US Patent Application 18223105. ASSISTED THIRD-PARTY PASSWORD AUTHENTICATION simplified abstract

From WikiPatents
Jump to navigation Jump to search

ASSISTED THIRD-PARTY PASSWORD AUTHENTICATION

Organization Name

Capital One Services, LLC


Inventor(s)

David Benko of San Franciso CA (US)

Michael Chen of Vienna VA (US)

ASSISTED THIRD-PARTY PASSWORD AUTHENTICATION - A simplified explanation of the abstract

This abstract first appeared for US patent application 18223105 titled 'ASSISTED THIRD-PARTY PASSWORD AUTHENTICATION

Simplified Explanation

The patent application describes a system, method, and apparatus for assisted third-party password authentication.

  • The method involves creating a secure connection between a first application and an authorization server on a client device.
  • An inline frame associated with the first application identifies user authorization credential inputs and sends them to the authorization server.
  • The authorization server responds by sending an authorization code back to the inline frame, which then redirects it to the first application.
  • The client device then transmits the authorization code to the authorization server to receive an access token for accessing a second application.


Original Abstract Submitted

Disclosed herein are system, method, and apparatus for assisted third-party password authentication. The method performed at a client device includes creating a secure connection from an inline frame associated with a first application on the client device to an authorization server for accessing a second application. The method includes identifying, by the inline frame, one or more events that represent inputs for a user authorization credential, and proxying, by the inline frame, the identified one or more events to the authorization server using the secure connection. The method includes receiving an authorization code from the authorization server in response to the proxying. The method includes redirecting, by the inline frame, the authorization code to the application on the client device. The method includes transmitting, from the client device to the authorization server, the authorization code to receive an access token for accessing the second application.