Proxy authentication network
Abstract
A Proxy Authentication Network includes a server that stores credentials for subscribers, along with combinations of devices and locations from which individual subscribers want to be authenticated. Data is stored in storage: the storage can be selected by the subscriber. The data stored in the storage, which can be personally identifiable information, can be stored in an encrypted form. The key used to encrypt such data can be divided between the storage and server. In addition, third parties can store portions of the encrypting key. Subscribers can be authenticated using their credentials from recognized device/location combinations; out-of-band authentication supports authenticating subscribers from other locations. Once authenticated, a party can request that the encrypted data be released. The portions of the key are then assembled at the storage. The storage then decrypts the data, generates a new key, and re-encrypts the data for transmission to the requester.
Claims
exact text as granted — not AI-modified1 . A method of authenticating via a computer server, comprising: the computer server receiving via a first communications channel an authentication token from a first authentication client; the computer server determining an authenticity of the authentication token; and in accordance with an outcome of the authenticity determining, the computer server transmitting a payload to a second authentication client via a second communications channel distinct from the first communications channel.
2 . The method according to claim 1 , wherein the payload effects a completion of a transaction with a relying party server distinct from the computer server, the authentication token receiving comprises a first segment of the transaction, and the payload transmitting comprises a second segment of the transaction.
3 . The method according to claim 1 , wherein the first authentication client is provided in a communication device, the authentication token is provided in a hardware token distinct from the communication device, and the authentication token receiving comprises the first authentication client requesting the authentication token from the hardware token, and the computer server receiving the requested authentication token from the first authentication client.
4 . The method according to claim 3 , wherein the authenticity determining comprises the computer server verifying that the authentication token was generated by the hardware token.
5 . The method according to claim 1 , wherein the first authentication client and the authentication token are provided in a common communication device, and the authentication token receiving comprises the computer server receiving the authentication token released from the communication device.
6 . The method according to claim 1 , wherein the authentication token is provided in a credential server, and the authentication token receiving comprises the computer server receiving the authentication token from the credential server.
7 . The method according to claim 1 , wherein the payload transmitting comprises the first authentication client specifying the second authentication client and the computer server directing the payload to the specified second authentication client.
8 . The method according to claim 1 , wherein the payload transmitting comprises the computer server identifying the second authentication client after receipt of the authentication token, and the computer server directing the payload to the identified second authentication client.
9 . The method according to claim 1 , wherein the payload transmitting comprises the computer server transmitting a session token to the first authentication client, receiving a payload request from the second authentication client, and transmitting the payload to the second authentication client in accordance with a correlation between the payload request and the session token.
10 . The method according to claim 9 , wherein the payload transmitting further comprises the computer server establishing a secure communications channel with the second authentication client in accordance with the correlation, and transmitting the payload to the second authentication client over the secure communications channel, the second communications channel comprising the secure communications channel.
11 . The method according to claim 1 , wherein the payload comprises an authentication payload for facilitating authentication of the second authentication client.
12 . The method according to claim 11 , wherein the authentication payload comprises a session certificate.
13 . The method according to claim 1 , wherein the payload comprises a command for execution by the second authentication client.
14 . The method according to claim 13 , wherein the command comprises a form-fill command.
15 . A computer-readable medium comprising computer processing instructions stored thereon for execution by a computer, the computer processing instructions, when executed by the computer, causing the computer to perform the method of claim 1 .
16 . A computer server comprising: an authentication client configured to determine an authenticity of an authentication token received at the computer server via a first communications channel, and to transmit a payload to a second authentication client via a second communications channel distinct from the first communications channel in accordance with an outcome of the authenticity determination.
17 . The computer server according to claim 16 , wherein the first authentication client is provided in a communication device, the authentication token is provided in a hardware token distinct from the communication device, and the authentication client receives the authentication token from the first authentication client.
18 . The computer server according to claim 16 , wherein the first authentication client and the authentication token are provided in a common communication device, and the authentication client receives the authentication token from the communication device.
19 . The computer server according to claim 16 , wherein the authentication token is provided in a credential server, and the authentication client receives the authentication token from the credential server.
20 . The computer server according to claim 16 , wherein the first authentication client specifies the second authentication client, and the authentication client is configured to direct the payload to the specified second authentication client.
21 . The computer server according to claim 16 , wherein the authentication client is configured to identify the second authentication client after receipt of the authentication token, and to direct the payload to the identified second authentication client.
22 . The computer server according to claim 16 , wherein the authentication client is configured to transmit a session token to the first authentication client, receive a payload request from the second authentication client, and transmit the payload to the second authentication client in accordance with a correlation between the payload request and the session token.
23 . The computer server according to claim 22 , wherein the authentication client is configured to establish a secure communications channel with the second authentication client in accordance with the correlation, and transmit the payload to the second authentication client over the secure communications channel, the second communications channel comprising the secure communications channel.
24 . A method of authenticating to a computer server comprising: a first authentication client transmitting an authentication token to the computer server via a first communications channel; and a second authentication client receiving a payload from the computer server via a second communications channel distinct from the first communications channel in accordance with an outcome of a determination of authenticity of the authentication token by the computer server.
25 . The method according to claim 24 , wherein the authentication clients are implemented in a common communication device.
26 . The method according to claim 24 , wherein the authentication clients are implemented in separate communication devices.
27 . The method according to claim 24 , wherein the first authentication client is provided in a communication device, the authentication token is provided in a hardware token distinct from the communication device, and the authentication token transmitting comprises the first authentication client requesting the authentication token from the hardware token and transmitting the requested authentication token to the computer server.
28 . The method according to claim 24 , wherein the first authentication client and the authentication token are provided in a common communication device, and the authentication token transmitting comprises the communication device releasing the authentication token to computer server.
29 . The method according to claim 24 , wherein the authentication token is provided in a credential server, and the authentication token transmitting comprises the first authentication client authorizing the credential server to transmit the authentication token to the computer server.
30 . The method according to claim 24 , wherein the payload receiving comprises the first authentication client identifying the second authentication client to the computer server and the computer server directing the payload to the identified second authentication client.
31 . The method according to claim 24 , wherein the second authentication client uses the payload to effect a completion of a transaction with a relying party server distinct from the computer server, the authentication token transmitting comprises a first segment of the transaction, and the payload receiving comprises a second segment of the transaction.
32 . The method according to claim 24 , wherein the payload receiving comprises the first authentication client receiving a session token from the computer server, and the second authentication client transmitting a payload request to the computer server and receiving the payload from the computer server in accordance with a correlation between the payload request and the session token.
33 . The method according to claim 32 , wherein the payload receiving further comprises the second authentication client establishing a secure communications channel with the computer server in accordance with the correlation, and receiving the payload over the secure communications channel, the second communications channel comprising the secure communications channel.
34 . The method according to claim 24 , wherein the payload comprises an authentication payload, and the second authentication client authenticates itself using the authentication payload.
35 . The method according to claim 34 , wherein the authentication payload comprises a session certificate.
36 . The method according to claim 24 , wherein the payload comprises a command, and the second authentication client executes the received command.
37 . The method according to claim 36 , wherein the command comprises a form-fill command.
38 . A communication device comprising: a first authentication client configured to transmit an authentication token to a computer server via a first communications channel; and a second authentication client configured to receive a payload from the computer server via a second communications channel distinct from the first communications channel in accordance with an outcome of a determination of authenticity of the authentication token by the computer server.Join the waitlist — get patent alerts
Track US2014157393A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.