US2020084208A1PendingUtilityA1

Network access security system and method

Assignee: KASADA PTY LTDPriority: Dec 24, 2013Filed: Nov 15, 2019Published: Mar 12, 2020
Est. expiryDec 24, 2033(~7.4 yrs left)· nominal 20-yr term from priority
H04L 63/061H04L 63/0861H04L 9/3242G06F 21/36H04L 63/102H04L 63/0442G06F 21/32
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method of providing for access to a computer resource, the method including the steps of: (a) providing an initial registration process including the identification and downloading of a user selected candidate image; (b) creating a first derived identifier from the candidate image; (c) upon a user requesting access to the computer resource, requesting from the user a second candidate image, and deriving a second derived identifier from the second candidate image; and (d) comparing the first and second derived identifier and where they are equivalent, granting the user access to the computer resource.

Claims

exact text as granted — not AI-modified
1 . A method of providing access to a server via a network, the method including:
 a) providing a registration process including identification of a user selected data structure;   b) distributing a one-time use data structure to a user device and the computer resource server;   c) modulating the user selected data structure with the one-time use data structure and applying a cryptographic hashing function to the modulated user selected data structure to derive a first derived identifier and a current modulation key;   d) transmitting the first derived identifier and the current modulation key to the server; and   e) upon a user requesting access to the server, (a) requesting the first derived identifier and the current modulation key, (b) utilizing (i) the one-time use data structure, (ii) the current modulation key, and (iii) a copy of the user selected data structure to derive a second derived identifier, and (c) comparing the first derived identifier and second derived identifier, and, if the first derived identifier matches the second derived identifier, granting access to the server.   
     
     
         2 . The method of  claim 1 , wherein the user selected data structure is broken up into a plurality of parts and each of the plurality of parts is used to derive the first derived identifier. 
     
     
         3 . The method of  claim 1 , wherein the user selected data structure is broken up into a plurality of parts and each of the plurality of parts is used to derive the second derived identifier. 
     
     
         4 . The method of  claim 1 , wherein the user selected data structure is broken up into a plurality of parts and each of the plurality of parts is used to derive the first derived identifier and the second derived identifier. 
     
     
         5 . The method of  claim 1 , wherein the user selected data structure includes an image. 
     
     
         6 . The method of  claim 5 , wherein the image is broken up into a plurality of parts and each of the plurality of parts is used to derive the first derived identifier. 
     
     
         7 . The method of  claim 5 , wherein the image is broken up into a plurality of parts and each of the plurality of parts is used to derive the second derived identifier. 
     
     
         8 . The method of  claim 5 , wherein the image is broken up into a plurality of parts and each of the plurality of parts is used to derive the first derived identifier and the second derived identifier. 
     
     
         9 . The method of  claim 1 , wherein the one-time use data structure includes a one-time password. 
     
     
         10 . The method of  claim 1 , wherein the cryptographic hashing function includes an asymmetric hashing function. 
     
     
         11 . An apparatus for providing access to a server via a network, the apparatus including:
 at least one processor;   a computer system operatively coupled to the at least one processor; and   a network environment operatively coupled to the at least one processor, wherein the at least one processor includes instructions to carry out,   a) providing a registration process including identification of a user selected data structure;   b) distributing a one-time use data structure to a user device and the computer resource server;   c) modulating the user selected data structure with the one-time use data structure and applying a cryptographic hashing function to the modulated user selected data structure to produce a first derived identifier and a current modulation key;   d) transmitting the first derived identifier and the current modulation key to the server; and   e) upon a user requesting access to the server, (a) requesting the first derived identifier and the current modulation key, (b) utilizing (i) the one-time use data structure, (ii) the current modulation key, and (iii) a copy of the user selected data structure to derive a second derived identifier, and (c) comparing the first derived identifier and second derived identifier, and, if the first derived identifier matches the second derived identifier, granting access to the server.   
     
     
         12 . The apparatus of  claim 11 , wherein the user selected data structure is broken up into a plurality of parts and each of the plurality of parts is used to derive the first derived identifier. 
     
     
         13 . The apparatus of  claim 11 , wherein the user selected data structure is broken up into a plurality of parts and each of the plurality of parts is used to derive the second derived identifier. 
     
     
         14 . The apparatus of  claim 11 , wherein the user selected data structure is broken up into a plurality of parts and each of the plurality of parts is used to derive the first derived identifier and the second derived identifier. 
     
     
         15 . The apparatus of  claim 11 , wherein the user selected data structure includes an image. 
     
     
         16 . The apparatus of  claim 15 , wherein the image is broken up into a plurality of parts and each of the plurality of parts is used to derive the first derived identifier. 
     
     
         17 . The apparatus of  claim 15 , wherein the image is broken up into a plurality of parts and each of the plurality of parts is used to derive the second derived identifier. 
     
     
         18 . The apparatus of  claim 15 , wherein the image is broken up into a plurality of parts and each of the plurality of parts is used to derive the first derived identifier and the second derived identifier. 
     
     
         19 . The apparatus of  claim 1 , wherein the one-time use data structure includes a one-time password. 
     
     
         20 . The apparatus of  claim 1 , wherein the cryptographic hashing function includes an asymmetric hashing function.

Join the waitlist — get patent alerts

Track US2020084208A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.