IP Library Granted Patent US 9,412,283
Granted Patent B2
US 9,412,283 · App. 14/143,659 · Granted Aug 9, 2016

System, design and process for easy to use credentials management for online accounts using out-of-band authentication

Inventor: Piyush Bhatnagar (Morganville, NJ)
G09C5/00H04L9/3228H04L63/0853H04L63/18H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,412,283
App. No.
14/143,659
Granted
Aug 9, 2016
Kind
B2
Abstract

The invention provides an easy to use credential management mechanism for multi-factor out-of-band multi-channel authentication process to protect a large number of documents without the need to remember all the document passwords. When opened, the secure document application generates a multi-dimensional code. The user scans the multi-dimensional code and validates the secure document application and triggers an out-of-band outbound mechanism. The portable mobile device invokes the authentication server to get authenticated. The authentication server authenticates the user based on shared secret key and is automatically allowed access to the secure document. The process of the invention includes an authentication server, a secure document application to generate an authentication vehicle or an embodiment (i.e. multi-dimensional bar code) and handle incoming requests, secret keys and a portable communication device with a smartphone application.

Claims (36)

1. A method for authentication for accessing an online portal in a system comprising a user, a client processing application, a portable communications device, and an authentication server having a provisioned user database and encrypted payload, wherein the method comprises:

providing a login portal and screen for access by a user, said login portal being in communication with said client processing application;

establishing contact between the client processing application and the authentication server wherein a new authentication session is started;

generating a session identifier at the authentication server, wherein the session identifier is communicated to the client processing application through at least a first communications channel;

creating a multi-dimensional barcode at the client processing application, wherein the barcode has dynamic encryption keys, portal information, session identifier, and a unique key, and wherein the barcode is displayed at the login screen;

holding the client processing application in waiting pending the authentication server notification of session validation;

starting authentication by user entering credential on the portable communications device, wherein the portable communications device validates credential and displays scan option;

using the portable communications device to scan the barcode displayed at the login screen and validate the client processing application;

finding on the portable communications device at least one encrypted user credentials with the encryption key from the barcode;

sending the encrypted credentials and session identifier from the portable communications device to the authentication server via a outbound out-of-band communications channel;

checking in provisioned user database of the authentication server, wherein the session is validated;

sending the encrypted payload to the waiting client processing application;

sending validation result from the authentication server to the portable communication device where the result is displayed;

decrypting the encrypted payload at the client processing application using the encryption keys;

extracting and decrypting the credentials at the client processing application;

using the decrypted credentials to access the online portal.

2. A method according to claim 1 wherein the login portal is provided at the client processing application for receiving information for the user.

3. A method according to claim 1 wherein the login portal and the client processing application for receiving information for the user are contained in a laptop.

4. A method according to claim 1 wherein the login portal and the client processing application for receiving information for the user are contained in a personal computer.

5. A method for authentication in a system comprising a user, a browser extension or plugin, a portable communications device, and an authentication server having a provisioned user database and a encrypted payload, wherein the method comprises:

detecting user intent to login to an online portal using a browser extension or plugin;

establishing contact between the browser extension or plugin and the authentication server wherein a new authentication session is started;

generating a session identifier at the authentication server, wherein the session identifier is communicated to the browser plugin through at least a first communications channel;

creating a multi-dimensional barcode at the browser extension or plugin, wherein the barcode has dynamic encryption keys, portal information, the session identifier, and a unique key, and wherein the barcode is displayed in the browser;

holding the browser in waiting pending authentication server notification of session validation;

starting authentication by user entering credential on the portable communications device, wherein the portable communications device validates the credential and displays scan option;

using the portable communications device to scan the barcode displayed at a login screen and validate the browser extension or plugin;

finding on the portable communications device at least one encrypted user credential with the encryption key from the barcode;

sending the at least one encrypted credential and the session identifier from the portable communications device to the authentication server via a outbound out-of-band communications channel;

checking in provisioned user database of the authentication server, wherein the session is validated;

sending the encrypted payload to the waiting browser extension or plugin;

sending validation result from the authentication server to the portable communication device where the result is displayed;

decrypting the payload at the browser extension or plugin using the encryption keys;

extracting and decrypting the at least one encrypted credential at the browser extension or plugin to obtain at least one decrypted credential;

using the at least one decrypted credential to populate a login form on the login page of the online portal in the browser;

initiating the login to the online portal by sending the login form to the online portal using the browser extension or plugin.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 21, 2023
From: PENNANTPARK LOAN AGENCY SERVICING, LLC, AS ADMINISTRATIVE AGENT
To: GCOM IP LLC
Reel/Frame 064650/0519 →
SECURITY INTEREST Recorded May 17, 2021
From: GCOM IP LLC
To: PENNANTPARK LOAN AGENCY SERVICING, LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 056257/0918 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded May 17, 2021
From: CERBERUS BUSINESS FINANCE, LLC
To: GCOM IP LLC
Reel/Frame 056267/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2021
From: AUTHOMATE INC.
To: GCOM IP LLC
Reel/Frame 056006/0170 →
SECURITY INTEREST Recorded Apr 22, 2021
From: GCOM IP LLC
To: CERBERUS BUSINESS FINANCY, LLC
Reel/Frame 056010/0709 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2019
From: BHATNAGAR, PIYUSH
To: AUTHOMATE INC.
Reel/Frame 048975/0499 →
Continuity (2)
Provisional Application 61747517 · Dec 31, 2012
Related Publication 20140223175A1 · Aug 7, 2014