IP Library › Granted Patent US 9,769,157
Granted Patent B2
US 9,769,157 · App. 14/860,420 · Granted Sep 19, 2017

Systems and methods for secure one-time password validation

Inventors: Wael Ibrahim (San Diego, CA); Upendra Mardikar (San Jose, CA)
Assignee: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
H04L63/0838G06Q20/00H04L63/0876H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,769,157
App. No.
14/860,420
Granted
Sep 19, 2017
Kind
B2
Abstract

A system may generate a seed one-time password (OTP). The system may also perform steps including transmitting the seed OTP to a user device, receiving a response OTP from the user device, and calculating an expected response OTP by applying a function to the seed OTP. The system may then compare the response OTP to the expected response OTP and send a result in response to comparing the response OTP to the expected response OTP.

Claims (52)

1. A method comprising:

generating, by a processor, a seed one-time password (OTP);

transmitting, by the processor, the seed OTP to a user device,

wherein the seed OTP is passed to a security utilities software development kit (SDK) on the user device for further processing to generate a response OTP in response to an integrity module confirming that the user device is in good health,

wherein the security utilities SDK is in communication with an OTP listening service;

receiving, by the processor, the response OTP from the user device,

wherein the response OTP is different from the seed OTP,

wherein the response OTP is generated using a function that is based on a device identifier associated with the user device and a device fingerprint associated with the user device;

calculating, by the processor, an expected response OTP by applying a function to the seed OTP,

wherein the function is based on the device identifier and the device fingerprint;

determining, by the processor, that the response OTP satisfies the expected response OTP; and

sending, by the processor, a result in response to the determining.

2. The method of claim 1 , further comprising receiving, by the processor, a request for the seed OTP, wherein the request includes the device identifier and the device fingerprint.

3. The method of claim 1 , wherein, in response to receiving the result from the processor, the user device displays a success notification screen and requests confirmation, wherein the success notification screen is displayed along with at least one of a service name request, a purpose, a time, a merchant, a merchant locator, or an amount.

4. The method of claim 1 , wherein the response OTP is transmitted by the user device to the processor in response to an authorization button being selected.

5. The method of claim 4 , wherein the seed OTP is transmitted to the user device with an authorization payload including at least one of a service identifier, a purpose, a time, a date, a merchant identifier, or an amount of the seed OTP for display with the authorization button.

6. The method of claim 1 , wherein the seed OTP is only valid for a predetermined time period.

7. A computer-based system, comprising:

a processor;

a tangible, non-transitory memory configured to communicate with the processor, the tangible, non-transitory memory having instructions stored thereon that, in response to execution by the processor, cause the processor to perform operations comprising:

generating, by the processor, a seed one-time password (OTP);

transmitting, by the processor, the seed OTP to a user device,

wherein the seed OTP is passed to a security utilities software development kit (SDK) on the user device for further processing to generate a response OTP in response to an integrity module confirming that the user device is in good health,

wherein the security utilities SDK is in communication with an OTP listening service;

receiving, by the processor, the response OTP from the user device,

wherein the response OTP is different from the seed OTP,

wherein the response OTP is generated using a function that is based on a device identifier associated with the user device and a device fingerprint associated with the user device;

calculating, by the processor, an expected response OTP by applying a function to the seed OTP,

wherein the function is based on the device identifier and the device fingerprint;

determining, by the processor, that the response OTP satisfies the expected response OTP; and

sending, by the processor, a result in response to the determining.

8. The computer-based system of claim 7 , further comprising receiving, by the processor, a request for the seed OTP, wherein the request includes the device identifier and the device fingerprint.

9. The computer-based system of claim 7 , wherein, in response to receiving the result from the processor, the user device displays a success notification screen and requests confirmation, wherein the success notification screen is displayed along with at least one of a service name request, a purpose, a time, a merchant, a merchant locator, or an amount.

10. The computer-based system of claim 7 , wherein the response OTP is transmitted by the user device to the processor in response to an authorization button being selected.

11. The computer-based system of claim 10 , wherein the seed OTP is transmitted to the user device with an authorization payload including at least one of a service identifier, a purpose, a time, a date, a merchant identifier, or an amount of the seed OTP for display with the authorization button.

12. The computer-based system of claim 7 , wherein the seed OTP is only valid for a predetermined time period.

13. An article of manufacture including a non-transitory, tangible computer readable storage medium having instructions stored thereon that, in response to execution by a computer-based system, cause the computer-based system to perform operations comprising:

generating, by the processor, a seed one-time password (OTP);

transmitting, by the processor, the seed OTP to a user device,

wherein the seed OTP is passed to a security utilities software development kit (SDK) on the user device for further processing to generate a response OTP in response to an integrity module confirming that the user device is in good health,

wherein the security utilities SDK is in communication with an OTP listening service;

receiving, by the processor, the response OTP from the user device,

wherein the response OTP is different from the seed OTP,

wherein the response OTP is generated using a function that is based on a device identifier associated with the user device and a device fingerprint associated with the user device;

calculating, by the processor, an expected response OTP by applying a function to the seed OTP,

wherein the function is based on the device identifier and the device fingerprint;

determining, by the processor, that the response OTP satisfies the expected response OTP; and

sending, by the processor, a result in response to the determining comparing the response OTP to the expected response OTP.

14. The article of claim 13 , further comprising receiving, by the processor, a request for the seed OTP, wherein the request includes the device identifier and the device fingerprint.

15. The article of claim 13 , wherein, in response to receiving the result from the processor, the user device displays a success notification screen and requests confirmation, wherein the success notification screen is displayed along with at least one of a service name request, a purpose, a time, a merchant, a merchant locator, or an amount.

16. The article of claim 13 , wherein the seed OTP is transmitted to the user device with an authorization payload including at least one of a service identifier, a purpose, a time, a date, a merchant identifier, or an amount of the seed OTP for display with an authorization button.

17. The article of claim 13 , wherein the seed OTP is only valid for a predetermined time period.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2015
From: IBRAHIM, WAEL; MARDIKAR, UPENDRA
To: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
Reel/Frame 036615/0093 →
Continuity (1)
Related Publication 20170085558A1 · Mar 23, 2017