METHOD FOR SECURE USER AND SITE AUTHENTICATION
First Claim
1. A method of authenticating a user on a network, comprising:
- receiving, by a security server, a request of a network site for authentication of the user;
calculating, by the security server in response to the receipt of the authentication request, a one-time-password based on a secret shared by the security server and the network site but not by the user, wherein the one-time-password is independently calculable by the network site based on the shared secret; and
transmitting, by the security server, the calculated one-time-password to authenticate the user to the network site.
11 Assignments
0 Petitions
Accused Products
Abstract
The present invention provides a new method of site and user authentication. This is achieved by creating a pop-up window on the user'"'"'s PC that is in communication with a security server, and where this communication channel is separate from the communication between the user'"'"'s browser and whichever web site they are at. A legitimate web site embeds code in the web page which communicates to the security server from the user'"'"'s desktop. The security server checks the legitimacy of the web site and then signals both the web page on the user'"'"'s browser, as well as the pop-up window to which it has a separate channel. The security server also sends a random image to both the pop-up window and the browser. If user authentication is requested by the web site the user is first authenticated by the security server for instance by out of band authentication. Then the security server computes a one time password based on a secret it shares with the web site and sends it to the pop up window. The user copies this one time password into their browser which sends it to the web site, which can re-compute the one time password to authenticate the user.
84 Citations
25 Claims
-
1. A method of authenticating a user on a network, comprising:
-
receiving, by a security server, a request of a network site for authentication of the user; calculating, by the security server in response to the receipt of the authentication request, a one-time-password based on a secret shared by the security server and the network site but not by the user, wherein the one-time-password is independently calculable by the network site based on the shared secret; and transmitting, by the security server, the calculated one-time-password to authenticate the user to the network site. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. An article of manufacture for authenticating a user on a network, comprising:
-
processor readable storage medium; and logic stored on the storage medium, wherein the stored logic is configured to be readable by a processor and thereby cause the processor to operate so as to; receive a request of a network site for authentication of the user; calculate in response to the receipt of the authentication request, a one-time-password based on a secret shared by a security server and the network site but not by the user, wherein the one-time-password is independently calculable by the network site based on the shared secret; and transmit the calculated one-time-password to authenticate the user to the network site. - View Dependent Claims (11, 12, 13, 14, 15)
-
-
16. A system for authenticating a user on a network, comprising:
-
a communications port configured to receive a request of a network site for authentication of the user; and a processor configured to calculate, in response to the receipt of the authentication request, a one-time-password based on a secret shared by a security server and the network site but not by the user, and to direct transmission of the calculated one-time-password to authenticate the user to the network site; wherein the one-time-password is independently calculable by the network site based on the shared secret. - View Dependent Claims (17, 18, 19, 20, 21)
-
-
22. A method of authenticating a user on a network, comprising:
-
receiving, by a first user agent on a user network device from a network site, a request of the network site for the user to be authenticated; transmitting, by the first user agent to a security server, the network site request; receiving, by a second user agent on the user network device from the security server in response to transmission of the network site request, a one-time-password calculated based on a secret shared by the security server and the network site but not by the user; transferring the one-time-password from second user agent to first user agent; and transmitting, by the first user agent to the network site, the one-time-password to authenticate the user to the network site wherein the one-time-password is independently calculable by the network site based on the shared secret. - View Dependent Claims (23, 24, 25)
-
Specification