CA2383000C

Solicited authentication of a specific user

Abstract

Secure web-based messaging according to a "push" paradigm is augmented by specific, intended recipient authentication. In particular, a document can be sent to a specified, intended recipient through the Web using e-mail recipient notification, and the recipient is authenticated prior to delivering the document to the recipient. Such authentication prevents a cracker from snooping a delivery notification e-mail message and retrieving the document prior to retrieval by the true intended recipient. In addition, such authentication of the recipient is driven by the sender such that prior participation by the recipient in the messaging system according to the present invention is not required.

CA2383000C, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Expired 16 August 2020, 6.1 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

17 claims: 5 independent, 12 dependent

  1. 1
    CA 02383000 2009-09-23 - 13 The embodiments of the invention in which an exclusive property or privilege is claimed are defined as follows:1. A method of securely directing private information from a sender to a recipient via a messaging system, the method comprising: transmitting a first message to the recipient, the first message including a recipient-specific resource locator;responsive to a retrieval using the recipient-specific resource locator, authenticating an identity of the recipient and thereafter, without involvement of the sender, supplying the private information to the recipient;and prior to the transmitting of the first message, receiving from the sender at least one criterion to be used for the authenticating the identity of the recipient, wherein the received at least one criterion identifies a type of authentication information for verification against a third-party information service, but does not specify particular information with which the identity of the recipient is to be authenticated, and wherein the authenticating includes verifying information received from the recipient using the third-party information service.
  2. 9
    A computer program product, comprising:a memory having computer readable code embodied therein, for execution by a CPU, in a secure messaging system for securely directing private information from a sender to a recipient said code comprising: code means for transmitting a first message to the recipient not previously enrolled in the secure messaging system, wherein the first message includes a recipient-specific resource locator;code means for servicing a session initiated by the recipient using the recipient-specific resource locator and authenticating an identity of the recipient;and CA 02383000 2009-09-23 - 15code means for supplying the private information after successful authentication of the recipient, without involvement of a sender thereof;and code means for, prior to the transmitting of the first message, receiving from the sender at least one criterion to be used for the authenticating the identity of the recipient, wherein the received at least one criterion identifies a type of authentication information for verification against a third-party information service, but does not specify particular information with which the identity of the recipient is to be authenticated, and wherein the authenticating includes verifying information received from the recipient using the third-party information service.
  3. 12
    A method for authenticating a first user for a data transaction between the first user and a second user using a messaging system wherein the second user has identified the first user, the method comprising:receiving from the second user, at least one criterion for authenticating an identity of the first user, wherein the received criterion identifies a type of authentication information for verification against a third-party information service but does not specify particular information with which the identity of the first user is to be authenticated;responsive to identification of the first user by the second user and prior to creation of an account for the first user, sending a first message to the first user;in a session with the first user in response to the first message, receiving user account information from the first user;sending a second message to the first user wherein the second message informs the first user regarding creation of a user account in accordance with the received user account information;and CA 02383000 2009-09-23 - 16authenticating the identity of the first user based at least in part on the received user account information and thereafter initiating the data transaction, wherein the authenticating includes verifying information received from the first user using the third-party information service.
  4. 15
    A method of securely conveying private information from a sender to a recipient using a push-oriented messaging system, the method comprising:receiving from the sender both the private information and at least one criterion for use in authenticating an identity of the recipient if the recipient has not previously been enrolled in the messaging system;transmitting a first message to the recipient, the first message including a recipient-specific resource locator;and in a session initiated by the recipient using the recipient-specific resource locator, authenticating the identity of the recipient and thereafter supplying the private information to the recipient without further involvement of the sender, wherein the received at least one criterion identifies a type of authentication information for verification against a third-party information service, but does not specify particular information with which the identity of the recipient is to be authenticated, and wherein the authenticating includes verifying information received from the recipient using the third-party information service. CA 02383000 2009-09-23
  5. 17
    A system comprising :at least one processor;memory operatively coupled to the processor;and a delivery server for use in securely directing private information to recipients, including a recipient not previously enrolled therewith, the delivery server embodied as instructions instantiated in the memory and executable on the processor to receive from a sender both the private information for delivery to the recipient and at least one criterion for authenticating an identity of the recipient, to transmit a first message to the recipient, wherein the first message includes a recipient-specific resource locator, to service a session initiated by the recipient using the recipient-specific resource locator and to authenticate the identity of the recipient based on the criterion received from the sender, wherein the received at least one criterion identifies a type of authentication information for verification against a third-party information service, but does not specify particular information with which the identity of the recipient is to be authenticated, and wherein the authenticating includes verifying information received from the recipient using the third-party information service.