US2016204946A1PendingUtilityA1

Trusted internet identity

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Jan 9, 2008Filed: Mar 22, 2016Published: Jul 14, 2016
Est. expiryJan 9, 2028(~1.5 yrs left)· nominal 20-yr term from priority
G06F 21/6218H04L 9/14H04L 63/06H04L 9/30H04L 9/3247G06F 2221/2107H04L 63/0442H04L 63/101G06F 2221/2141G06F 2221/2129G06F 2221/2111H04L 63/08H04L 63/0853
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A token or other storage device uses Internet identities to set file access attribute rights. Subsequently, requests to access a file can be controlled by confirming the Internet identity of the requestor by either validating the request with a known public key or retrieving the public key from an Internet identity provider. Files may be stored encrypted and may be re-encrypted with the public key associated with Internet identity making the request.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method comprising:
 receiving, by a server computing system through a network, a communication representing a data access request from a client computing device, the communication including authentication information generated based on a first encryption key;   identifying a user associated with the data access request;   identifying, by the server computing system, a second encryption key that is stored in association with the user;   verifying, by the server computing system, the authentication information based on the second encryption key; and   confirming the data access request based on the verification.   
     
     
         2 . The computer-implemented method of  claim 1 , wherein confirming the data access request comprises:
 determining that the user has access rights to a particular file and controlling user access to the particular file based on the determination.   
     
     
         3 . The computer-implemented method of  claim 1 , wherein the authentication information comprises a credential. 
     
     
         4 . The computer-implemented method of  claim 1 , wherein the authentication information is signed with the first encryption key. 
     
     
         5 . The computer-implemented method of  claim 4 , wherein the first encryption key comprises a private key. 
     
     
         6 . The computer-implemented method of  claim 5 , wherein the private key is local to the client computing device. 
     
     
         7 . The computer-implemented method of  claim 5 , wherein the second encryption key comprises a public key that corresponds to the private key. 
     
     
         8 . The computer-implemented method of  claim 7 , wherein verifying the authentication information comprises verifying the signature using the public key. 
     
     
         9 . The computer-implemented method of  claim 6 , wherein the public key is retrieved by the server computing system based on the association. 
     
     
         10 . The computer-implemented method of  claim 9 , wherein the public key is retrieved from a data store based on the request. 
     
     
         11 . The computer-implemented method of  claim 9 , wherein the public key is associated with an Internet identity of the user. 
     
     
         12 . A peripheral computing device comprising:
 a processor;   a communication interface configured to communicate with a host computer;   a memory configured to store a private encryption key; and   at least one module configured to facilitate data access control for a user of the host computer by performing a cryptographic process, using the processor, to authenticate the user with a remote computing system, that is remote to the host computer, wherein the cryptographic process comprises generation of an authentication request that is signed with the private encryption key and includes authentication information indicative of data requested by the user, wherein the signed authentication request is sent to the remote computing system.   
     
     
         13 . The peripheral computing device of  claim 12 , wherein the remote computing system determines whether the user has an access right to the requested data and returns an indication of the determination to the host computer. 
     
     
         14 . The peripheral computing device of  claim 12 , wherein the remote computing system comprises a web server that retrieves a public encryption key corresponding to the private encryption key. 
     
     
         15 . The peripheral computing device of  claim 12 , wherein the communication interface is configured to facilitate a local communicative coupling of the peripheral computing device to the host computer. 
     
     
         16 . The peripheral computing device of  claim 15 , wherein the communication interface comprises a wired interface. 
     
     
         17 . The peripheral computing device of  claim 16 , wherein the communication interface comprises a universal serial bus (USB) interface. 
     
     
         18 . A computing device comprising:
 a processor;   a communication interface configured to communicate with a peripheral device local to the computing device; and   memory storing instructions which, when executed by the processor, configure the computing device to:
 generate a user interface that receives a user request to access data; 
 receive an authentication request from the peripheral device that is signed with a private encryption key and includes authentication information indicative of the user request to access the data; 
 send the signed authentication request to a computing system; and 
 receive a response to the signed authentication request from the computing system, the response being indicative of a verification of the user request to access the data; and 
 generate a user interface that displays the data to the user. 
   
     
     
         19 . The computing device of  claim 18 , wherein the peripheral device comprises a removable token that is removably coupleable to the computing device through the communication interface. 
     
     
         20 . The computing device of  claim 18 , wherein the computing system comprises a remote server that verifies the user request to access the data based on a public encryption key that corresponds to the private encryption key.

Join the waitlist — get patent alerts

Track US2016204946A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.