×

Session key security protocol

  • US 7,971,240 B2
  • Filed: 04/20/2009
  • Issued: 06/28/2011
  • Est. Priority Date: 05/15/2002
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method for exchanging information in a multi-site authentication system having a first network server and a second network server coupled to a data communication network, said method comprising:

  • receiving, from a client computing device via the first network server, a request for a service provided by the second network server;

    receiving, from the first network server, an authentication ticket along with the request, said authentication ticket including;

    a session key encrypted by a public key associated with the second network server;

    message content encrypted by the session key; and

    a signature generated by the first network server using a private key associated with the first network server to sign the encrypted session key and the encrypted message content, said signature including address information of the second network server;

    decrypting, at the second network server, the signature included in the authentication ticket using a public key associated with the first network server that corresponds to the private key used to generate the signature;

    identifying, at the second network server, the address information for the second network server in the verified signature to validate the signature included in the authentication ticket;

    verifying, at the second network server, the authentication ticket content based on the validated signature included in the authentication ticket;

    decrypting, at the second network server, the encrypted session key included in the authentication ticket via a private key associated with the second network server; and

    decrypting, at the second network server, the encrypted message content included in the authentication ticket via the decrypted session key.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×