Methods and systems for secure user authentication
US7904946B1 · kind B1 · utility
Assignee
Inventors
Key dates
| Filing date | Dec 11, 2006 |
| Grant date | Mar 8, 2011 |
| Priority date | — |
| Expiry date | Apr 19, 2029 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04W88/02
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
Methods and systems for secure user authentication utilizes OTP generation and validation techniques in which the shared secret for generating the OTP is not stored in the user's mobile device but instead is dynamically synthesized based on a PIN that activates the OTP generation and the personalized OTP data. The client software has no knowledge of what the correct PIN should be and always generates a normal looking OTP based on whatever PIN is entered, and the only way to learn whether or not the OTP is correct is to submit it during user login. By limiting the number of failed login attempts before the account is locked, brute-force attacks via the online channel will fail, and further, brute-force attacks to uncover the correct PIN for generating the correct OTP offline will also fail even if a hacker steals the user's mobile device and extracts the data inside for offline hacking, because there is nothing on the client that contains the PIN or encrypted by the PIN.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.