发明名称 Method and system for enabling secure one-time password authentication
摘要 An approach for facilitating a one-time password (OTP) authentication procedure is described. A dedicated validation appliance receives a one-time password authentication request via an application programming interface, which is a single point of access to the dedicated validation appliance. The dedicated validation appliance then determines a validity of the request based on the correlating of a submitted OTP against OTP values independently generated by the dedicated validation appliance based on a large secret key exclusive to a client device that initiated the request. The single point of access to the dedicated validation appliance as well as exclusive sharing of the secret key with only another dedicated validation appliance or one-time with the client device reduces the likelihood of attackers discovering the secret keys.
申请公布号 US9230084(B2) 申请公布日期 2016.01.05
申请号 US201213658558 申请日期 2012.10.23
申请人 Verizon Patent and Licensing Inc. 发明人 Robertson James A.
分类号 G06F12/14;G06F21/34;H04L9/32;G06F21/30;H04L29/06 主分类号 G06F12/14
代理机构 代理人
主权项 1. A method comprising: receiving, via an application programming interface, a one-time password authentication request, wherein the application programming interface is a single point of access to a dedicated validation appliance for maintaining one or more secret keys, wherein the application programming interface is associated with an authentication service separate from the dedicated validation appliance, wherein the authentication service is restricted from accessing the one or more secret keys; receiving, per the request, a one-time password and an identifier of a user for which the one-time password is exclusively generated for a limited period of time for completion of the authentication procedure; determining, by the dedicated validation appliance, a validity of the request based on a correlation between the identifier of the user and the one-time password with at least one of the one or more secret keys within the limited period of time; and authenticating the user based on the determined validity of the request, wherein the user is associated with a client device for enabling user entry of the one-time password via an authentication service for initiating the authentication.
地址 Basking Ridge NJ US