US2023308280A1PendingUtilityA1

Security authentification system for membership login of online website and method thereof

Assignee: EBAY KOREA CO LTDPriority: Feb 11, 2015Filed: Jun 1, 2023Published: Sep 28, 2023
Est. expiryFeb 11, 2035(~8.6 yrs left)· nominal 20-yr term from priority
Inventors:Jin Yong Lee
H04L 9/3228H04L 9/08H04L 9/32G06F 21/42G06F 21/36G06Q 20/425G06Q 20/4014G06Q 20/3276G06Q 20/3827H04W 12/068G06Q 20/3274G06Q 20/385H04L 9/3236H04L 63/0838H04L 63/18H04L 9/0863H04L 9/0869H04W 12/06H04L 9/3297
73
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A security authentication system provides verification without having to directly enter an ID and a password on a user device. In accordance with some aspects, a first user device receives one-time use authentication information from an authentication server without the authentication server receiving user login authentication information from the first user device. The first user device provides for communication of the one-time use authentication information from the first user device to a second user device. The first user device receives one-time password information (OTP), the OTP information initially received at the second user device from the authentication server in response to a request for the OTP information transmitted from the second user device to the authentication server, the request for the OTP information based on the one-time use authentication information. The first user device transmits, to the authentication server, the OTP information for verification of the first user device.

Claims

exact text as granted — not AI-modified
The invention claimed is: 
     
         1 . A computer-implemented method comprising:
 receiving, at a first user device, one-time use authentication information from an authentication server without the authentication server receiving user login authentication information from the first user device;   providing for communication of the one-time use authentication information from the first user device to a second user device;   receiving, at the first user device, one-time password information (OTP), the OTP information initially received at the second user device from the authentication server in response to a request for the OTP information transmitted from the second user device to the authentication server, the request for the OTP information based on the one-time use authentication information; and   transmitting, from the first user device to the authentication server, the OTP information for verification of the first user device.   
     
     
         2 . The computer-implemented method of  claim 1 , wherein providing for communication of the one-time use authentication information comprises:
 presenting a QR code on a display of the first user device.   
     
     
         3 . The computer-implemented method of  claim 1 , wherein the method further comprises:
 transmitting, from the first device to the authentication server, a request to log in to a website, wherein the one-time use authentication information is generated by the authentication server in response to the request to log in to the website.   
     
     
         4 . The computer-implemented method of  claim 1 , wherein the one-time use authentication information is generated by the authentication server based at least in part on an IP address of the first user device and/or a time of issuance of the one-time use authentication information. 
     
     
         5 . The computer-implemented method of  claim 1 , wherein the request for the OTP information transmitted from the second user device to the authentication server causes the authentication server to generate the OTP information. 
     
     
         6 . The computer-implemented method of  claim 6 , wherein the OTP information is generated based at least in part on an IP address of the first user device, the one-time use authentication information, the user login authentication information, and/or an IP address of the second user device. 
     
     
         7 . The computer-implemented method of  claim 1 , wherein the method further comprises:
 transmitting, from the first user device to the authentication server, the one-time use authentication information in conjunction with the OTP information for verification of the first user device.   
     
     
         8 . One or more machine-readable media storing computer-useable instructions that, when used by one or more processors, cause a first user device to perform operations, the operations comprising:
 receiving, at a first user device, one-time use authentication information from an authentication server without the authentication server receiving user login authentication information from the first user device;   providing for communication of the one-time use authentication information from the first user device to a second user device;   receiving, at the first user device, one-time password information (OTP), the OTP information initially received at the second user device from the authentication server in response to a request for the OTP information transmitted from the second user device to the authentication server, the request for the OTP information based on the one-time use authentication information; and   transmitting, from the first user device to the authentication server, the OTP information for verification of the first user device.   
     
     
         9 . The one or more machine-readable media of  claim 8 , wherein providing for communication of the one-time use authentication information comprises:
 presenting a QR code on a display of the first user device.   
     
     
         10 . The one or more machine-readable media of  claim 8 , wherein the operations further comprise:
 transmitting, from the first device to the authentication server, a request to log in to a website, wherein the one-time use authentication information is generated by the authentication server in response to the request to log in to the website.   
     
     
         11 . The one or more machine-readable media of  claim 8 , wherein the one-time use authentication information is generated by the authentication server based at least in part on an IP address of the first user device and/or a time of issuance of the one-time use authentication information. 
     
     
         12 . The one or more machine-readable media of  claim 8 , wherein the request for the OTP information transmitted from the second user device to the authentication server causes the authentication server to generate the OTP information. 
     
     
         13 . The one or more machine-readable media of  claim 12 , wherein the OTP information is generated based at least in part on an IP address of the first user device, the one-time use authentication information, the user login authentication information, and/or an IP address of the second user device. 
     
     
         14 . The one or more machine-readable media of  claim 8 , wherein the operations further comprise:
 transmitting, from the first user device to the authentication server, the one-time use authentication information in conjunction with the OTP information for verification of the first user device.   
     
     
         15 . A computer system for a first user device comprising:
 one or more processors; and   one or more machine-readable media storing computer-useable instructions that cause the processors to:   receiving, at the first user device, one-time use authentication information from an authentication server without the authentication server receiving user login authentication information from the first user device;   providing for communication of the one-time use authentication information from the first user device to a second user device;   receiving, at the first user device, one-time password information (OTP), the OTP information initially received at the second user device from the authentication server in response to a request for the OTP information transmitted from the second user device to the authentication server, the request for the OTP information based on the one-time use authentication information; and   transmitting, from the first user device to the authentication server, the OTP information for verification of the first user device.   
     
     
         16 . The computer system of  claim 15 , wherein providing for communication of the one-time use authentication information comprises:
 presenting a QR code on a display of the first user device.   
     
     
         17 . The computer system of  claim 15 , wherein the operations further comprise:
 transmitting, from the first device to the authentication server, a request to log in to a website, wherein the one-time use authentication information is generated by the authentication server in response to the request to log in to the website.   
     
     
         18 . The computer system of  claim 15 , wherein the one-time use authentication information is generated by the authentication server based at least in part on an IP address of the first user device and/or a time of issuance of the one-time use authentication information. 
     
     
         19 . The computer system of  claim 15 , wherein the request for the OTP information transmitted from the second user device to the authentication server causes the authentication server to generate the OTP information, wherein the OTP information is generated based at least in part on an IP address of the first user device, the one-time use authentication information, the user login authentication information, and/or an IP address of the second user device. 
     
     
         20 . The computer system of  claim 15 , wherein the operations further comprise:
 transmitting, from the first user device to the authentication server, the one-time use authentication information in conjunction with the OTP information for verification of the first user device.

Join the waitlist — get patent alerts

Track US2023308280A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.