Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

134 results about "One-time password" patented technology

A one-time password (OTP), also known as one-time pin or dynamic password, is a password that is valid for only one login session or transaction, on a computer system or other digital device. OTPs avoid a number of shortcomings that are associated with traditional (static) password-based authentication; a number of implementations also incorporate two-factor authentication by ensuring that the one-time password requires access to something a person has (such as a small keyring fob device with the OTP calculator built into it, or a smartcard or specific cellphone) as well as something a person knows (such as a PIN).

Method and system for preventing identity spoofing using artificial intelligence driven pattern recognition

The invention provides a method and system for preventing identity spoofing during digital authentication processes using artificial intelligence (AI)-driven pattern recognition. The system receives an input data stream from a user attempting to authenticate, which may include biometric data, device behavior data, or user interaction data. An AI-based pattern recognition model processes this data to analyze user behavior patterns and detect any anomalies that may indicate potential spoofing attempts. The system compares the processed data against a pre-established user profile to generate an authentication decision. If anomalies are detected, the system can flag the authentication for further review or trigger additional verification steps, such as multi-factor authentication (MFA) or one-time password (OTP) prompts. The system continuously learns from user interaction data and dynamically updates the user profile to improve the accuracy of identity verification.
Owner:SIVAKUMAR NITHYA REKHA +14

Enhanced one-time passcode devices

ActiveUS20250267144A1Securing communicationPassbookEngineering
A third verification factor is introduced into the two-factor authentication process, thereby establishing a robust three-factor authentication system. Specifically, a One-Time Password (OTP) that is typically generated for authentication purposes undergoes an additional layer of security by utilizing the OTP in a data authentication scheme of a user's chip-enabled credit, debit, banking, or similar card. An enhanced OTP generator sends the OTP to the card, which encrypts either the OTP or a value derived from the OTP (e.g., such as a hash of the OTP) with a cryptographic key associated with the card to create an encrypted authentication token. The encrypted authentication token is then provided to the authenticating party. Also described is an enhanced OTP generation device in the form of a passbook.
Owner:WELLS FARGO BANK NA

Systems and methods for time-based one-time password management for a medical device

A data monitoring system comprising a server communicatively coupled to a client device and a data module via a network. The server is configured to store a private key of a public-private key pair associated with the data module, receive a request from the client device for authenticated access to the data module, and generate an authentication key based at least on the private key and a time. The client device is configured to generate the request for authenticated access to the data module and transmit the request to the server. The data module is configured to store the private key of the public-private key pair associated with the data module, generate the authentication key based at least on the private key and the time, and grant access to the data module if the authentication key generated by the data module and the authentication key generated by the server match.
Owner:ABIOMED INC

Mobile application program authority management method and system

The invention discloses a mobile application program authority management method and system. The method comprises the following steps: receiving login information uploaded by a user through a mobile terminal, an equipment identifier of the mobile terminal and a timestamp when the user inputs the login information; verifying the integrity of the login information, and if the verification is passed, generating a first dynamic token based on the received data; encrypting the first dynamic token to form a one-time password token and sending the one-time password token to the mobile terminal, wherein the mobile terminal generates a second dynamic token according to the one-time password token; performing matching verification on the first dynamic token and the second dynamic token; receiving an operation instruction uploaded by the user through the mobile terminal, performing secondary identity verification on the user based on the operation instruction, and determining the authority of the user; and performing data transmission between the mobile terminal and the server or executing corresponding operation according to the authority of the user. According to the invention, the accuracy and security of identity verification are effectively improved, and the privacy leakage and abuse of the user are prevented.
Owner:EZHOU VOCATIONAL UNIV

Unclonable electronic device for providing unique identifier or authenticity certificate

An unclonable electronic device for providing a unique identifier or authenticity certificate wherein the prototype of the unclonable electronic device comprises: an ESP32 or ESP32 compatible microcontroller, having a unique chip identifier, built-in WiFi and Bluetooth functions; and a thin film transistor display having a resolution of at least 240 * 240 pixels. When a customer scans an unclonable electronic device to be validated, the server receives a message to be validated. The server generates a one-time password according to the identification of the chip of the unclonable electronic device to be verified. The server verifies whether the one-time password is consistent with the one-time password in the unique identifier or the authenticity certificate; if yes, verification succeeds; if not, verification fails, and a warning message is sent to the code scanning device.
Owner:杨友源

Using subscriber identity module (SIM) card as a security key for SIM swap fraud prevention

A method of utilizing a SIM card as a security key for subscriber identity module (SIM) swap prevention is described. The method includes receiving, from a service provider, an initial one-time password (OTP) delivery request comprising an OTP message, a mobile station international subscriber directory number (MSISDN) destined to receive the OTP message, and a SIM indicator associated with the MSISDN; determining, based on the OTP delivery request, a current international mobile subscriber identity (IMSI) associated with the MSISDN; obtaining, from a datastore based on the SIM indicator associated with the MSISDN, an IMSI of record for the MSISDN; comparing the current IMSI associated with the MSISDN and the IMSI of record for the MSISDN; and determining, based on the comparing, whether to deliver the OTP message to the MSISDN or block delivery of the OTP message to the MSISDN.
Owner:T MOBILE INNOVATIONS LLC

Method and system for optimising OTP channels in digital verification

A system and method for one time password (OTP) channel optimization is provided. The method includes: for each of a plurality of optimization criteria, and based on at least one attribute of a plurality of OTP channels, ascertaining a recommendation of the OTP channels, thereby ascertaining a plurality of recommendations for the plurality of optimization criteria respectively; in response to a verification request comprising an end user identifier, and based on at least one attribute of the end user identifier, selectively providing a first recommendation wherein the recommendations include the first recommendation; in response to a selected first OTP channel which is included in the first recommendation, instructing for a first OTP to be provided via the first OTP channel to a first device associated with the end user identifier wherein the OTP channels include the first OTP channel; and validating a first OTP entry against the first OTP.
Owner:KEREH YOEL HARTANTO

Authentication with dynamic user identification

An embodiment includes receiving, from a device, at an authentication service, a dynamic user identifier having a one-time password in an authentication message constructed to carry the dynamic user identifier in place of a pre-determined user identifier of a user. The embodiment locates in a profiles database, using a customized search query with a code based on the dynamic user identifier, a user profile. The embodiment receives at the authentication service, a secondary identification data of the user including a biometric information of the user. The embodiment validates the biometric information using the user profile and enables, when the validating is successful, the device to perform an operation. The enabling is not based on the authentication service validating an entirely static user identifier and is not based on the authentication service validating a manually typed password.
Owner:US BANK NATIONAL ASSOCIATION

Authentication with dynamic user identification

An embodiment includes receiving, from a device, at an authentication service, a dynamic user identifier having a one-time password in an authentication message constructed to carry the dynamic user identifier in place of a pre-determined user identifier of a user. The embodiment locates in a profiles database, using a customized search query with a code based on the dynamic user identifier, a user profile. The embodiment receives at the authentication service, a secondary identification data of the user including a biometric information of the user. The embodiment validates the biometric information using the user profile and enables, when the validating is successful, the device to perform an operation. The enabling is not based on the authentication service validating an entirely static user identifier and is not based on the authentication service validating a manually typed password.
Owner:US BANK NATIONAL ASSOCIATION

Control system, management method, and management program

A control system, a management method, and a management program for autonomous driving capable of reliably performing a safety check on a surrounding of an autonomous driving vehicle and reducing a risk of collision during a startup due to a check omission. Whether a safety check is performed is grasped using an in-vehicle camera that monitors a surrounding of a vehicle, a QR code (registered trademark) set at the surrounding of the vehicle, or a one-time password, and an erroneous vehicle is not subjected to a startup by using a check result in response to an instruction to start an autonomous driving by an on-site manager. Further, a range in which the autonomous driving or the remote control operation is permitted is set according to a range in which the check is performed. Accordingly, a risk of collision during a startup of the autonomous driving vehicle is reduced.
Owner:ASTEMO LTD

Sending Authentication Codes for Secure Access

Authentication codes (e.g., a One Time Passwords) are used in various ways to provide enhanced authentication. For example, multiple authentication codes may be sent to different users in order to provide access to a first user. In addition to sending authentication codes, multiple users may have to provide authentication credentials (e.g., a username / password) in order for a first user to access a resource, such as a bank account. The use of authentication codes may be applied to communication sessions, such as voice and video communication sessions. In addition, the authentication codes may be used to approve an incoming communication, such as and incoming email.
Owner:MICRO FOCUS LLC

Dynamic certificate updating method and system

The present invention proposes a dynamic certificate update method and system, applied to an authentication server, comprising: generating a secret seed for the user and encrypting and storing it; pre-installing the secret seed in a physical token; generating a unique identifier for the user during registration and associating it with the secret seed; when the user requests the issuance or renewal of a digital certificate, generating a one-time password and a VDF result based on the current time and the secret seed using the physical token; receiving the one-time password and VDF result, and verifying the validity of the one-time secret based on the secret seed and the current time, while also verifying the VDF result to ensure time synchronization; if the verification is successful, issuing or updating the digital certificate for the user, and dynamically updating the permission information in the digital certificate based on fuzzy logic. By introducing a secret seed, combining the one-time password with the VDF result for verification, and updating permissions based on fuzzy logic, the present invention effectively meets the high requirements for identity authentication and data encryption in today's complex and ever-changing network environments.
Owner:BEIJING ZHONGYU YONGXIN NETWORK TECH CO LTD

Systems and methods for cross coupling risk analytics and one-time-passcodes

Example embodiments provide systems and methods for validating an action using a physical token, such as a near-field-communications (NFC)-capable chip. A server may receive a request to perform the action, and may require validation from the holder of the physical token. The holder of the physical token may log into an application using their login credentials, providing a first tier of authentication. The holder may then scan the physical token with a reader on their mobile device, which provides a second tier of authentication. The scan may reveal a value for a counter on the physical token, which may be compared to a counter at the server in order to validate that the physical token has been used as expected. If the server deems it appropriate, a third (or further) tier may be required, such as scanning a photographic identification of the holder.
Owner:CAPITAL ONE SERVICES LLC

Systems and methods of identity authentication using a custom visual code

Systems and methods for authenticating user identity using custom visual code is disclosed. One disclosed method includes determining user identification information based on received biometric data; generating a temporary one-time password; encrypting the user identification information and the temporary one-time password; and generating a visual code based in part on the encrypted temporary one-time password and user identification information. The method may further include generating a prompt requesting a passcode or biometric data when a user device is within a predetermined threshold range of an authenticating device.
Owner:WELLS FARGO BANK NA

Cross-domain secure authentication engine in an item listing system

PendingUS20260187631A1Service domainEngineering
Methods, systems, and computer storage media for providing a cross-domain secure authentication engine in an item listing system are described. The cross-domain secure authentication engine is an advanced, modular system designed to handle user authentication seamlessly across different service domains, while ensuring security features and an adaptive user experience. In an item listing system, the cross-domain secure authentication engine operates based on a security-focused framework that streamlines user authentication across multiple domains without sacrificing user experience. It integrates a modal containing an iframe-based sign-in interface associated with a separate authentication domain and employs a postMessage API for cross-origin communication. Key features include dynamic modal resizing—adjusting the sign-in window to different authentication steps (like email, password, or OTP)—and parameterized iframes that remove unnecessary UI elements for a cleaner user experience. The cross-domain secure authentication engine also supports security measures and supports incremental, multi-step authentication flows to reduce user friction.
Owner:EBAY INC

Portable file system structure using non-fungible tokens

A portable file system structure that uses NFTs allows access to information regarding a directory structure using one or more directory NFTs. This may be used to view and / or modify the directory structure via one or more front ends. Access to one or more of the files themselves, and or decryption of encrypted content, may be obtained via one or more access NFTs, one-time passwords, and / or other authorization mechanisms. The files themselves may be stored in one or more different storage locations, such as cloud storage. The storage locations may be changed independently of the front end, and a front end associated with the directory structure may be de-associated so that another front end may be associated and then used to view and / or modify the directory structure.
Owner:TOKENFORM LLC

Systems and methods of identity authentication using a custom visual code

Systems and methods for authenticating user identity using custom visual code is disclosed. One disclosed method includes determining user identification information based on received biometric data; generating a temporary one-time password; encrypting the user identification information and the temporary one-time password; and generating a visual code based in part on the encrypted temporary one-time password and user identification information. The method may further include generating a prompt requesting a passcode or biometric data when a user device is within a predetermined threshold range of an authenticating device.
Owner:WELLS FARGO BANK NA

Method and apparatus for trust domain creation and destruction

A method of creating a trusted execution domain includes initializing, by a processing device executing a trust domain resource manager (TDRM), a trust domain control structure (TDCS) and a trust domain protected memory (TDPM) associated with a trust domain (TD). The method further includes generating a one-time cryptographic key, assigning the one-time cryptographic key to an available host key id (HKID) in a multi-key total memory encryption (MK-TME) engine, and storing the HKID in the TDCS. The method further includes associating a logical processor to the TD, adding a memory page from an address space of the logical processor to the TDPM, and transferring execution control to the logical processor to execute the TD.
Owner:INTEL CORP

Systems and methods for cryptographic authentication of contactless cards

Example embodiments of systems and methods for data transmission between contactless card and receiving devices are provided. In an embodiment, the contactless card may be configured to create a cryptogram based on a plurality of keys and a counter. The cryptogram may be transmitted to the receiving device. The contactless card may be configured to transmit a one-time password to the client device. The counter value may be adjusted each time the one-time password is generated, and the counter may be configured to increment in a non-monotonic sequence, the sequence associated with one or more cryptographic algorithms.
Owner:CAPITAL ONE SERVICES LLC

System and method for providing secured can communications

Example embodiments of the present disclosure provide secured controller area network (CAN) communications among vehicle components. According to embodiments, a method for providing may include: generating, by at least one processing unit of a sender, a one-time passcode (OTP); obtaining, by the at least one processing unit of the sender, a master key pre-provisioned to the sender and the receiver; deriving, by the at least one processing unit of the sender, a shared key based on the OTP and the master key; generating, by the at least one processing unit of the sender, a message authentication code (MAC) based on the derived shared key; appending, by the at least one processing unit of the sender, the MAC to a message; and transmitting, by the at least one processing unit of the sender, the appended message to a receiver via a CAN bus.
Owner:TOYOTA JIDOSHA KK

Authentication device, method, and computer program

The present invention solves a problem related to theft of personal information of a user caused by theft of a unique common number allocated to the user. A user terminal receives one-time password data issued from an authentication device (S1204, S1103). The one-time password data and personal information are handed over from the user terminal to a request device (S1105, S1301). The request device transmits the one-time password data and the personal information to an authentication device (S1302, S1205). The authentication device, upon determining that the one-time password data is valid and the personal information is valid (S1206), generates and transmits authentication data to the request device (S1207, S1208, S1303).
Owner:NTI

Multi-factor user authentication

A system for multi-factor user authentication for payment card-based transactions are described. The multifactor authentication may be based on a one-time passcode / password (OTP) as sent by an authentication server. A user device may, based on receiving the OTP, send an authentication code. The authentication code may be generated / determined based on the OTP. The authentication code may be augmented biometric identifier (ID) of a user associated with the user device. The authentication server may validate a transaction based on the authentication code.
Owner:BANK OF AMERICA CORP

User identity authentication method, device, equipment, medium and program product

The invention provides a user identity authentication method. The method can be applied to the technical fields of big data and artificial intelligence. The method comprises the steps of obtaining user biological characteristic data in response to a user identity authentication request, performing identity authentication according to the user biological characteristic data, and generating a first authentication result; and if the first authentication result is successful authentication, acquiring behavior data of the user for performing the identity authentication request, inputting the behavior data of the user for performing the identity authentication request into a pre-trained behavior authentication model, and outputting a second authentication result. And if the second authentication result is successful authentication, performing identity authentication through a one-time password, and generating a target authentication result. The invention further provides a user identity authentication device and equipment, a storage medium and a program product.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

System and method for dynamic integration of user-provided data with one-time-password authentication cryptogram

The disclosed system and method is directed to improving operational security associated with One-Time Password (OTP) authentication card. The proposed solution involves incorporating a user-provided data value, such as a Personal Identification Number (PIN) and / or a password, into the cryptographic process flow for the generation of the Message Authentication Code (MAC) associated with a OTP authentication cryptogram. A key operational aspect corresponds to the scrambling of a unique card-stored data such as a shared secret value, with run-time data externally provided by the user. In this way, the proposed system and method incorporates two factors of identification, associated with card-stored and user-known data elements, into an OTP card authentication cryptogram.
Owner:CAPITAL ONE SERVICES LLC

Communication data encryption and decryption method and system based on key rotation

The invention provides a communication data encryption and decryption method and system based on key rotation. The communication data encryption method comprises the steps of obtaining to-be-encrypted original data; according to the current moment, determining a corresponding current shared key from a preset key version set; according to the current shared key and a data packet timestamp, a corresponding encryption key is generated through a preset key algorithm, and the data packet timestamp is generated based on the current moment; according to the encryption key, encrypting the original data through a preset encryption algorithm to obtain corresponding encrypted data; and in combination with the encrypted data, the data packet timestamp, the key version number of the current shared key and a dynamic password, an encrypted communication data packet is constructed and obtained, the dynamic password is obtained by calculation through a preset one-time cryptographic algorithm according to the current shared key and the current moment, and the security of data communication is improved.
Owner:GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD

Message packet loss detection method and device

The invention discloses a message packet loss detection method and device, relates to the technical field of communication, and is used for detecting the packet loss rate of a data stream of an encrypted audio and video application. The method comprises the following steps: acquiring a plurality of messages of a first data stream of an audio and video application, wherein each message in the plurality of messages is encrypted by adopting a one-time password book OTP; obtaining a ciphertext serial number of each message in the plurality of messages according to the serial number position of the message in the first data stream, thereby obtaining a plurality of ciphertext serial numbers; decrypting the plurality of ciphertext serial numbers according to a message serial number incremental rule of the first data stream and values of ciphertext serial numbers of multiple groups of adjacent two messages in the plurality of messages to obtain a plurality of plaintext serial numbers corresponding to the plurality of messages; and determining the packet loss rate of the first data stream according to the plurality of plaintext serial numbers.
Owner:HUAWEI TECH CO LTD

Vehicle ADB debugging method and device based on one-time password

The invention provides a vehicle ADB debugging method and device based on a one-time password, and belongs to the technical field of vehicle-mounted system debugging, an authorized user registers in an authentication server and binds a secret key, and time-based one-time password TOTP user registration is completed; verifying the ADB debugging authentication verification code sent by the user through the authentication server, and starting a vehicle ADB debugging mode after the verification is passed; wherein the ADB debugging authentication verification code sent by the user is generated based on the bound secret key and the current time; debugging information is obtained by executing a universal system command or a pre-configured self-defined debugging command, and a fault is positioned. Therefore, the verification code needing to be input when ADB debugging is started each time is generated only based on the binding key and the current time, and the password leakage risk is avoided; and through presetting a self-defined debugging command, the problems of overload debugging information and low precision of the traditional ADB are solved, and the fault positioning efficiency is improved.
Owner:BEI DOU ZHI LIAN KE JI YOU XIAN GONG SI

Transformed one time password (OTP) for authentication

A password-protected device may support transformed passwords. In one example, a one-time password (OTP) may have a time-limited validity. The transform may be known to a user, and the transform may include manipulating characters in the OTP, such as by transposing characters, incrementing characters, or the like. The user may enter a transformed password to the system, and the system may reverse the transform and then compare the OTP to a reference OTP. The transform may provide an extra level of security over and above that provided by passwords themselves.
Owner:DELL PROD LP

One-time password (OTP) delivery method

A method includes connecting, by a user equipment (UE), to an access site or application. The UE receives, from a first device, a first message including an access code for accessing an access site or application through a dedicated application available on the UE, and extracts the access code from the first message to the dedicated application. The UE transmits an access code to an access site or application via a dedicated application for authentication.
Owner:NOKIA TECHNOLOGIES OY