Multi factor authentication using different devices
Customizing an application on a mobile device includes storing at least a portion of customization data in a customization server that is independent of the mobile device, a user of the mobile device accessing the customization server independently of the mobile device, receiving authorization data from the customization server that enables the mobile device to securely receive customization data from the customization server, and the mobile device using the authorization data to cause the customization server to provide the customization data to the mobile device. The authorization data may be provided by postal message, email message, an SMS text message, and/or a visual code provided on a screen of a computer used to access the customization server. The user may use a computer to provide credential information to access the customization server. Customizing the application may allow the mobile device to access a user service on behalf of the user.
1 . A method for customizing an application on a mobile device, the application being generic to at least one of a plurality of service providers or a plurality of users, the method comprising:
storing customization data in a customization server that is independent of the mobile device, wherein the customization data, when used to modify the application, changes the application to a customized application that is specific to at least one of a given service provider of the plurality of service providers or a user of the mobile device;
in response to the user of the mobile device initiating customization of the application by contacting the customization server through an access channel other than the application, providing authorization data to the user from the customization server, wherein the authorization data enables the mobile device to securely receive the customization data from the customization server; and
receiving the authorization data from the mobile device and causing the customization server to provide the customization data to the mobile device, wherein the customization data enables the mobile device to change the application to the customized application.
2 . The method, according to claim 1 , wherein the authorization data is provided by at least one of: postal message, email message, an SMS text message, or a visual code provided on a screen of a computer used to contact the customization server.
3 . The method, according to claim 2 , wherein the user uses a computer separate from the mobile device to contact the customization server to initiate customization of the application.
4 . The method, according to claim 2 , wherein the authorization data is provided by the visual code on the screen of the computer and the mobile device receives the visual code using a camera of the mobile device.
5 . The method, according to claim 1 , wherein customizing the application enables the mobile device to access a user service on behalf of the user.
6 . The method, according to claim 1 , wherein the user of the mobile device initiating customization of the application by contacting the customization server through an access channel other than the application comprises the user of the mobile device contacting the customization server without using the mobile device.
7 . The method, according to claim 5 , wherein the user service is banking.
8 . The method, according to claim 1 , wherein certificate pinning is used to require that the mobile device only communicate with predetermined customization servers.
9 . A non-transitory computer-readable medium containing executable code for customizing an application on a mobile device, the application being generic to at least one of a plurality of service providers or a plurality of users, the executable code, when executed by at least one processor, causing the processor to:
store customization data in a customization server that is independent of the mobile device, wherein the customization data, when used to modify the application, changes the application to a customized application that is specific to at least one of a given service provider of the plurality of service providers or a user of the mobile device;
in response to the user of the mobile device initiating customization of the application by contacting the customization server through an access channel other than the application, providing authorization data to the user from the customization server, wherein the authorization data enables the mobile device to securely receive customization data from the customization server; and
receive the authorization data from the mobile device and cause the customization server to provide the customization data to the mobile device, wherein the customization data enables the mobile device to change the application to the customized application.
10 . The non-transitory computer-readable medium, according to claim 9 , wherein the authorization data is provided by at least one of: postal message, email message, an SMS text message, or a visual code provided on a screen of a computer used to contact the customization server.
11 . The non-transitory computer-readable medium, according to claim 10 , wherein the access channel comprises a computer separate from the mobile device.
12 . The non-transitory computer-readable medium, according to claim 9 , wherein changing the application to the customized application enables the mobile device to access a user service on behalf of the user.
13 . The non-transitory computer-readable medium, according to claim 9 , wherein the user of the mobile device initiating customization of the application by contacting the customization server through an access channel other than the application comprises the user of the mobile device contacting the customization server without using the mobile device.
14 . The non-transitory computer-readable medium, according to claim 12 , wherein the customization data includes a secret key that enables the mobile device to access the user service.
15 . The non-transitory computer-readable medium, according to claim 12 , wherein the user service is banking.
16 . A method for customizing an application on a mobile device, the method comprising:
downloading the application to the mobile device, the application being generic to at least one of a plurality of service providers or a plurality of users;
initiating customization of the application by contacting a customization server through an access channel other than the application, the customization server being independent of the mobile device and storing customization data, wherein the customization data, when used to modify the application, changes the application to a customized application that is specific to at least one of a given service provider of the plurality of service providers or a user of the mobile device;
in response to contacting the customization server, receiving authorization data from the customization server, wherein the authorization data enables the mobile device to securely receive the customization data from the customization server; and
providing the authorization data from the mobile device to the customization server and, in response, receiving the customization data from the customization server, wherein the customization data enables the mobile device to change the application to the customized application.
17 . The method, according to claim 16 , wherein initiating customization of the application by contacting the customization server through an access channel other than the application comprises the user of the mobile device contacting the customization server without using the mobile device.
18 . The method, according to claim 16 , wherein receiving the authorization data from the customization server comprises receiving the authorization data by at least one of: postal message, email message, an SMS text message, or a visual code provided on a screen of a computer used to contact the customization server.
19 . The method, according to claim 16 , wherein the authorization data is received via a visual code on a screen of a computer used to contact the customization server and the method further comprises receiving the visual code using a camera of the mobile device.
20 . The method, according to claim 16 , wherein customizing the application enables the mobile device to access a user service on behalf of the user.