Session Identifier Token for Secure Authentication Using a Personal Identification Device
Abstract
Methods and a unique session identifier token are disclosed for using in-band and optionally out-of-band protocols to authenticate a session are disclosed. The system to produce a probability the mobile device is in possession of a known person and the use of the unique session identifier token are used to prevent attacks by replay. In some embodiments, out-of-band protocols as well as use of entangled pairs eliminate the possibility of man-in-the middle pirating of an authentication session. A unique user-initiated session reduces authentication to a single message unit transaction from a mobile device to a relying party, securely affirming the user's identity and the user's intent to authenticate.
Claims
exact text as granted — not AI-modified1 . A unique session identifier token to be employed as part of an authentication session to uniquely identify the authentication session from other authentication sessions, the unique session identifier token comprising:
a unique identifier object having a time component and a unique data object; and whereas the time component represents a time of creation of the unique session identifier token.
2 . The unique session identifier token of claim 1 , wherein the unique data object comprises an item selected from a group consisting of a string value and a numeric value.
3 . The unique session identifier token of claim 2 , wherein the numeric value comprises a complex number.
4 . The unique session identifier token of claim 3 , wherein the complex number is created by observing a first particle of an entangled pair at an instant in time.
5 . The unique session identifier token of claim 2 , wherein the string value is produced by a one-time passcode generation algorithm that employs a time-based or hash-based secret key.
6 . A method for verifying an integrity of a bidirectional authentication session, the bidirectional authentication session being initiated by a relying party over a conventional in-band network using a unique session identifier token, the unique session identifier token comprising a unique identifier object having a time component and a unique data object, the method comprising:
the relying party creating a challenge message having the unique session identifier token, the relying party setting the unique identifier object to a unique value and the relying party setting the time component based upon a current time-of-day; the relying party transmitting the challenge message over the conventional in-band network to a subscribing party; upon receiving the challenge message by the subscribing party, the subscribing party creating a challenge message response, the challenge message response including the unique session identifier token and the subscribing party transmitting the challenge message response over the conventional in-band network to the relying party; and the relying party comparing the unique session identifier token of the challenge message to the unique session identifier token of the challenge message response, thereby determining the integrity of the bidirectional authentication session.
7 . The method for verifying the integrity of the bidirectional authentication session of claim 6 , wherein the unique data object is a string and in the step of the relying party setting the unique identifier object, the relying party generating a one-time passcode, the relying party setting the unique data object to the one-time passcode.
8 . The method verifying the integrity of the bidirectional authentication session of claim 7 , wherein the step of the relying party generating the one-time passcode using a time-based or hash-based secret key.
9 . The method for verifying the integrity of the bidirectional authentication session of claim 6 , wherein the unique data object is a numeric value.
10 . The method for verifying the integrity of the bidirectional authentication session of claim 9 , wherein the numeric value comprises a complex number.
11 . The method for verifying the integrity of the bidirectional authentication session of claim 10 , wherein in the step of the relying party setting the unique identifier object comprises:
the relying party generating the complex number by observing a first particle of an entangled particle pair at an instant in time; the first particle of the entangled particle pair changing a second particle of the entangled particle pair over an out-of-band network; and the subscribing party generating a second complex number by observing the second particle of the entangled particle pair.
12 . A method for verifying an integrity of a bidirectional authentication session, the bidirectional authentication session being initiated by a relying party over an out-of-band network using a unique session identifier token, the unique session identifier token comprising a unique identifier object having a time component and a unique data object, the method comprising:
the relying party creating a challenge message having the unique session identifier token, the relying party setting the unique identifier object to a unique value and the relying party setting the time component based upon a current time-of-day; the relying party transmitting the challenge message over the out-of-band network to a subscribing party; upon receiving the challenge message, the subscribing party creates a challenge message response, the challenge message response including the unique session identifier token and the subscribing party transmitting the challenge message response over a conventional in-band network to the relying party; and upon receiving the challenge message response from the conventional in-band network, the relying party comparing the unique session identifier token of the challenge message to the unique session identifier token of the challenge message response, thereby determining the integrity of the bidirectional authentication session.
13 . The method for verifying the integrity of the bidirectional authentication session of claim 12 , wherein the unique data object is a string and in the step of the relying party setting the unique identifier object, the relying party generating a one-time passcode, the relying party setting the unique data object to the one-time passcode.
14 . The method for verifying the integrity of the bidirectional authentication session of claim 13 , wherein the step of the relying party generating the one-time passcode using a time-based or hash-based secret key.
15 . The method for verifying the integrity of the bidirectional authentication session of claim 13 , wherein the unique data object is a numeric value.
16 . The method for verifying the integrity of the bidirectional authentication session of claim 15 , wherein the numeric value comprises a complex number.
17 . The method for verifying the integrity of the bidirectional authentication session of claim 16 , wherein in the step of the relying party setting the unique identifier object comprising:
the relying party generating the complex number by observing a first particle of an entangled pair at an instant in time; observing the first particle producing over the out-of-band network an observation event of a second particle of entangled particle pair; and the subscribing party generating a second complex number by observing the second particle of the entangled particle pair.Join the waitlist — get patent alerts
Track US2021352471A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.