Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

73 results about "One-time password" patented technology

A one-time password (OTP), also known as one-time pin or dynamic password, is a password that is valid for only one login session or transaction, on a computer system or other digital device. OTPs avoid a number of shortcomings that are associated with traditional (static) password-based authentication; a number of implementations also incorporate two-factor authentication by ensuring that the one-time password requires access to something a person has (such as a small keyring fob device with the OTP calculator built into it, or a smartcard or specific cellphone) as well as something a person knows (such as a PIN).

Using subscriber identity module (SIM) card as a security key for SIM swap fraud prevention

A method of utilizing a SIM card as a security key for subscriber identity module (SIM) swap prevention is described. The method includes receiving, from a service provider, an initial one-time password (OTP) delivery request comprising an OTP message, a mobile station international subscriber directory number (MSISDN) destined to receive the OTP message, and a SIM indicator associated with the MSISDN; determining, based on the OTP delivery request, a current international mobile subscriber identity (IMSI) associated with the MSISDN; obtaining, from a datastore based on the SIM indicator associated with the MSISDN, an IMSI of record for the MSISDN; comparing the current IMSI associated with the MSISDN and the IMSI of record for the MSISDN; and determining, based on the comparing, whether to deliver the OTP message to the MSISDN or block delivery of the OTP message to the MSISDN.
Owner:T MOBILE INNOVATIONS LLC

Authentication with dynamic user identification

An embodiment includes receiving, from a device, at an authentication service, a dynamic user identifier having a one-time password in an authentication message constructed to carry the dynamic user identifier in place of a pre-determined user identifier of a user. The embodiment locates in a profiles database, using a customized search query with a code based on the dynamic user identifier, a user profile. The embodiment receives at the authentication service, a secondary identification data of the user including a biometric information of the user. The embodiment validates the biometric information using the user profile and enables, when the validating is successful, the device to perform an operation. The enabling is not based on the authentication service validating an entirely static user identifier and is not based on the authentication service validating a manually typed password.
Owner:US BANK NATIONAL ASSOCIATION

Control system, management method, and management program

A control system, a management method, and a management program for autonomous driving capable of reliably performing a safety check on a surrounding of an autonomous driving vehicle and reducing a risk of collision during a startup due to a check omission. Whether a safety check is performed is grasped using an in-vehicle camera that monitors a surrounding of a vehicle, a QR code (registered trademark) set at the surrounding of the vehicle, or a one-time password, and an erroneous vehicle is not subjected to a startup by using a check result in response to an instruction to start an autonomous driving by an on-site manager. Further, a range in which the autonomous driving or the remote control operation is permitted is set according to a range in which the check is performed. Accordingly, a risk of collision during a startup of the autonomous driving vehicle is reduced.
Owner:ASTEMO LTD

Systems and methods for cross coupling risk analytics and one-time-passcodes

Example embodiments provide systems and methods for validating an action using a physical token, such as a near-field-communications (NFC)-capable chip. A server may receive a request to perform the action, and may require validation from the holder of the physical token. The holder of the physical token may log into an application using their login credentials, providing a first tier of authentication. The holder may then scan the physical token with a reader on their mobile device, which provides a second tier of authentication. The scan may reveal a value for a counter on the physical token, which may be compared to a counter at the server in order to validate that the physical token has been used as expected. If the server deems it appropriate, a third (or further) tier may be required, such as scanning a photographic identification of the holder.
Owner:CAPITAL ONE SERVICES LLC

Cross-domain secure authentication engine in an item listing system

PendingUS20260187631A1Service domainEngineering
Methods, systems, and computer storage media for providing a cross-domain secure authentication engine in an item listing system are described. The cross-domain secure authentication engine is an advanced, modular system designed to handle user authentication seamlessly across different service domains, while ensuring security features and an adaptive user experience. In an item listing system, the cross-domain secure authentication engine operates based on a security-focused framework that streamlines user authentication across multiple domains without sacrificing user experience. It integrates a modal containing an iframe-based sign-in interface associated with a separate authentication domain and employs a postMessage API for cross-origin communication. Key features include dynamic modal resizing—adjusting the sign-in window to different authentication steps (like email, password, or OTP)—and parameterized iframes that remove unnecessary UI elements for a cleaner user experience. The cross-domain secure authentication engine also supports security measures and supports incremental, multi-step authentication flows to reduce user friction.
Owner:EBAY INC

Portable file system structure using non-fungible tokens

A portable file system structure that uses NFTs allows access to information regarding a directory structure using one or more directory NFTs. This may be used to view and / or modify the directory structure via one or more front ends. Access to one or more of the files themselves, and or decryption of encrypted content, may be obtained via one or more access NFTs, one-time passwords, and / or other authorization mechanisms. The files themselves may be stored in one or more different storage locations, such as cloud storage. The storage locations may be changed independently of the front end, and a front end associated with the directory structure may be de-associated so that another front end may be associated and then used to view and / or modify the directory structure.
Owner:TOKENFORM LLC

Systems and methods of identity authentication using a custom visual code

Systems and methods for authenticating user identity using custom visual code is disclosed. One disclosed method includes determining user identification information based on received biometric data; generating a temporary one-time password; encrypting the user identification information and the temporary one-time password; and generating a visual code based in part on the encrypted temporary one-time password and user identification information. The method may further include generating a prompt requesting a passcode or biometric data when a user device is within a predetermined threshold range of an authenticating device.
Owner:WELLS FARGO BANK NA

Method and apparatus for trust domain creation and destruction

A method of creating a trusted execution domain includes initializing, by a processing device executing a trust domain resource manager (TDRM), a trust domain control structure (TDCS) and a trust domain protected memory (TDPM) associated with a trust domain (TD). The method further includes generating a one-time cryptographic key, assigning the one-time cryptographic key to an available host key id (HKID) in a multi-key total memory encryption (MK-TME) engine, and storing the HKID in the TDCS. The method further includes associating a logical processor to the TD, adding a memory page from an address space of the logical processor to the TDPM, and transferring execution control to the logical processor to execute the TD.
Owner:INTEL CORP

Systems and methods for cryptographic authentication of contactless cards

Example embodiments of systems and methods for data transmission between contactless card and receiving devices are provided. In an embodiment, the contactless card may be configured to create a cryptogram based on a plurality of keys and a counter. The cryptogram may be transmitted to the receiving device. The contactless card may be configured to transmit a one-time password to the client device. The counter value may be adjusted each time the one-time password is generated, and the counter may be configured to increment in a non-monotonic sequence, the sequence associated with one or more cryptographic algorithms.
Owner:CAPITAL ONE SERVICES LLC

System and method for providing secured can communications

Example embodiments of the present disclosure provide secured controller area network (CAN) communications among vehicle components. According to embodiments, a method for providing may include: generating, by at least one processing unit of a sender, a one-time passcode (OTP); obtaining, by the at least one processing unit of the sender, a master key pre-provisioned to the sender and the receiver; deriving, by the at least one processing unit of the sender, a shared key based on the OTP and the master key; generating, by the at least one processing unit of the sender, a message authentication code (MAC) based on the derived shared key; appending, by the at least one processing unit of the sender, the MAC to a message; and transmitting, by the at least one processing unit of the sender, the appended message to a receiver via a CAN bus.
Owner:TOYOTA JIDOSHA KK

Authentication device, method, and computer program

The present invention solves a problem related to theft of personal information of a user caused by theft of a unique common number allocated to the user. A user terminal receives one-time password data issued from an authentication device (S1204, S1103). The one-time password data and personal information are handed over from the user terminal to a request device (S1105, S1301). The request device transmits the one-time password data and the personal information to an authentication device (S1302, S1205). The authentication device, upon determining that the one-time password data is valid and the personal information is valid (S1206), generates and transmits authentication data to the request device (S1207, S1208, S1303).
Owner:NTI

Multi-factor user authentication

A system for multi-factor user authentication for payment card-based transactions are described. The multifactor authentication may be based on a one-time passcode / password (OTP) as sent by an authentication server. A user device may, based on receiving the OTP, send an authentication code. The authentication code may be generated / determined based on the OTP. The authentication code may be augmented biometric identifier (ID) of a user associated with the user device. The authentication server may validate a transaction based on the authentication code.
Owner:BANK OF AMERICA CORP

User identity authentication method, device, equipment, medium and program product

The invention provides a user identity authentication method. The method can be applied to the technical fields of big data and artificial intelligence. The method comprises the steps of obtaining user biological characteristic data in response to a user identity authentication request, performing identity authentication according to the user biological characteristic data, and generating a first authentication result; and if the first authentication result is successful authentication, acquiring behavior data of the user for performing the identity authentication request, inputting the behavior data of the user for performing the identity authentication request into a pre-trained behavior authentication model, and outputting a second authentication result. And if the second authentication result is successful authentication, performing identity authentication through a one-time password, and generating a target authentication result. The invention further provides a user identity authentication device and equipment, a storage medium and a program product.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

System and method for dynamic integration of user-provided data with one-time-password authentication cryptogram

The disclosed system and method is directed to improving operational security associated with One-Time Password (OTP) authentication card. The proposed solution involves incorporating a user-provided data value, such as a Personal Identification Number (PIN) and / or a password, into the cryptographic process flow for the generation of the Message Authentication Code (MAC) associated with a OTP authentication cryptogram. A key operational aspect corresponds to the scrambling of a unique card-stored data such as a shared secret value, with run-time data externally provided by the user. In this way, the proposed system and method incorporates two factors of identification, associated with card-stored and user-known data elements, into an OTP card authentication cryptogram.
Owner:CAPITAL ONE SERVICES LLC

Communication data encryption and decryption method and system based on key rotation

The invention provides a communication data encryption and decryption method and system based on key rotation. The communication data encryption method comprises the steps of obtaining to-be-encrypted original data; according to the current moment, determining a corresponding current shared key from a preset key version set; according to the current shared key and a data packet timestamp, a corresponding encryption key is generated through a preset key algorithm, and the data packet timestamp is generated based on the current moment; according to the encryption key, encrypting the original data through a preset encryption algorithm to obtain corresponding encrypted data; and in combination with the encrypted data, the data packet timestamp, the key version number of the current shared key and a dynamic password, an encrypted communication data packet is constructed and obtained, the dynamic password is obtained by calculation through a preset one-time cryptographic algorithm according to the current shared key and the current moment, and the security of data communication is improved.
Owner:GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD

Message packet loss detection method and device

The invention discloses a message packet loss detection method and device, relates to the technical field of communication, and is used for detecting the packet loss rate of a data stream of an encrypted audio and video application. The method comprises the following steps: acquiring a plurality of messages of a first data stream of an audio and video application, wherein each message in the plurality of messages is encrypted by adopting a one-time password book OTP; obtaining a ciphertext serial number of each message in the plurality of messages according to the serial number position of the message in the first data stream, thereby obtaining a plurality of ciphertext serial numbers; decrypting the plurality of ciphertext serial numbers according to a message serial number incremental rule of the first data stream and values of ciphertext serial numbers of multiple groups of adjacent two messages in the plurality of messages to obtain a plurality of plaintext serial numbers corresponding to the plurality of messages; and determining the packet loss rate of the first data stream according to the plurality of plaintext serial numbers.
Owner:HUAWEI TECH CO LTD

Vehicle ADB debugging method and device based on one-time password

The invention provides a vehicle ADB debugging method and device based on a one-time password, and belongs to the technical field of vehicle-mounted system debugging, an authorized user registers in an authentication server and binds a secret key, and time-based one-time password TOTP user registration is completed; verifying the ADB debugging authentication verification code sent by the user through the authentication server, and starting a vehicle ADB debugging mode after the verification is passed; wherein the ADB debugging authentication verification code sent by the user is generated based on the bound secret key and the current time; debugging information is obtained by executing a universal system command or a pre-configured self-defined debugging command, and a fault is positioned. Therefore, the verification code needing to be input when ADB debugging is started each time is generated only based on the binding key and the current time, and the password leakage risk is avoided; and through presetting a self-defined debugging command, the problems of overload debugging information and low precision of the traditional ADB are solved, and the fault positioning efficiency is improved.
Owner:BEI DOU ZHI LIAN KE JI YOU XIAN GONG SI

Authentication with dynamic user identification

An embodiment includes receiving, from a device, at an authentication service, a dynamic user identifier having a one-time password in an authentication message constructed to carry the dynamic user identifier in place of a pre-determined user identifier of a user. The embodiment locates in a profiles database, using a customized search query with a code based on the dynamic user identifier, a user profile. The embodiment receives at the authentication service, a secondary identification data of the user including a biometric information of the user. The embodiment validates the biometric information using the user profile and enables, when the validating is successful, the device to perform an operation. The enabling is not based on the authentication service validating an entirely static user identifier and is not based on the authentication service validating a manually typed password.
Owner:US BANK NATIONAL ASSOCIATION

Application login method, device, system, storage medium, and program product

PCT designated stageWO2026138132A1Terminal equipmentEngineering
Embodiments of the present disclosure provide an application login method, a device, a system, a storage medium, and a program product. In the embodiments of the present disclosure, a user inputs, on a login page of an application, a composite password comprising a static password and a one-time password. A terminal device of the user requests, from a first service device via the composite password, an access token for logging into a first application. The first service device can separate the static password and the one-time password from the composite password, and acquire a two-factor verification result of the static password and the one-time password. Two-factor authentication is introduced into a conventional password-based authentication process, thereby improving security of identity authentication and contributing to improving security of application login. In addition, a password-based authentication process of OIDC is also used, thereby reducing intrusion into the password-based authentication process and reducing development difficulty and costs of identity authentication.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1

Multi-factor authentication providing a credential via a contactless card for secure messaging

Exemplary embodiments may use a contactless card as a secondary form of authentication in a multi-factor authentication for a secure messaging service. The recipient party of a request to initiate a messaging service session (such as a server computing device) may be programmed to use the phone number of the originating device to look up records regarding an identity of a party and their associated phone number as a primary credential and then may require an authentication credential originating from the contactless card as a secondary credential for the initiating party. In some instances, the credential originating from the contactless card is a onetime password that is valid only for a period of time. The recipient party determines whether the onetime password is valid. If both credentials are valid, a secure messaging session may be initiated with the initiating party.
Owner:CAPITAL ONE SERVICES LLC

Using subscriber identity module (SIM) card as a security key for SIM swap fraud prevention

A method of utilizing a SIM card as a security key for subscriber identity module (SIM) swap prevention is described. The method includes receiving, from a service provider, an initial one-time password (OTP) delivery request comprising an OTP message, a mobile station international subscriber directory number (MSISDN) destined to receive the OTP message, and a SIM indicator associated with the MSISDN; determining, based on the OTP delivery request, a current international mobile subscriber identity (IMSI) associated with the MSISDN; obtaining, from a datastore based on the SIM indicator associated with the MSISDN, an IMSI of record for the MSISDN; comparing the current IMSI associated with the MSISDN and the IMSI of record for the MSISDN; and determining, based on the comparing, whether to deliver the OTP message to the MSISDN or block delivery of the OTP message to the MSISDN.
Owner:T MOBILE INNOVATIONS LLC

Online authentication systems and methods

A server may include at least one server processor configured to execute an application. A desktop virtualization system may include at least one desktop virtualization processor. The desktop virtualization processor may be configured to instantiate a virtual desktop; authenticate a user of a client device; in response to authenticating the user of the client device, place the client device in communication with the virtual desktop through at least one network; launch a secure browser in the virtual desktop; and using the secure browser, place the client device in communication with the server through the at least one network. The application may be configured to perform processing in response to at least one command from the client device. The processing may include generating a one-time passcode, establishing a code word not communicated through the at least one network, and sending a message including the one-time passcode to a sender client device.
Owner:AXOS BANK

System and method for securing financial transactions using geotagged and timestamped machine-readable codes

Exemplary embodiments of the present disclosure are, directed towards a system and method for securing financial transactions using geotagged and timestamped machine-readable codes. The system includes computing device with financial transactions securing module that enables user device registration with elements such as IMEI, SIM, IP address, and GPS data to create secure device profile. Unique machine-readable code is, generated for each transaction, embedding real-time geolocation, timestamp, and transaction data to ensure location-based authenticity. Biometric authentication further verifies the user's identity. The system transmits transaction data to server with financial transactions verification module, which performs real-time location verification by cross-referencing GPS data and validating timestamps to prevent expired code reuse. The system detects device-specific mismatches, anomalies, and unauthorized access attempts, generating alerts and automatically blocking transactions if inconsistencies arise. Fallback OTP verification is, triggered when primary verification fails; ensuring only authorized users complete the transaction. This system enhances security, transparency, and fraud prevention in digital transactions.
Owner:KUNAPARAJU RAMBABU

System, method and apparatus for liveness verification using biometric one-time password

A system for liveness verification is disclosed, including a liveness verification token, a registered client device, and a liveness verification server. The token includes a biometric sensor, a one-time password (OTP) generator, a clock module, and a token interface, and is configured to obtain a biometric reading from an individual, compare it to a registered biometric reading to verify identity, determine whether the individual is alive at the time of reading, and generate an OTP based in part on the biometric reading and a password key. The server includes an OTP generator, a clock module, and an interface through which the server receives the OTP generated by the token. The server is configured to generate an OTP using information stored in a user file that is associated with the individual and identified with a unique identifier included in the token OTP. The server verifies the liveness of the individual by comparing the OTPs.
Owner:伊斯梅尔·吉布林

Systems and methods of cloud-based multifactor authentication

A method may include receiving, by a multifactor authentication (MFA) service instantiated on a computing system, a token generated by a cloud services provider and associated with a user device. The MFA service may be instantiated within a tenancy of the cloud services provider. The method may include determining, by the computing system, an authorized cloud service instantiated within the tenancy. The method may include receiving, by the computing system, a request to access the authorized cloud service by the user device, where the request may include a multi-factor authentication request. The method may include generating, by the MFA service instantiated on the computing system, a one-time pad (OTP). The method may include providing, by the MFA service instantiated on the computing system, the OTP to the user device such that the user device accesses the authorized cloud service.
Owner:MCMILLEN HOLDINGS INC DBA RYANTECH

System and method for parallel manufacture and verification of one-time-password authentication cards

The disclosed system and method are directed to a novel implementation of encryption service provision which obviates a need for network communication between a card manufacturing / personalization entity and a validation entity during the card personalization phase. The proposed solution decouples the operation flow associated with personalization of an OTP card (as carried out by a manufacturing HSM) and the validation of an OTP card cryptogram (as carried out by a distinct validation HSM). This is accomplished by the generation and distribution of a third master key which enables the personalization and the validation HSMs to independently derive the shared secret value used in generation and validation of a transaction cryptogram associated with an OTP card operation.
Owner:CAPITAL ONE SERVICES LLC

Online authentication for medical devices

A medical device includes a QR generator and a user access / activity log. The QR generator generates a QR code at least from a username of a user and at least one OTP (one-time password) for the user and enables access of the user to the medical device upon receiving an OTP from the user. The user sends the QR code to an online authorization server for the medical device for decryption upon authentication of the user. The log lists user activity once the user is authenticated by the server. The server receives the QR code, which includes at least an encrypted text containing at least the OTP and a user identification, and decrypts the encrypted text using a private key associated with the medical device. The authorization server enables the user to log in for authentication and, if authenticated, displays the at least one OTP to the user.
Owner:BIOSENSE WEBSTER (ISRAEL) LTD

Method and apparatus for providing order information using dynamic QR codes

A method and apparatus for providing order information using a dynamic QR code are provided. An order information provision method using a dynamic QR code according to one embodiment of the present invention is executed by a computing device and includes the steps of obtaining a one-time password from a first URL in response to a protocol request from a user terminal, verifying the validity of the one-time password, and, if the one-time password is valid, providing the user terminal with corresponding internet resource address information based on the one-time password. The user terminal can recognize the QR code displayed on the QR code terminal to obtain the first URL, send the protocol request to the location specified by the first URL, and access the order information using the internet resource address information provided in response to the protocol request.
Owner:ARCH SEOUL CO LTD

Authentication apparatus, method, and computer program

To solve the problem of the theft of personal information of a user caused by the theft of a unique common number assigned to the user.SOLUTION: The user device generates a one-time password (S1104). A user delivers a one-time password and individual information to a requesting device (S1106, S1301). The requesting device sends the one-time password and the private information to the authenticating device (S1302, S1206). The authenticating device 200 generates a one-time password (S1205). When the authenticator determines that the one-time password is valid and the private information is valid (S1207), the authenticator generates an authenticator and sends it to the requester (S1208, S1209, S1303).SELECTED DRAWING: Figure 8
Owner:NTI