Invention Grant
- Patent Title: Authentication based on shared secret seed updates for one-time passcode generation
-
Application No.: US16264925Application Date: 2019-02-01
-
Publication No.: US11032271B2Publication Date: 2021-06-08
- Inventor: Brian C. Mullins , Kevin Bowers
- Applicant: RSA Security LLC
- Applicant Address: US MA Bedford
- Assignee: RSA Security LLC
- Current Assignee: RSA Security LLC
- Current Assignee Address: US MA Bedford
- Agency: Danielson Legal LLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/08

Abstract:
Techniques are provided for authenticating a user using shared secret seed updates for one-time passcode (OTP) generation. One method comprises, in response to a first authentication of a client using a given OTP derived from a given shared secret seed, updating, by a server, the given shared secret seed using the given OTP and/or a timestamp from the first authentication to generate an updated given shared secret seed; and evaluating a second authentication using a new OTP derived from the updated given shared secret seed. An anomaly may be detected when the client attempts the second authentication using an OTP and the server determines that the OTP was generated by a previously used shared secret seed. The server may store a set of previously accepted OTPs, and evaluate the previously accepted OTPs to validate the new OTP.
Public/Granted literature
- US20200252392A1 Authentication Based on Shared Secret Seed Updates for One-Time Passcode Generation Public/Granted day:2020-08-06
Information query