Patent · US Active

Methods and systems for secure user authentication

US7904946B1 · kind B1 · utility

60Cited by
31References
2Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 11, 2006
Grant dateMar 8, 2011
Priority date
Expiry dateApr 19, 2029

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04W88/02
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Methods and systems for secure user authentication utilizes OTP generation and validation techniques in which the shared secret for generating the OTP is not stored in the user's mobile device but instead is dynamically synthesized based on a PIN that activates the OTP generation and the personalized OTP data. The client software has no knowledge of what the correct PIN should be and always generates a normal looking OTP based on whatever PIN is entered, and the only way to learn whether or not the OTP is correct is to submit it during user login. By limiting the number of failed login attempts before the account is locked, brute-force attacks via the online channel will fail, and further, brute-force attacks to uncover the correct PIN for generating the correct OTP offline will also fail even if a hacker steals the user's mobile device and extracts the data inside for offline hacking, because there is nothing on the client that contains the PIN or encrypted by the PIN.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.