US2014215596A1PendingUtilityA1

Method for personalizing an authentication token

Assignee: PRISM TECHNOLOGIES LLCPriority: May 10, 2002Filed: Mar 28, 2014Published: Jul 31, 2014
Est. expiryMay 10, 2022(expired)· nominal 20-yr term from priority
G06Q 20/341G06F 21/34G06Q 20/385H04L 9/0863G06F 21/46G07F 7/1008G06Q 20/40975H04L 9/0869
67
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An authentication token using a smart card that an organisation would issue to its customer, the smart card having a processor for executing a software application that is responsive to a user input to generate a one-time password as an output. The smart card co-operates with an interface device for inputting the user input and displaying the one-time password. The authentication token may be used in combination with a remote authentication server for validation of the password and hence authentication of the user.

Claims

exact text as granted — not AI-modified
I claim: 
     
         1 . A method for personalizing an authentication token responsive to a user input from an authentication token interface device to generate a secure password comprising:
 requesting from the authentication token, by a personalization device in communication with the authentication token, a serial number of the authentication token;   establishing an encrypted session between the authentication token and the personalization device upon receipt of the serial number;   sending, by the personalization device to the authentication token, an initial seed value and an initial secret key responsive to authentication of the serial number;   storing, by the personalization device, the initial seed value and the initial secret key; and,   transferring, by the personalization device to the authentication token, the initial seed value and the initial secret key used by the authentication token to generate the secure password.

Join the waitlist — get patent alerts

Track US2014215596A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.