发明名称 Methods and systems for secure user authentication
摘要 Methods and systems for secure user authentication utilizes OTP generation and validation techniques in which the shared secret for generating the OTP is not stored in the user's mobile device but instead is dynamically synthesized based on a PIN that activates the OTP generation and the personalized OTP data. The client software has no knowledge of what the correct PIN should be and always generates a normal looking OTP based on whatever PIN is entered, and the only way to learn whether or not the OTP is correct is to submit it during user login. By limiting the number of failed login attempts before the account is locked, brute-force attacks via the online channel will fail, and further, brute-force attacks to uncover the correct PIN for generating the correct OTP offline will also fail even if a hacker steals the user's mobile device and extracts the data inside for offline hacking, because there is nothing on the client that contains the PIN or encrypted by the PIN.
申请公布号 US7904946(B1) 申请公布日期 2011.03.08
申请号 US20060636839 申请日期 2006.12.11
申请人 CITICORP DEVELOPMENT CENTER, INC. 发明人 CHU RONALD KING-HANG;KOGEN MARK;TAN WARREN;MA SIMON;SMUSHKOVICH YOSIF;GLINDRO GERRY;NICHOLAS JEFFREY WILLIAM COYTE
分类号 H04L29/00 主分类号 H04L29/00
代理机构 代理人
主权项
地址