Invention Grant
- Patent Title: Automatic upgrade from one step authentication to two step authentication via application programming interface
-
Application No.: US15813712Application Date: 2017-11-15
-
Publication No.: US10592656B2Publication Date: 2020-03-17
- Inventor: Larry A. Brocious , Michael J. Howland , Paul E. Rogers
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee Address: US NY Armonk
- Agency: Garg Law Firm, PLLC
- Agent Rakesh Garg; Edward Wixted
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/40 ; H04L9/32 ; H04L9/08 ; H04L29/06 ; G06F21/31

Abstract:
A client transmits a user identifier and a password to a server via an application programming interface (API). The client establishes an authenticated session with the server in which the client has a first set of permissions for operations associated with the API. The client receives, responsive to a verification of the user identifier and password by the server, a logon response and a shared secret. The client generates a one time passcode (OTP) based upon the shared secret. The client sends the OTP to the server via the API. Responsive to the server validating the OTP against the shared secret, the server grants a second set of permissions for operations associated with the API.
Public/Granted literature
Information query