发明名称 Authenticating a User with Hash-Based PIN Generation
摘要 Systems and methods for authenticating a user of a service are disclosed. A Personal Identification Number (PIN) is generated using a plurality of variables, and a user is authenticated by comparing the PIN generated at the user's mobile device with a PIN generated on an authentication server. The authentication enables the user to access a service or resource hosted on a host server. When requesting access to the resource, the user generates a device PIN and transmits the device PIN along with their unique key into the host server. The host server forwards the device PIN and the key to the authentication server. The authentication server generates a server PIN and compares the server PIN to the device PIN. If the two PINs match, the authentication server transmits a successful authentication response to the host server. The PIN generation process is a standard hash process, such as MD5 or SHA1, and uses at least the key provided by the user, a device identifier, and a current date/time. The device identifier is one of a unique identifier of the hardware on the mobile device or a unique identifier of a communication channel. This combination of the device identifier and the key ensures that only an authorized user is allowed access to the service.
申请公布号 US2012144203(A1) 申请公布日期 2012.06.07
申请号 US20100961163 申请日期 2010.12.06
申请人 ALBISU LUIS F.;AT&T INTELLECTUAL PROPERTY I, L.P. 发明人 ALBISU LUIS F.
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址