/938,195 · Granted Apr 12, 2016

Multi-factor authentication using an authentication device

Inventor: Christopher Johnson (Boston, MA)
Assignee: Oracle International Corporation
H04L63/083H04L63/0853H04L63/18H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,313,198
App. No.
13/938,195
Granted
Apr 12, 2016
Kind
B2
Abstract

Systems and methods of authenticating users using a possession factor communicate a first authentication code to the user device and a second authentication code to an authentication device that is assumed to be the user's possession. Both authentication codes are presented to the user via their respective devices. An authentication application on the authentication device asks the user to compare the authentication codes and respond, via the authentication device, if these two authentication codes match. Authentication codes may be identical or different and match based on a user association. If a message from the authentication device indicates that the two codes match, then it is confirmed that the user possesses the authentication device and has authorized the authentication to proceed. For enhanced security, the authentication application may optionally be installed and executed on a Subscriber Identity Module (SIM) installed in the authentication device.

Claims (39)

1. A method for authenticating a user of a primary service, comprising:

receiving an authentication request from a primary service to authenticate a user of a user device;

communicating a first authentication code to the user device for presentation to the user;

communicating a second authentication code to an authentication device in the user's possession for presentation to the user, wherein the second authentication code is different than the first authentication code and includes a correspondence with the first authentication code;

receiving a response message via the authentication device, wherein the response message includes an indication of whether the user has confirmed that the second authentication code corresponds with the first authentication code;

in response to the response message including an indication that the user has confirmed that the second authentication code corresponds with the first authentication code, communicating an authentication response to the primary service indicating that the user is in possession of the authentication device and has authorized access to the primary service via the user device, wherein the authentication response is communicated when the user has indicated that the two authentication codes match; and

wherein in response to the response message including an indication that the user has not confirmed that the second authentication code corresponds with the first authentication code, communicating an authentication response to the primary service indicating that the user has not authorized access to the primary service via the user device.

2. The method of claim 1 , wherein the first and second authentication codes provide a correspondence that is recognizable by the user.

3. The method of claim 1 , wherein an authentication code includes a sound.

4. The method of claim 1 , wherein the authentication device includes an authentication application and wherein the authentication application is configured to time out if a predetermined amount of time passes without receiving the user confirmation that the second authentication code corresponds with the first authentication code.

5. The method of claim 4 , wherein the authentication application is implemented as a software application.

6. The method of claim 4 , wherein the authentication application is stored and executed on a Subscriber Identity Module connected with the authentication device.

7. The method of claim 6 , wherein the authentication application is adapted to be installed by a wireless phone carrier associated with the Subscriber Identity Module.

8. The method of claim 6 , wherein the second authentication code is communicated to the authentication device via a communications channel controlled by the wireless phone carrier associated with the Subscriber Identity Module.

9. The method of claim 6 , wherein the response message is received via a communication channel controlled by the wireless phone carrier associated with the Subscriber Identity Module.

10. One or more non-transitory tangible media including instructions adapted to direct a processor to perform a series of operations, the operations comprising:

receiving an authentication request from a primary service to authenticate a user of a user device;

communicating a first authentication code to the user device for presentation to the user;

communicating a second authentication code to an authentication device in the user's possession for presentation to the user, wherein the second authentication code is different than the first authentication code and includes a correspondence with the first authentication code;

receiving a response message via the authentication device, wherein the response message includes an indication of whether the user has confirmed that the second authentication code corresponds with the first authentication code;

in response to the response message including an indication that the user has confirmed that the second authentication code corresponds with the first authentication code, communicating an authentication response to the primary service indicating that the user is in possession of the authentication device and has authorized access to the primary service via the user device, wherein the authentication response is communicated when the user has indicated that the two authentication codes match; and

wherein in response to the response message including an indication that the user has not confirmed that the second authentication code corresponds with the first authentication code, communicating an authentication response to the primary service indicating that the user has not authorized access to the primary service via the user device.

11. An apparatus for authenticating a user of a primary service, the apparatus comprising:

one or more processors;

one or more non-transitory tangible media including instructions executable by the one or more processors for:

receiving an authentication request from a primary service to authenticate a user of a user device;

communicating a first authentication code to the user device for presentation to the user;

communicating a second authentication code to an authentication device in the user's possession for presentation to the user, wherein the second authentication code is different than the first authentication code and includes a correspondence with the first authentication code;

receiving a response message via the authentication device, wherein the response message includes an indication of whether the user has confirmed that the second authentication code corresponds with the first authentication code;

in response to the response message including an indication that the user has confirmed that the second authentication code corresponds with the first authentication code, communicating an authentication response to the primary service indicating that the user is in possession of the authentication device and has authorized access to the primary service via the user device, wherein the authentication response is communicated when the user has indicated that the two authentication codes match; and

wherein in response to the response message including an indication that the user has not confirmed that the second authentication code corresponds with the first authentication code, communicating an authentication response to the primary service indicating that the user has not authorized access to the primary service via the user device.

12. The apparatus of claim 11 , wherein the first and second authentication codes provide a correspondence that is recognizable by the user.

13. The apparatus of claim 11 , wherein an authentication code includes a sound.

14. The apparatus of claim 11 , wherein the authentication device includes an authentication application and wherein the authentication application is configured to time out if a predetermined amount of time passes without receiving the user confirmation that the second authentication code corresponds with the first authentication code.

15. The apparatus of claim 14 , wherein the authentication application is implemented as a software application.

16. The apparatus of claim 14 , wherein the authentication application is stored and executed on a Subscriber Identity Module connected with the authentication device.

17. The apparatus of claim 16 , wherein the authentication application is adapted to be installed by a wireless phone carrier associated with the Subscriber Identity Module.

18. The apparatus of claim 16 , wherein the second authentication code is communicated to the authentication device via a communications channel controlled by the wireless phone carrier associated with the Subscriber Identity Module.

19. The apparatus of claim 16 , wherein the response message is received via a communication channel controlled by the wireless phone carrier associated with the Subscriber Identity Module.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2013
From: JOHNSON, CHRISTOPHER
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 030763/0047 →
Continuity (3)
Provisional Application 61805921 · Mar 27, 2013
Provisional Application 61806349 · Mar 28, 2013
Related Publication 20140298421A1 · Oct 2, 2014