Methods and system for device authentication

US9332432B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9332432-B2
Application numberUS-201313958520-A
CountryUS
Kind codeB2
Filing dateAug 2, 2013
Priority dateAug 2, 2013
Publication dateMay 3, 2016
Grant dateMay 3, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A request is received to access a user account. A geolocation of a mobile device registered with the user account is obtained directly from the mobile device. Authentication credentials for the user account are verified for correctness. A mobile device geolocation verification request is transmitted to a cellular data provider. The cellular data provider is equipped to independently determine a true geolocation region of the mobile device for comparison with the geolocation of the mobile device as obtained directly from the mobile device. A verification response to the mobile device geolocation verification request is received from the cellular data provider. The verification response indicates whether or not the geolocation of the mobile device as obtained directly from the mobile device corresponds to the true geolocation region of the mobile device. A response to the access request based on the verification response is transmitted.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for authentication of a request to access a user account, comprising: operating a server to receive an access request to access a user account, the access request including authentication credentials; obtaining at the server a geolocation of a mobile device registered with the user account from the mobile device, wherein the geolocation of the mobile device is obtained directly from the mobile device; operating the server to verify correctness of the authentication credentials for the user account; operating the server to transmit a mobile device geolocation verification request to a cellular data provider, the cellular data provider equipped to independently determine a true geolocation region of the mobile device for comparison with the geolocation of the mobile device as obtained directly from the mobile device; receiving at the server from the cellular data provider a verification response to the mobile device geolocation verification request, the verification response indicating whether or not the geolocation of the mobile device as obtained directly from the mobile device corresponds to the true geolocation region of the mobile device; and operating the server to transmit a response to the access request based on the verification response. 2. A method for authentication of a request to access a user account as recited in claim 1 , wherein the access request is received from the mobile device. 3. A method for authentication of a request to access a user account as recited in claim 1 , wherein the geolocation of the mobile device obtained from the mobile device is defined as latitude and longitude coordinates of a current location of the mobile device. 4. A method for authentication of a request to access a user account as recited in claim 1 , wherein the geolocation of the mobile device obtained from the mobile device is defined as an identification of a cell tower to which the mobile device is currently registered. 5. A method for authentication of a request to access a user account as recited in claim 1 , wherein transmitting the mobile device geolocation verification request is done upon successful verification of correctness of the authentication credentials for the user account. 6. A method for authentication of a request to access a user account as recited in claim 1 , wherein the mobile device geolocation verification request includes a cell number of the mobile device and the geolocation of the mobile device obtained directly from the mobile device. 7. A method for authentication of a request to access a user account as recited in claim 1 , wherein the cellular data provider is equipped to access a cellular network to determine a geolocation of a cell tower to which the mobile device is currently registered, wherein the geolocation of the cell tower is defined as one or more of an identification of the cell tower and latitude and longitude coordinates of the cell tower. 8. A method for authentication of a request to access a user account as recited in claim 7 , wherein the true geolocation region of the mobile device is defined as a geographic area over which a communication can be transmitted from the cell tower to which the mobile device is currently registered. 9. A method for authentication of a request to access a user account as recited in claim 1 , wherein the verification response indicates whether or not the geolocation of the mobile device obtained directly from the mobile device corresponds to the true geolocation region of the mobile device as determined by the cellular data provider. 10. A method for authentication of a request to access a user account as recited in claim 9 , wherein the verification response is defined as a probability that the mobile device geolocation obtained directly from the mobile device corresponds to the true geolocation region of the mobile device as determined by the cellular data provider. 11. A method for mobile device authentication, comprising: operating a server to receive a mobile device geolocation verification request including an identifier of a mobile device and a unverified geolocation of the mobile device; operating the server to direct performance of a process to determine a geolocation region of a cell tower to which the mobile device is currently registered; operating the server to compare the geolocation region of the cell tower to the unverified geolocation of the mobile device to generate a response to the mobile device geolocation verification request; and operating the server to provide the response to the mobile device geolocation verification request in reply to the mobile device geolocation verification request. 12. A method for mobile device authentication as recited in claim 11 , wherein the identifier of the mobile device is a cell number of the mobile device. 13. A method for mobile device authentication as recited in claim 11 , wherein the unverified geolocation of the mobile device is defined as one or more of latitude and longitude coordinates of the mobile device and an identifier of a cell tower to which the mobile device asserts a current connection. 14. A method for mobile device authentication as recited in claim 11 , wherein determining the geolocation region of the cell tower to which the mobile device is currently registered includes transmitting a simple message system ping through a cellular network to the mobile device. 15. A method for mobile device authentication as recited in claim 14 , wherein the simple message system ping is hidden from a user of the mobile device. 16. A method for mobile device authentication as recited in claim 11 , wherein the geolocation region of the cell tower is defined as a geographic area over which a communication can be transmitted from the cell tower to which the mobile device is currently registered. 17. A method for mobile device authentication as recited in claim 11 , wherein the response to the mobile device geolocation verification request indicates whether or not the unverified geolocation of the mobile corresponds to the geolocation region of the cell tower to which the mobile device is currently registered. 18. A method for mobile device authentication as recited in claim 17 , wherein the response to the mobile device geolocation verification request is defined as a probability that the unverified geolocation of the mobile device corresponds to the geolocation region of the cell tower to which the mobile device is currently registered. 19. A system for authentication of a request to access a user account, comprising: a plurality of servers for managing the user account, wherein one or more of the plurality of servers include logic for, receiving an access request to access the user account, the access request including authentication credentials, obtaining a geolocation of a mobile device registered with the user account from the mobile device, wherein the geolocation of the mobile device is obtained directly from the mobile device, verifying correctness of the authentication credentials for the user account, transmitting a mobile device geolocation verification request to a cellular data provider, the cellular data provider equipped to independently determine a true geolocation region of the mobile device for comparison with the geolocation of the mobile device as obtained directly from the mobile device, receiving from the cellular data provider a verification response to the mobile device geolocation verification request, the verification response indicating whethe

Assignees

Inventors

Classifications

  • H04L63/107Primary

    wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

  • H04W12/06Primary

    Authentication · CPC title

  • using credential vaults, e.g. password manager applications or one time password [OTP] applications · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9332432B2 cover?
A request is received to access a user account. A geolocation of a mobile device registered with the user account is obtained directly from the mobile device. Authentication credentials for the user account are verified for correctness. A mobile device geolocation verification request is transmitted to a cellular data provider. The cellular data provider is equipped to independently determine a…
Who is the assignee on this patent?
Yahoo Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/107. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 03 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).