Automated security token administrative services
First Claim
1. A system allowing a security token user to perform at least one administrative security function on his security token, whereby said user does not need to login in an operating system, the system comprising:
- at least one credential associated with said user;
an authenticating computer system;
a local client in processing communications with an authenticating computer system including;
one or more functionally connected user input devices;
a user interface for handling input from and output to said user;
an access request generator that generates and sends an administrative access request to said authenticating computer system to perform said at least one administrative security function, wherein said administrative access request includes said at least one credential; and
a mediating section that mediates said at least one administrative security function between said authenticating computer system, said client and said user; and
wherein said authenticating computer system includes;
a security section that is responsive to said administrative access request for performing said at least one administrative security function, wherein said at least one administrative security function includes an authenticating section that authenticates said user to said authenticating computer system using said at least one credential and an access section that allows access to system resources and services, without logging said user on to an operating environment associated with said local client, wherein;
if said user is authenticated, said at least one administrative security function is retrieved and sent to said local client for routing into said security token and said at least one administrative function is performed on the security token, andif said user authentication fails, the attempt to perform said at least one administrative function on the security token is ended.
4 Assignments
0 Petitions
Accused Products
Abstract
This invention provides a system, method and computer program product to allow a user to access administrative security features associated with the use of a security token. The administrative security features provide the user the ability to unlock a locked security token, diagnose a security token, activate and deactivate a security token, request a replacement security token or temporary password or report the loss of a security token. The invention comprises a client application which integrates into the standard user login dialog associated with an operating system. A portion of the user dialog is linked to a remote server to access the administrative services.
27 Citations
24 Claims
-
1. A system allowing a security token user to perform at least one administrative security function on his security token, whereby said user does not need to login in an operating system, the system comprising:
-
at least one credential associated with said user; an authenticating computer system; a local client in processing communications with an authenticating computer system including; one or more functionally connected user input devices; a user interface for handling input from and output to said user; an access request generator that generates and sends an administrative access request to said authenticating computer system to perform said at least one administrative security function, wherein said administrative access request includes said at least one credential; and a mediating section that mediates said at least one administrative security function between said authenticating computer system, said client and said user; and
wherein said authenticating computer system includes;a security section that is responsive to said administrative access request for performing said at least one administrative security function, wherein said at least one administrative security function includes an authenticating section that authenticates said user to said authenticating computer system using said at least one credential and an access section that allows access to system resources and services, without logging said user on to an operating environment associated with said local client, wherein; if said user is authenticated, said at least one administrative security function is retrieved and sent to said local client for routing into said security token and said at least one administrative function is performed on the security token, and if said user authentication fails, the attempt to perform said at least one administrative function on the security token is ended. - View Dependent Claims (2, 3, 4, 6, 7, 8, 9, 10, 11, 12, 14, 15, 16, 17, 18)
-
-
5. A system allowing a security token user to perform at least one administrative security function on his security token, whereby said user does not need to login in an operating system, the system comprising:
-
at least one credential associated with said user; a security token functionally connected to a local client including a user authentication mechanism, wherein said user authentication mechanism includes a changeable security state, said changeable security state operative to mediate access to system resources and services; said local client in processing communications with a server including; one or more functionally connected user input devices; a user interface for handling input from and output to said user; an access request generator that generates and sends an administrative access request to said server to perform said at least one administrative security function, wherein said administrative access request includes said at least one credential; a mediating section that mediates at least one administrative security function between said server, said client and said security token; and said server including; a security section that is responsive to said administrative access request for performing said at least one administrative security function, wherein said at least one administrative security function includes an authenticating section that authenticates said user to said server using said at least one credential and a security state altering section that alters changeable security state, without logging said user on to an operating environment associated with said local client, wherein; if said user is authenticated, said at least one administrative security function is retrieved and sent to said local client for routing into said security token and said at least one administrative function is performed on the security token, and if said user authentication fails, the attempt to perform said at least one administrative function on the security token is ended. - View Dependent Claims (13)
-
-
19. A method allowing a security token user to perform at least one administrative security function on his security token, whereby said user does not need to login in an operating system, the method comprising the steps of:
-
displaying said at least one administrative security function on a user interface display, receiving a credential from a user interface input device without logging on to an operating environment associated with said local client, causing a request for said at least one administrative security function to be sent to an authenticating computer system, wherein said request includes said credential, attempting to authenticate said user using said credential, if said user is authenticated, retrieving said at least one administrative security function, sending said at least one administrative security function to said local client for routing into said security token, and performing said at least one administrative function on the security token, and ending the attempt to perform said at least one administrative function on the security token if said user authentication fails. - View Dependent Claims (20, 21, 22, 23)
-
-
24. A computer program product embodied in a tangible form readable by a computer system having executable instructions stored thereon for causing the computer system to allow a security token user to perform at least one administrative security function on his security token, whereby said user does not need to login in an operating system, said executable instructions comprising the actions of:
-
causing a client application to display said at least one administrative security function on a user interface display associated with said local client, causing said client application to receive said user'"'"'s request for said at least one administrative security function from a user input device, causing a credential input by said user in combination with said user'"'"'s request to transmit said at least one administrative security function over a network to a remote server, causing a server application to receive said request and said credential from said network, causing said server application to authenticate said user using said credential against a stored reference, and if said user is authenticated, causing retrieval of said at least one administrative security function, causing said at least one administrative security function to be sent to said local client for routing into said security token, and causing the performance of said at least one administrative function on the security token, and ending the attempt to perform said at least one administrative function on the security token if said user authentication fails, wherein said actions are executed without logging said user on to an operating environment associated with said local client.
-
Specification