IP Library Granted Patent US 10,360,558
Granted Patent B2
US 10,360,558 · App. 14/660,240 · Granted Jul 23, 2019

Simplified two factor authentication for mobile payments

Inventors: Mohammed Mujeeb Kaladgi (Bangalore, IN); Mahesh Malatesh Chitragar (Bangalore, IN); Vishwanatha Salian (Bangalore, IN)
Assignee: CA, Inc.
G06Q20/3674G06F21/31G06Q20/322G06Q20/325G06Q20/367G06Q20/3672G06Q20/3829G06Q20/4012H04L63/0428H04L63/083H04L63/0838H04L63/0853H04W12/06G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,360,558
App. No.
14/660,240
Granted
Jul 23, 2019
Kind
B2
Abstract

A method for two factor authentication is described. The method comprises sending an activation code stored on a mobile device to a server for verification. An encrypted secret key generated by the server using the activation code is received. The secret key is decrypted using the activation code stored on the mobile device. The mobile device encrypts the secret key using a predetermined PIN. As a result of a user inputting the predetermined PIN, the secret key is decrypted, the mobile device generates a first token using the secret key and transmits the first token to the server to authenticate the user. After receiving authentication from the server, the information on the mobile device is synced with the server.

Claims (71)

1. A method, comprising:

sending an activation code stored on a mobile device to a server for verification;

receiving an encrypted secret key generated by the server using the activation code;

decrypting the secret key using the activation code stored on the mobile device;

encrypting the secret key using a predetermined PIN;

receiving the predetermined PIN from a user;

confirming that the predetermined PIN received from the user is correct by comparing the predetermined PIN received from the user with a user-defined PIN stored on the mobile device;

in response to receiving the predetermined PIN and confirming that the predetermined PIN received from the user is correct, determining whether a synchronization between the server and the mobile device is required:

in response to determining that a synchronization between the server and the mobile device is required, decrypting the secret key;

generating, via the mobile device, a first token using the secret key;

transmitting the first token to the server to authenticate the user;

receiving authentication from the server; and

syncing information on the mobile device with the server; and

in response to receiving the predetermined PIN:

generating a dynamic card verification value; and

transmitting the dynamic card verification value to an issuer for authentication during a transaction.

2. The method of claim 1 , wherein the dynamic card verification value is generated using a limited use key.

3. The method of claim 1 , wherein the first token is a one-time password generated using the secret key.

4. The method of claim 1 , wherein the server authenticates the user by generating a second token identical to the first token.

5. The method of claim 1 , wherein determining whether a synchronization between the server and the mobile device is required comprises determining whether a synchronization is required to update card authentication data.

6. The method of claim 1 , wherein the encryption step is completed using cryptographic camouflage.

7. The method of claim 5 , wherein the card authentication data required to be updated comprises a limited use key.

8. A mobile device, comprising:

a processor; and

a non-transitory, computer-readable storage medium storing computer-readable instructions that when executed by the processor cause the mobile device to perform:

sending an activation code stored on the mobile device to a server for verification;

receiving an encrypted secret key generated by the server using the activation code;

decrypting the secret key using the activation code stored on the mobile device;

encrypting the secret key using a predetermined PIN;

receiving the predetermined PIN from a user;

confirming that the predetermined PIN received from the user is correct by comparing the predetermined PIN received from the user with a user-defined PIN stored on the mobile device;

in response to receiving the predetermined PIN and determining that the predetermined PIN received from the user is correct, determining whether a synchronization between the server and the mobile device is required;

in response to determining that a synchronization between the server and the mobile device is required:

decrypting the secret key;

generating, via the mobile device, a first token using the secret key;

transmitting the first token to the server to authenticate the user;

receiving authentication from the server; and

syncing information on the mobile device with the server; and

in response to receiving the predetermined PIN:

generating a dynamic card verification value; and

transmitting the dynamic card verification value to an issuer for authentication during a transaction.

9. The mobile device of claim 8 , wherein the dynamic card verification value is generated using a limited use key.

10. The mobile device of claim 8 , wherein the first token is a one-time password generated using the secret key.

11. The mobile device of claim 8 , wherein the server authenticates the user by generating a second token identical to the first token.

12. The mobile device of claim 8 , wherein the user-defined PIN stored on the mobile device remains stored on the mobile device and is not shared with the server.

13. The mobile device of claim 8 , wherein the encryption step is completed using cryptographic camouflage.

14. The mobile device of claim 8 , wherein syncing information comprises receiving a limited use key.

15. A computer program product comprising:

a non-transitory computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code comprising:

computer-readable program code configured to send an activation code stored on a mobile device to a server for verification;

computer-readable program code configured to receive an encrypted secret key generated by the server using the activation code;

computer-readable program code configured to decrypt the secret key using the activation code stored on the mobile device;

computer-readable program code configured to encrypt the secret key using a predetermined PIN;

computer-readable program code configured to receive the predetermined PIN from a user;

computer-readable program code configured to confirm that the predetermined PIN received from the user is correct by comparing the predetermined PIN received from the user with a user-defined PIN stored on the mobile device;

computer-readable program code configured to, in response to receiving the predetermined PIN and confirming that the predetermined PIN received from the user is correct, determining whether a synchronization between the server and the mobile device is required;

computer-readable program code configured to, in response to determining that a synchronization between the server and the mobile device is required:

decrypt the secret key;

generate, via the mobile device, a first token using the secret key;

transmit the first token to the server to authenticate the user;

receive authentication from the server; and

sync information on the mobile device with the server;

computer-readable program code configured to, in response to receiving the predetermined PIN:

generate a dynamic card verification value; and

transmit the dynamic card verification value to an issuer for authentication during a transaction.

16. The computer program product of claim 15 , wherein the dynamic card verification value is generated using a limited use key.

17. The computer program product of claim 15 , wherein the first token is a one-time password generated using the secret key.

18. The computer program product of claim 15 , wherein the server authenticates the user by generating a second token identical to the first token.

19. The computer program product of claim 15 , wherein the secret key is encrypted using cryptographic camouflage.

20. The computer program product of claim 15 , wherein the computer-readable program code configured to sync information further comprises:

computer-readable program code configured to receive a limited use key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2015
From: KALADGI, MOHAMMED MUJEEB; CHITRAGAR, MAHESH MALATESH; SALIAN, VISHWANATHA
To: CA, INC.
Reel/Frame 035183/0220 →
Continuity (1)
Related Publication 20160275491A1 · Sep 22, 2016