IP Library Granted Patent US 9,391,985
Granted Patent B2
US 9,391,985 · App. 14/835,707 · Granted Jul 12, 2016

Environment-based two-factor authentication without geo-location

Inventor: Guy Hefetz (New York, NY)
H04L63/0853G06F21/44G06F21/73G06Q20/3224G06Q20/4014G06Q20/4016G06Q30/06G06Q50/265H04L51/18H04L63/08H04L63/083H04L63/0876H04L63/107H04M15/8033H04W4/008H04W4/02H04W4/14H04W12/06H04W12/08G06F2221/2111
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,391,985
App. No.
14/835,707
Granted
Jul 12, 2016
Kind
B2
Abstract

The invention provides a method and system for accomplishing two-factor authentication for internet transactions, wherein the user of the device through which the transaction is negotiated needs to give only a single yes/no verification to the system. In some embodiments, the second factor authentication is automated without any action on the part of the user. The method calls on the user's wireless voice device for the detection of environmental wireless signals (“Short Distance Wireless Information” or “SDWI”), and uses these signals collectively as a “fingerprint” that uniquely identifies the wireless signals near the wireless voice device. The system stores these SDWI fingerprints, and later uses the stored information to establish whether or not the user's wireless voice device is near a previously-recognized SDWI.

Claims (31)

1. A computer-implemented method of controlling the access of an Internet user to conduct a transaction via a website, where the user has access to a mobile voice device that is paired with an identifier of the user, and is in communication with the website via a computer having a computer signature, the method comprising the computer-implemented steps of:

a. receiving the computer signature;

b. receiving an identifier of the user;

c. checking whether the computer signature is stored in a database;

d. sending a notification from a server to the mobile voice device that is paired with the identifier received in step (b), which causes the mobile voice device to acquire and report available Short Distance Wireless Information (SDWI);

e. if SDWI is not available, then attempting to authenticate the transaction, and if the transaction is authenticated then communicating an indication of success to the web site; or

f. if the stored computer signature is correlated in the database with stored SDWI that matches the SDWI acquired at step (d), then communicating an indication of success to the website; and

g. if the stored SDWI does not match the SDWI acquired at step (d), then attempting to authenticate the transaction, and if the transaction is authenticated then communicating an indication of success to the website, and correlating the computer signature in the database with the SDWI acquired at step (d).

2. The method of claim 1 , wherein the SDWI is an IP address of a wireless device that is independent and separate from both the mobile voice device and the computer.

3. The method of claim 1 , wherein the SDWI is at least one identifier of a wireless device that is independent and separate from both the mobile voice device and the computer.

4. The method of claim 3 , wherein the SDWI comprises at least one of:

a. Wi-Fi MAC address;

b. Wi-Fi SSID; and

c. Wi-Fi signal strength.

5. The method of claim 1 , wherein the user is not presented with an option to automate future transactions.

6. The method of claim 1 , wherein the process of authenticating the transaction in steps (e) and (g) is performed by the software installed on the mobile voice device.

7. The method of claim 6 , wherein the user is not presented with an option to automate future transactions.

8. The method of claim 1 , further comprising the step of receiving an indication of a change in SDWI during an active session in which the transaction has been authenticated, and if the received SDWI is not correlated with the computer signature, sending notification to the mobile voice device or to a server.

9. The method of claim 1 , wherein the process of authenticating the user in steps (e) and (g) is done by presenting options to the user, via the software installed on the mobile voice device, the options including at least one of:

a. the option to approve or not approve the transaction; and

b. the option to use the association of SDWI and computer signature of another user; but not including

c. an option to automate future transactions.

10. The method of claim 9 , wherein the software installed on the mobile voice device presents to the user an option to delete from the database the correlation of the computer signature with the stored SDWI.

11. The method of claim 1 , wherein if the access to the website in steps (e) and (g) is successfully authenticated, then the acquired SDWI is correlated in the database with the computer signature.

12. The method of claim 1 , wherein the process of authenticating the user in steps (e) and (g) is done by presenting to the user, via the software installed on the mobile voice device, two options, and wherein if the user chooses to allow access to the website, then all future access to the website that are characterized by the same computer signature and the same acquired SDWI are allowed automatically.

13. The method of claim 1 , wherein in step (d), if the SDWI is not available or is not reported within a pre-set period of time, the method further comprises the step of sending a notification to the mobile voice device.

14. The method of claim 1 , wherein the received SDWI is correlated in the database with the computer signature only if the SDWI is that of a Wi-Fi device that is protected by a password and is using encrypted communications.

15. The method of claim 1 , wherein the stored and correlated SDWI and computer signature were correlated by a prior user who is not the current user, and the prior user was granted access to the website.

16. The method of claim 1 , wherein the match in step (f) is between the SDWI and computer signature of a prior user granted access to the website, and the SDWI and computer signature of the current user, and if both match then allowing access to the current user.

17. The method of claim 1 , wherein in step (d) the notification sent to the user is a silent notification which does not alert the user that the notification arrived.

18. The method of claim 1 , further comprising the step of receiving an indication of a change in SDWI during an active session in which the transaction has been authenticated, and if the received SDWI is not correlated with the computer signature, then attempting to authenticate the-transaction, and if the transaction is authenticated then communicating an indication of success to the website.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2019
From: HEFETZ, GUY
To: SPRIV LLC
Reel/Frame 050260/0030 →
Continuity (14)
Continuation In Part 14479266 · Sep 5, 2014
Continuation In Part 14145862 · Dec 31, 2013
Continuation In Part 13479235 · May 23, 2012
Continuation In Part 13065691 · Mar 28, 2011
Continuation In Part 12260065 · Oct 28, 2008
Continuation In Part 11346240 · Feb 3, 2006
Continuation In Part 12600808
Continuation In Part 12357380 · Jan 21, 2009
Continuation In Part 11405789 · Apr 18, 2006
Provisional Application 60674709 · Apr 26, 2005
Provisional Application 61445860 · Feb 23, 2011
Provisional Application 61318329 · Mar 28, 2010
Provisional Application 60711346 · Aug 25, 2005
Related Publication 20160050203A1 · Feb 18, 2016