IP Library Granted Patent US 11,290,445
Granted Patent B2
US 11,290,445 · App. 16/538,122 · Granted Mar 29, 2022

Online authentication systems and methods

Inventor: Carlos M. Cu Castro (Los Angeles, CA)
Assignee: AXOS BANK
H04L63/0838G06F9/452H04L63/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,290,445
App. No.
16/538,122
Granted
Mar 29, 2022
Kind
B2
Abstract

A server may include at least one server processor configured to execute an application. A desktop virtualization system may include at least one desktop virtualization processor. The desktop virtualization processor may be configured to instantiate a virtual desktop; authenticate a user of a client device; in response to authenticating the user of the client device, place the client device in communication with the virtual desktop through at least one network; launch a secure browser in the virtual desktop; and using the secure browser, place the client device in communication with the server through the at least one network. The application may be configured to perform processing in response to at least one command from the client device. The processing may include generating a one-time passcode, establishing a code word not communicated through the at least one network, and sending a message including the one-time passcode to a sender client device.

Claims (70)

1. An authentication system comprising:

a server including at least one server hardware processor configured to execute an application; and

a desktop virtualization system including at least one virtualization system hardware processor configured to:

instantiate a virtual desktop;

authenticate a user of a client device by:

causing an authentication service to issue a one-time passcode for the user,

receiving the one-time passcode from the client device, and

determining that the one-time passcode from the client device matches the one-time passcode issued by the authentication service;

in response to authenticating the user of the client device, place the client device in communication with the virtual desktop through at least one network;

launch a secure browser in the virtual desktop;

using the secure browser, place the client device in communication with the server through the at least one network;

in response to at least one command from the client device sent through the secure browser of the virtual desktop:

generate a one-time passcode,

establish a code word not communicated through the at least one network, and

send a message including the one-time passcode to a sender client device;

confirm entry of the one-time passcode and the code word by a user of the sender client device; and

in response to confirming the entry, providing wire transfer instructions to the sender client device.

2. The authentication system of claim 1 , further comprising the client device including at least one client hardware processor.

3. The authentication system of claim 2 , wherein the at least one client hardware processor is configured to:

perform processing associated with authenticating the user and sending the at least one command; and

prevent processing associated with tasks unrelated to the processing associated with authenticating the user and sending the at least one command.

4. The authentication system of claim 2 , wherein the client device comprises at least one biometric sensor.

5. The authentication system of claim 4 , wherein the at least one virtualization system hardware processor is further configured to authenticate the user by:

receiving biometric data from the at least one biometric sensor; and

determining that the biometric data matches known biometric data of the user.

6. The authentication system of claim 5 , wherein the at least one virtualization system hardware processor is further configured to authenticate the user by:

receiving additional credentials from the client device; and

determining that the additional credentials match known credentials of the user.

7. The authentication system of claim 1 , wherein the at least one virtualization system hardware processor is further configured to authenticate the user by:

receiving additional credentials from the client device; and

determining that the additional credentials match known credentials of the user.

8. The authentication system of claim 1 , wherein the at least one virtualization system hardware processor is further configured to authenticate the user by:

receiving biometric data from the client device; and

determining that the biometric data matches known biometric data of the user.

9. The authentication system of claim 8 , wherein the at least one virtualization system hardware processor is further configured to authenticate the user by:

receiving additional credentials from the client device; and

determining that the additional credentials match known credentials of the user.

10. The authentication system of claim 1 , wherein the at least one server hardware processor is configured to:

receive user authentication information from the secure browser; and

prior to performing the processing in response to the at least one command, validating the user authentication information.

11. The authentication system of claim 1 , wherein the message does not include the code word.

12. An authentication method comprising:

instantiating, by at least one virtualization system hardware processor, a virtual desktop;

authenticating, by the at least one virtualization system hardware processor, a user of a client device, the authenticating comprising:

causing an authentication service to issue a one-time passcode for the user,

receiving the one-time passcode from the client device, and

determining that the one-time passcode from the client device matches the one-time passcode issued by the authentication service;

in response to authenticating the user of the client device, placing, by the at least one virtualization system hardware processor, the client device in communication with the virtual desktop through at least one network;

launching, by the at least one virtualization system hardware processor, a secure browser in the virtual desktop;

using the secure browser, placing, by the at least one virtualization system hardware processor, the client device in communication with a server through the at least one network;

performing, by at least one server hardware processor, processing in response to at least one command from the client device sent through the secure browser of the virtual desktop, the processing including:

generating a one-time passcode,

establishing a code word not communicated through the at least one network, and

sending a message including the one-time passcode to a sender client device;

confirming, by the at least one server hardware processor, entry of the one-time passcode and the code word by a user of the sender client device; and

in response to confirming the entry, providing, by the at least one server hardware processor, wire transfer instructions to the sender client device.

13. The authentication method of claim 12 , further comprising:

performing, by at least one client hardware processor, processing associated with authenticating the user and sending the at least one command; and

preventing, by the at least one client hardware processor, processing associated with tasks unrelated to the processing associated with authenticating the user and sending the at least one command.

14. The authentication method of claim 12 , wherein the authenticating further comprises:

receiving biometric data from the client device; and

determining that the biometric data matches known biometric data of the user.

15. The authentication system of claim 14 , wherein the authenticating further comprises:

receiving additional credentials from the client device; and

determining that the additional credentials match known credentials of the user.

16. The authentication method of claim 14 , further comprising collecting, by at least one biometric sensor of the client device, the biometric data.

17. The authentication method of claim 12 , wherein the authenticating further comprises:

receiving additional credentials from the client device; and

determining that the additional credentials match known credentials of the user.

18. The authentication method of claim 12 , wherein the message does not include the code word.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2019
From: CU CASTRO, CARLOS M.
To: AXOS BANK
Reel/Frame 050026/0357 →
Continuity (1)
Related Publication 20210051142A1 · Feb 18, 2021