Patent · US Active

Methods and systems for secure user authentication

US9002750B1 · kind B1 · utility

51Cited by
32References
30Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 23, 2007
Grant dateApr 7, 2015
Priority date
Expiry dateMay 26, 2031

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04W88/02
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

For secure user authentication using a one-time password (OTP) application is pre-stored on a device for generating a OTP value responsive to entry of a valid PIN, no part of the PIN is stored on the device and pre-storing on a server the PIN and a valid shared secret for the user. Upon receiving entry a purported PIN, a purported shared secret is dynamically synthesized on the device by the OTP application based on the purported PIN of the user and a purported OTP value is generated based on the purported shared secret. When entry of the purported OTP value is received by the server in an attempt to log on the server from another device, the server cryptographically calculates a purported shared secret based on the purported OTP value, and log on to the server from the other device is allowed if the calculated purported shared secret corresponds to the pre-stored shared secret.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.