IP Library Granted Patent US 9,699,183
Granted Patent B2
US 9,699,183 · App. 15/016,205 · Granted Jul 4, 2017

Mutual authentication of a user and service provider

Inventor: Resh Wallaja (San Francisco, CA)
Assignee: Kachyng, Inc.
H04L63/0869G06Q20/00H04L9/0861H04L9/321H04L9/3228H04L63/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,699,183
App. No.
15/016,205
Granted
Jul 4, 2017
Kind
B2
Abstract

Disclosed is a process for mutual authentication of a user and service provider. The process receives, at a key generation module (KGM), a notification of an event generated at a computing device. The process transmits the notification of the event to an authentication server. A third party server receives a shared secret provided by a registered user for the event. The shared secret transmitted to the KGM by the authentication server. The KGM generates a one-time key for the event. The process appends the shared secret to the one time key to generate an appended key, which is transmitted to a registered user mobile device. The process authenticates the event in response to receiving a notification from the computing device within a predetermined time period indicating the one-time key was entered at the computing device.

Claims (20)

1. A method for mutual authentication of a user and service provider, the method comprising:

receiving, at a key generation module (KGM), a notification of an event generated at a computing device;

transmitting the notification of the event to an authentication server;

receiving, at a third party server, a shared secret provided by a registered user for the event, the shared secret transmitted to the KGM by the authentication server;

generating, by the KGM, a one-time key for the event;

appending the shared secret to the one time key to generate an appended key;

transmitting the appended key to a registered user mobile device; and

responsive to receiving a notification from the computing device within a predetermined time period indicating the one-time key was entered at the computing device, authenticating the event.

2. The method as claims in claim 1 , wherein the KGM is a service provider server.

3. The method as claims in claim 1 , wherein the KGM comprises a service provider server and the third party server.

4. The method as claims in claim 3 , wherein the event to be authenticated is transmitted by the service provider server to the authentication server through the third party server, said authentication server provides the shared secret to the third party server.

5. The method of claim 4 , wherein the one time key is generated by the third party server.

6. The method of claim 1 , wherein the appended key is transmitted using at least one of Single Data Message Format (SDMF), Multiple Data Message Format (MDMF), Unstructured Supplementary Services Data (USSD), 3G video over voice, interactive voice response (IVR), placed telephone call and general packet radio service (GPRS).

7. The method of claim 1 , wherein the event is initiated by providing a missed call from the computing device to the KGM.

8. The method of claim 1 , wherein transmitting the appended key to the mobile device comprises invoking automatically a mobile application on the mobile device to display the appended key.

9. The method of claim 1 , wherein the shared secret is at least one of an image, a sound, a word, a phrase, a number, and an alphanumeric word.

10. The method of claim 1 , wherein the one time key is at least one of a symbol, an alphanumeric word, and a number.

11. The method of claim 1 , further comprising terminating the event responsive to receiving a predefined key sequence from the mobile device.

12. The method of claim 11 , further comprising locking an account of the registered user upon receipt of the predefined key sequence from the mobile device.

13. The method of claim 12 , wherein the authentication server generates a digital code and transmits the digital code to a service provider server with a mobile number of the mobile device, the digital code unlocking the registered user's account upon receipt of an unlock request from the registered user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2016
From: WALLAJA, RESH
To: PAYTEL INC.
Reel/Frame 039438/0689 →
CHANGE OF NAME Recorded Aug 15, 2016
From: PAYTEL, INC.
To: KACHYNG, INC.
Reel/Frame 039688/0218 →
Priority Claims (2)
IN 915/CHE/2010 · Mar 31, 2010 · national
IN 154/CHE/2010 · Apr 22, 2010 · national
Continuity (2)
Continuation 13637998
Related Publication 20160156627A1 · Jun 2, 2016