×

One time password entry to access multiple network sites

  • US 20030115452A1
  • Filed: 12/19/2000
  • Published: 06/19/2003
  • Est. Priority Date: 12/19/2000
  • Status: Abandoned Application
First Claim
Patent Images

1. A system for accessing multiple different network stations without entry of a password, comprising:

  • a first network station representing a network entity and configured to transmit a request for authentication of a user seeking access, the user having an associated password, an associated user identifier, and an associated asymmetric crypto-key, including a first private key portion obtainable with the password, a second private key portion and a public key portion;

    a second network station representing the user, and having the user identifier, a combination symmetric crypto-key corresponding to a first symmetric crypto-key and a second symmetric crypto-key, and the obtained first private key portion encrypted with the first symmetric crypto-key stored thereat, and configured to (i) transmit the stored user identifier MAC'"'"'d with the stored combination symmetric crypto-key responsive to the transmitted authentication request, and (ii) transmit the transmitted authentication request encrypted with the stored combination symmetric crypto-key; and

    a third network station, representing a sponsor, having the user identifier, the combination symmetric crypto-key, the first symmetric crypto-key, and the second private key portion stored thereat, and configured to (i) retrieve the stored combination symmetric crypto-key by matching the transmitted user identifier with the stored user identifier, (ii) verify the MAC with the retrieved combination symmetric crypto-key to verify identity of the user, (iii) decrypt the transmitted encrypted authentication request with the retrieved combination symmetric crypto-key to recover the authentication request, (iv) encrypt the recovered authentication request with the stored second private key portion and (v) transmit the encrypted authentication request and the first symmetric crypto-key, both encrypted with the retrieved combination symmetric crypto-key;

    wherein the second network station is further configured to (i) decrypt the transmitted encrypted authentication request and first symmetric crypto-key, with the stored combination symmetric crypto-key to recover the encrypted authentication request and the first symmetric crypto-key, (ii) decrypt the stored encrypted first private key portion with the recovered first symmetric crypto-key to recover the first private key portion, (iii) to transmit the recovered encrypted authentication request further encrypted with the recovered first private key portion;

    wherein the first station is further configured to decrypt the transmitted further encrypted authentication request with the public key to thereby authenticate the user.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×