US2004098627A1PendingUtilityA1

Process based security system authentication system and method

Priority: Feb 1, 2002Filed: Aug 5, 2003Published: May 20, 2004
Est. expiryFeb 1, 2022(expired)· nominal 20-yr term from priority
Inventors:Vincent Larsen
G06F 21/6218G06F 2221/2141
32
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for authenticating a user in a process-based security system between an authenticating process and an authentication module, begins when the authenticating process sends an initiation request to an authentication module. The authentication module modifies a task structure of the authenticating process to indicate the initiation request and generates a random number. The random number is sent to the authenticating process. The authenticating process performs a transformative function on said random number and a user password to form first authenticating data. The first authenticating data and user identification data is sent to the authentication module. The authentication module retrieves a user password associated with the received user identification data and performs the transformative function on the random number and said retrieved user password to form second authenticating data. The first authenticating data is compared with the second authenticating data, such that when the first authenticating data is equal to the second authenticating data, the user identified by the user identification data is authenticated.

Claims

exact text as granted — not AI-modified
What is claimed is:  
     
         1 . A method for authenticating a user in a process-based security system, comprising the steps of: 
 sending an initiation request from an authenticating process to an authentication module;    modifying a task structure of the authenticating process to indicate the initiation request;    generating a random number at said authentication module;    sending said random number to said authenticating process;    performing a transformative function on said random number and a user password by the authenticating process to form first authenticating data;    sending said first authenticating data and user identification data to said authentication module;    retrieving a user password associated with the received user identification data by the authentication module;    performing said transformative function on said random number and said retrieved user password by the authentication module to form second authenticating data;    comparing said first authenticating data with said second authenticating data, such that when said first authenticating data is equal to said second authenticating data, the user identified by the user identification data is authenticated.    
     
     
         2 . The method of authenticating in accordance with  claim 1 , wherein said authenticating process is a login routine.  
     
     
         3 . The method of authenticating in accordance with  claim 1 , wherein said authentication module is part of an operating system.  
     
     
         4 . The method for authenticating of  claim 1 , further comprising the step of checking the task structure of the authenticating process to determine if an authentication has been initiated before the step of retrieving a user password.  
     
     
         5 . The method for authenticating of  claim 1 , wherein said transformative function in a hash function.  
     
     
         6 . The method for authenticating of  claim 1 , wherein said transformative function is a keyed MD5 signature function.  
     
     
         7 . The method for authenticating of  claim 1 , wherein said random number is a cryptographically strong pseudo-random number.  
     
     
         8 . The method for authenticating of  claim 1 , further comprising the step of storing the user password in unencrypted form.  
     
     
         9 . The method for authenticating of  claim 1 , wherein said transformative function is performed on said random number concatenated with said user password.  
     
     
         10 . The method for authenticating of  claim 1 , further comprising the step of modifying the task structure of the authenticating process to indicate completion of the initiation request.  
     
     
         11 . A system for authenticating a user in a process-based security system, comprising: 
 an authentication module;    an authenticating process in communication with said authentication module;    wherein said authenticating process sends an authentication request to an authentication module and the authentication modifies a task structure of the authenticating process to indicate the authentication request; wherein the authentication module generates a random number and send said random number to said authenticating process, the authenticating process performing a transformative function on said random number and a user password to form first authenticating data; the authenticating process sends said first authenticating data and user identification data to said authentication module; the authentication module retrieves a user password associated with the received user identification data and performs said transformative function on said random number and said retrieved user password to form second authenticating data; and    the authentication module compares said first authenticating data with said second authenticating data, such that when said first authenticating data is equal to said second authenticating data, the user identified by the user identification data is authenticated.    
     
     
         12 . The system for authenticating in accordance with  claim 11 , wherein said authenticating process is a login routine.  
     
     
         13 . The system for authenticating in accordance with  claim 11 , wherein said authentication module is part of an operating system.  
     
     
         14 . The system for authenticating of  claim 11 , further comprising the authentication module checking the task structure of the authenticating process to determine if an authentication has been initiated before the step of retrieving a user password.  
     
     
         15 . The system for authenticating of  claim 11 , wherein said transformative function in a hash function.  
     
     
         16 . The system for authenticating of  claim 11 , wherein said transformative function is a keyed MD 5  signature function.  
     
     
         17 . The system for authenticating of  claim 11 , wherein said random number is a cryptographically strong pseudo-random number.  
     
     
         18 . The system for authenticating of  claim 11 , further comprising the step of storing the user password in unencrypted form.  
     
     
         19 . The system for authenticating of  claim 11 , wherein said transformative function is performed on said random number concatenated with said user password.  
     
     
         20 . The system for authenticating of  claim 11 , further comprising the authentication module modifying the task structure of the authenticating process to indicate completion of the initiation request.

Join the waitlist — get patent alerts

Track US2004098627A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.