IP Library › Granted Patent US 11,991,287
Granted Patent B2
US 11,991,287 · App. 17/752,467 · Granted May 21, 2024

Username-less and password-less one-time identification and authentication code method and system

Inventors: Guido Pellizzer (Lovere, IT); Federico Simonetti (San Jose, CA)
H04L9/3228H04L63/0815H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,991,287
App. No.
17/752,467
Granted
May 21, 2024
Kind
B2
Abstract

A method for a user to access resources within a secure network without inputting a username or password is presented and claimed where the method comprises inputting, by the user, login credentials into an authentication service and obtaining from the authentication service at least one secret code; inputting the at least one secret code into an OTCP to initialize the OTCP; generating within the OTCP a one-time code (OTC) utilizing the at least one secret code but not including the user's login credentials or username; supplying, by the user, the OTC to a secure web portal wherein the secure web portal confirms authenticity of the OTC with the authentication service; and the secure web portal supplying access to the user of the secure web portal resources upon receipt of authentication of the user.

Claims (35)

1. A computer network-accessible identity and authentication service (IAS) for authenticating a user for a third party, the computer-implemented IAS comprising:

a code generation component configured to generate one or more user codes for an enrolling user of the IAS, wherein a first user code of the one or more user codes being a unique identifier to the IAS for the user, and each of the one or more user codes are unique identifiers associated with the enrolling user;

an enrollment component that enrolls the enrolling user with the IAS, wherein the enrollment component:

generates one or more user codes for an enrolling user via the code generation component; and

obtains username and password credentials from the enrolling user and maintains the obtained username and password credentials in association with the one or more user codes for the enrolling user; and

provides the one or more user codes of the enrolling user to a one-time code program (OTCP) executing on a computing device associated with the enrolling user; and

an authentication component, wherein the authentication component:

receives a request over a computer network from a third-party service for authentication of a requesting user, wherein the request includes encoded data for identifying and authenticating the requesting user, and wherein the encoded data does not include a username or password;

extracts at least a first user code from the encoded data;

determines login credentials of the requesting user as associated with the at least a first user code;

determines whether the requesting user is authorized to access restricted content of the third-party service according to the login credentials of the requesting user as associated with the at least a first user code; and

returns a validity indication to the third-party service based on the determination of whether the requesting user is authorized to access restricted content of the third party.

2. The computer network-accessible identity and authentication service of claim 1 , wherein the encoded data comprises a one-time code (OTC) generated by the OTCP of the enrolling user.

3. The computer network-accessible identity and authentication service of claim 1 , wherein the OTC is encoded as a hash-based message authentication code (HMAC) one-time password (HOTP).

4. The computer network-accessible identity and authentication service of claim 1 , wherein the OTC is encoded as a time-based one-time password (TOTP).

5. The computer network-accessible identity and authentication service of claim 1 , wherein the OTC is encoded with a Base32 encoding.

6. The computer network-accessible identity and authentication service of claim 1 , wherein the OTC is encoded with a sha256 encoding.

7. The computer network-accessible identity and authentication service of claim 1 , wherein the OTC was generated by the OTCP according to the one or more codes according to at least one of the one or more user codes provided to the OTCP during enrollment with the IAS.

8. A computer-implemented method of an identity and authentication service (IAS) for providing user authentication of a user to a third-party service, the method comprising:

enrolling at least a first user with the IAS, comprising:

generating a plurality of user codes for the first user, wherein each of the plurality of user codes is a unique identifier for the first user;

maintaining user authentication credentials of the first user for the third-party service in association with the plurality of user codes for the first user; and

providing the plurality of user codes for the first user to a one-time code program (OTCP) executing on a computing device associated with the first user; and

subsequent to enrolling the first user with the IAS, and for each request from the third-party service to authenticate a requesting user:

obtaining encoded data for identifying and authenticating the requesting user, wherein the encoded data does not include a username or password of the first user;

extracting a first user code from the encoded data;

determining whether the first user code corresponds to the first user;

upon a determination that the first user code corresponds to the first user, determining that the login credentials of the first user allow the first user access to the third-party service; and

upon a determination that the login credentials of the first user allow the first user access to the third-party service, returning a validity indication to the third-party service.

9. The computer-implemented method of claim 8 , wherein the encoded data comprises a one-time code (OTC) generated by the OTCP of the requesting user.

10. The computer-implemented method of claim 8 , wherein the OTC is encoded as a hash-based message authentication code (HMAC) one-time password (HOTP).

11. The computer-implemented method of claim 8 , wherein the OTC is encoded as a time-based one-time password (TOTP).

12. The computer-implemented method of claim 8 , wherein the OTC is encoded with a Base32 encoding.

13. The computer-implemented method of claim 8 , wherein the OTC is encoded with a sha256 encoding.

14. The computer-implemented method of claim 8 , wherein the OTC was generated by the OTCP according to the one or more codes according to at least one of the one or more user codes provided to the OTCP during enrollment with the IAS.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2026
From: PELLIZZER, GUIDO; SIMONETTI, FEDERICO
To: XIID CORPORATION
Reel/Frame 076051/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2022
From: PELLIZZER, GUIDO; SIMONETTI, FEDERICO
To: XIID CORPORATION
Reel/Frame 060002/0588 →
Continuity (4)
Continuation 16915121 · Jun 29, 2020
Continuation In Part 16665928 · Oct 28, 2019
Provisional Application 62751859 · Oct 29, 2018
Related Publication 20220286289A1 · Sep 8, 2022