IP Library › Granted Patent US 10,592,656
Granted Patent B2
US 10,592,656 · App. 15/813,712 · Granted Mar 17, 2020

Automatic upgrade from one step authentication to two step authentication via application programming interface

Inventors: Larry A. Brocious (Apalachin, NY); Michael J. Howland (Endicott, NY); Paul E. Rogers (Johnson City, NY)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/40G06F21/31H04L9/0838H04L9/0863H04L9/3228H04L63/0838H04L63/0892H04L63/205H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,592,656
App. No.
15/813,712
Granted
Mar 17, 2020
Kind
B2
Abstract

A client transmits a user identifier and a password to a server via an application programming interface (API). The client establishes an authenticated session with the server in which the client has a first set of permissions for operations associated with the API. The client receives, responsive to a verification of the user identifier and password by the server, a logon response and a shared secret. The client generates a one time passcode (OTP) based upon the shared secret. The client sends the OTP to the server via the API. Responsive to the server validating the OTP against the shared secret, the server grants a second set of permissions for operations associated with the API.

Claims (17)

1. A method comprising:

transmitting, by a client, a user identifier and a password to a server via an application programming interface (API);

establishing an authenticated session with the server, the client having a first set of permissions for operations associated with the API;

receiving, responsive to a verification of the user identifier and password by the server, a logon response a shared secret,

wherein the server determines whether the user identifier is to be upgraded from one step authentication to two step authentication after successful verification of the user identifier and the password and grants the client limited permission with respect to permitted API operations and requires the two step authentication for each subsequent logon attempt;

generating, by the client, a one time passcode (OTP) based upon the shared secret;

sending the OTP to the server via the API;

granting, responsive to the server validating the OTP against the shared secret, a second set of permissions for operations associated with the API; and

transmitting the user ID, the password, and a current OTP generated based upon the shared secret to the server in a subsequent logon operation.

2. The method of claim 1 , further comprising:

receiving, by the client device, the user identifier and password, from a user.

3. The method of claim 1 , wherein the receiving of the logon response and shared secret is responsive to a determination that a user associated with the user identifier is designated for upgrading from one factor authentication to two factor authentication.

4. The method of claim 1 , further comprising:

storing, by the client, the shared secret within client preferences associated with a user.

5. The method of claim 1 , wherein the server is configured to store the shared secret within a user profile associated with a user.

6. The method of claim 1 , wherein the API includes a Representational state transfer (REST) API.

7. The method of claim 1 , wherein the second set of permissions is greater than the first set of permissions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2017
From: BROCIOUS, LARRY A.; HOWLAND, MICHAEL J.; ROGERS, PAUL E.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 044136/0472 →
Continuity (2)
Continuation 15689073 · Aug 29, 2017
Related Publication 20190065731A1 · Feb 28, 2019