Transparent client authentication
Abstract
A system and method for authenticating an application (client) to a server or service. During a registration phase, an application that requests access to a service can receive a service identifier, which it can authenticate. The application can generate and send to the server or service an application-service key that is based upon the authenticated service identifier and a secret application key; a service-application identifier that can be based upon the authenticated service identifier and an application identifier; and a registration nonce, all of which can be stored at the server. During the authentication phase, the client can send to the server the application-service identifier, which the server can use to lookup the stored registration data. The server can send the registration nonce to the client, which can compute a proof of possession of the service-application key and send to the server. The server can compute its own version of this key and compare it to the received key. If they correspond, then the client is authenticated.
Claims
exact text as granted — not AI-modified1 - 33 . (canceled)
34 . A method for registering an application at a client computer to a service at a server for later re-authentication, the method comprising:
sending from the server, to the application at the client, a service identifier; receiving at the server, from the application at the client, an application-service identifier, wherein the application-service identifier is generated at the client based upon the service identifier and an application identifier of the application; receiving at the server, from the application at the client, a registration nonce and an application-service key, wherein the application-service key is based upon the registration nonce, the service identifier, and a secret application key; and storing at the server the registration nonce, the application-service identifier and the application-service key, wherein the application is authenticated by comparing an expected proof of possession of the secret application key determined using the stored application-service identifier and the stored application-service key with a proof of possession of the secret application key received from the client.
35 . The method of claim 34 , wherein the application-service identifier is a message authentication code generated from the application identifier and the service identifier.
36 . The method of claim 34 , wherein the application-service identifier is a message digest.
37 . The method of claim 34 , wherein the application-service key is a message authentication code generated from the service identifier and the secret application key.
38 . The method of claim 34 , wherein the application-service key is a message authentication code generated from the service identifier, the secret application key, and the registration nonce.
39 . The method of claim 34 , wherein an application is a type of application.
40 . The method of claim 34 , wherein an application is a specific instance of an application installed on a particular computer.
41 . The method of claim 34 , wherein an application is a specific instance of a running application.
42 . The method of claim 34 , wherein:
the service identifier is generated at the server and uniquely identifies the service; the application-service identifier uniquely identifies a pairing between the application and the service; and the secret application key is generated at the client for the application.
43 . A system comprising:
at least one memory device storing data and instructions; and at least one processor configured to access the memory device and, by executing the instructions, to perform operations comprising:
generating a service identifier uniquely identifying a service provided by the system;
sending, to an application at a client, the service identifier;
receiving, from the application at the client, an application-service identifier, wherein the application-service identifier is generated at the client based upon the service identifier and an application identifier of the application;
receiving, from the application at the client, a registration nonce and an application-service key, wherein the application-service key is based upon the registration nonce, the service identifier and a secret application key; and
storing the registration nonce, the application-service identifier, and the application-service key;
wherein the server authenticates the application by comparing an expected proof of possession of the secret application key determined using the stored application-service identifier and the stored application-service key to a proof of possession of the secret application key received from the client.
44 . The system of claim 43 , wherein the application-service identifier is a message authentication code generated from the application identifier and the service identifier.
45 . The system of claim 43 , wherein the application-service identifier is a message digest.
46 . The system of claim 43 , wherein the application-service key is a message authentication code generated from the service identifier and the secret application key.
47 . The system of claim 43 , wherein the application-service key is a message authentication code generated from the service identifier, the secret application key, and the registration nonce.
48 . The system of claim 43 , wherein an application is a type of application.
49 . The system of claim 43 , wherein an application is a specific instance of an application installed on a particular computer.
50 . A computing device comprising:
a processor; a memory device storing program instructions; and wherein the processor is configured to access the memory device and execute the program instructions to control the computing device to perform operations comprising:
providing a plurality of services to a plurality of client computers, each of the plurality of services being associated with respective one of a plurality of unique service identifiers;
sending, to an application at a first client computer the plurality of client computers, a first service identifier of the plurality of unique service identifiers corresponding to a first service of the plurality of services, the application being respectively associated with a first application identifier of a plurality of application identifiers;
receiving, from the application at the first client, an application-service identifier, wherein the application-service identifier comprises a combination of the first service identifier and the first application identifier;
receiving, from the application at the first client, a registration nonce and an application-service key, wherein the application-service key is based upon the registration nonce, the first service identifier and a secret application key; and
storing the registration nonce, the application-service identifier, and the application-service key;
wherein, after the storing, the server authenticates the application of the first client to access the first service of the plurality of services by determining that an expected proof of possession of the secret application key determined using the stored application-service identifier and the stored application-service key matches a proof of possession of the secret application key received from the first client.Join the waitlist — get patent alerts
Track US2016191486A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.