US2014157393A1PendingUtilityA1

Proxy authentication network

Assignee: IAMSECUREONLINE INCPriority: Jun 13, 2005Filed: Feb 6, 2014Published: Jun 5, 2014
Est. expiryJun 13, 2025(expired)· nominal 20-yr term from priority
H04L 63/0407H04L 9/321H04L 63/0884H04L 9/085G06F 21/33H04L 2209/76H04L 9/0861H04L 63/08H04L 63/0853H04L 9/0894
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A Proxy Authentication Network includes a server that stores credentials for subscribers, along with combinations of devices and locations from which individual subscribers want to be authenticated. Data is stored in storage: the storage can be selected by the subscriber. The data stored in the storage, which can be personally identifiable information, can be stored in an encrypted form. The key used to encrypt such data can be divided between the storage and server. In addition, third parties can store portions of the encrypting key. Subscribers can be authenticated using their credentials from recognized device/location combinations; out-of-band authentication supports authenticating subscribers from other locations. Once authenticated, a party can request that the encrypted data be released. The portions of the key are then assembled at the storage. The storage then decrypts the data, generates a new key, and re-encrypts the data for transmission to the requester.

Claims

exact text as granted — not AI-modified
1 . A method of authenticating via a computer server, comprising: the computer server receiving via a first communications channel an authentication token from a first authentication client; the computer server determining an authenticity of the authentication token; and in accordance with an outcome of the authenticity determining, the computer server transmitting a payload to a second authentication client via a second communications channel distinct from the first communications channel. 
     
     
         2 . The method according to  claim 1 , wherein the payload effects a completion of a transaction with a relying party server distinct from the computer server, the authentication token receiving comprises a first segment of the transaction, and the payload transmitting comprises a second segment of the transaction. 
     
     
         3 . The method according to  claim 1 , wherein the first authentication client is provided in a communication device, the authentication token is provided in a hardware token distinct from the communication device, and the authentication token receiving comprises the first authentication client requesting the authentication token from the hardware token, and the computer server receiving the requested authentication token from the first authentication client. 
     
     
         4 . The method according to  claim 3 , wherein the authenticity determining comprises the computer server verifying that the authentication token was generated by the hardware token. 
     
     
         5 . The method according to  claim 1 , wherein the first authentication client and the authentication token are provided in a common communication device, and the authentication token receiving comprises the computer server receiving the authentication token released from the communication device. 
     
     
         6 . The method according to  claim 1 , wherein the authentication token is provided in a credential server, and the authentication token receiving comprises the computer server receiving the authentication token from the credential server. 
     
     
         7 . The method according to  claim 1 , wherein the payload transmitting comprises the first authentication client specifying the second authentication client and the computer server directing the payload to the specified second authentication client. 
     
     
         8 . The method according to  claim 1 , wherein the payload transmitting comprises the computer server identifying the second authentication client after receipt of the authentication token, and the computer server directing the payload to the identified second authentication client. 
     
     
         9 . The method according to  claim 1 , wherein the payload transmitting comprises the computer server transmitting a session token to the first authentication client, receiving a payload request from the second authentication client, and transmitting the payload to the second authentication client in accordance with a correlation between the payload request and the session token. 
     
     
         10 . The method according to  claim 9 , wherein the payload transmitting further comprises the computer server establishing a secure communications channel with the second authentication client in accordance with the correlation, and transmitting the payload to the second authentication client over the secure communications channel, the second communications channel comprising the secure communications channel. 
     
     
         11 . The method according to  claim 1 , wherein the payload comprises an authentication payload for facilitating authentication of the second authentication client. 
     
     
         12 . The method according to  claim 11 , wherein the authentication payload comprises a session certificate. 
     
     
         13 . The method according to  claim 1 , wherein the payload comprises a command for execution by the second authentication client. 
     
     
         14 . The method according to  claim 13 , wherein the command comprises a form-fill command. 
     
     
         15 . A computer-readable medium comprising computer processing instructions stored thereon for execution by a computer, the computer processing instructions, when executed by the computer, causing the computer to perform the method of  claim 1 . 
     
     
         16 . A computer server comprising: an authentication client configured to determine an authenticity of an authentication token received at the computer server via a first communications channel, and to transmit a payload to a second authentication client via a second communications channel distinct from the first communications channel in accordance with an outcome of the authenticity determination. 
     
     
         17 . The computer server according to  claim 16 , wherein the first authentication client is provided in a communication device, the authentication token is provided in a hardware token distinct from the communication device, and the authentication client receives the authentication token from the first authentication client. 
     
     
         18 . The computer server according to  claim 16 , wherein the first authentication client and the authentication token are provided in a common communication device, and the authentication client receives the authentication token from the communication device. 
     
     
         19 . The computer server according to  claim 16 , wherein the authentication token is provided in a credential server, and the authentication client receives the authentication token from the credential server. 
     
     
         20 . The computer server according to  claim 16 , wherein the first authentication client specifies the second authentication client, and the authentication client is configured to direct the payload to the specified second authentication client. 
     
     
         21 . The computer server according to  claim 16 , wherein the authentication client is configured to identify the second authentication client after receipt of the authentication token, and to direct the payload to the identified second authentication client. 
     
     
         22 . The computer server according to  claim 16 , wherein the authentication client is configured to transmit a session token to the first authentication client, receive a payload request from the second authentication client, and transmit the payload to the second authentication client in accordance with a correlation between the payload request and the session token. 
     
     
         23 . The computer server according to  claim 22 , wherein the authentication client is configured to establish a secure communications channel with the second authentication client in accordance with the correlation, and transmit the payload to the second authentication client over the secure communications channel, the second communications channel comprising the secure communications channel. 
     
     
         24 . A method of authenticating to a computer server comprising: a first authentication client transmitting an authentication token to the computer server via a first communications channel; and a second authentication client receiving a payload from the computer server via a second communications channel distinct from the first communications channel in accordance with an outcome of a determination of authenticity of the authentication token by the computer server. 
     
     
         25 . The method according to  claim 24 , wherein the authentication clients are implemented in a common communication device. 
     
     
         26 . The method according to  claim 24 , wherein the authentication clients are implemented in separate communication devices. 
     
     
         27 . The method according to  claim 24 , wherein the first authentication client is provided in a communication device, the authentication token is provided in a hardware token distinct from the communication device, and the authentication token transmitting comprises the first authentication client requesting the authentication token from the hardware token and transmitting the requested authentication token to the computer server. 
     
     
         28 . The method according to  claim 24 , wherein the first authentication client and the authentication token are provided in a common communication device, and the authentication token transmitting comprises the communication device releasing the authentication token to computer server. 
     
     
         29 . The method according to  claim 24 , wherein the authentication token is provided in a credential server, and the authentication token transmitting comprises the first authentication client authorizing the credential server to transmit the authentication token to the computer server. 
     
     
         30 . The method according to  claim 24 , wherein the payload receiving comprises the first authentication client identifying the second authentication client to the computer server and the computer server directing the payload to the identified second authentication client. 
     
     
         31 . The method according to  claim 24 , wherein the second authentication client uses the payload to effect a completion of a transaction with a relying party server distinct from the computer server, the authentication token transmitting comprises a first segment of the transaction, and the payload receiving comprises a second segment of the transaction. 
     
     
         32 . The method according to  claim 24 , wherein the payload receiving comprises the first authentication client receiving a session token from the computer server, and the second authentication client transmitting a payload request to the computer server and receiving the payload from the computer server in accordance with a correlation between the payload request and the session token. 
     
     
         33 . The method according to  claim 32 , wherein the payload receiving further comprises the second authentication client establishing a secure communications channel with the computer server in accordance with the correlation, and receiving the payload over the secure communications channel, the second communications channel comprising the secure communications channel. 
     
     
         34 . The method according to  claim 24 , wherein the payload comprises an authentication payload, and the second authentication client authenticates itself using the authentication payload. 
     
     
         35 . The method according to  claim 34 , wherein the authentication payload comprises a session certificate. 
     
     
         36 . The method according to  claim 24 , wherein the payload comprises a command, and the second authentication client executes the received command. 
     
     
         37 . The method according to  claim 36 , wherein the command comprises a form-fill command. 
     
     
         38 . A communication device comprising: a first authentication client configured to transmit an authentication token to a computer server via a first communications channel; and a second authentication client configured to receive a payload from the computer server via a second communications channel distinct from the first communications channel in accordance with an outcome of a determination of authenticity of the authentication token by the computer server.

Join the waitlist — get patent alerts

Track US2014157393A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.