CA2811703C

A new method for secure user and site authentication

Abstract

The present invention provides a new method of site and user authentication that is achieved by creating a pop-up window on the user's PC that is in communication with a security server, and where this communication channel is separate from the communication between the user's browser and whichever web site they are at. A legitimate web site embeds code in the web page which communicates to the security server from the user's desktop. The security server checks the legitimacy of the web site and then signals both the web page on the user's browser, as well as the pop-up window to which it has a separate channel. If user authentication is requested by the web site the user is first authenticated by the security server for instance by out of band authentication.

CA2811703C, drawing sheet 1
Sheet 1 of 2

Term

4.4 yearsleft in the term

Expires 3 February 2031.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

24 claims: 5 independent, 19 dependent

  1. 1
    What is claimed is:1. A method of authenticating a user on a network, comprising: receiving, by a security server, a request of a network site for authentication of the user;calculating, by the security server in response to the receipt of the authentication request, a one-time-password based on (I) a secret shared by the security server and the network site but not by the user, and the secret is not shared or associated by Hie security server or the network site with the user, and (ii) a one-time-password generating algorithm, wherein the one-time-password is independently calculable by the network site based on the shared secret and the one-time-password generating algorithm: transmitting, by the security server to the network site, a time stamp or counter value associated with the calculated one-time-password;and transmitting, by the security server to the user, the calculated one-time-password to authenticate the user to the network site.
  2. 5
    6. The method of claim 5, further comprising:storing, by the security server on the user network device, a local session object;wherein the received user network device identifier includes the stored local session object;and wherein the received network site identifier includes a network address of the network site presented in the displayed network page,
  3. 7
    8. The method of claim 7, wherein:the first type visual cue is a light;the first state is green;and the second state is red,
  4. 9
    10. An article of manufacture for authenticating a user on a network, comprising:non-transitory processor readable storage medium;and logic stored on the storage medium, wherein the stored logic is configured to be readable by a processor and thereby cause the processor to operate so as to: receive a request of a network site for authentication of the user;io CA 2611703 2017-12-01 calculate in response to the receipt of the authentication request, a one-timepassword based on (i) a secret shared by a security server and the network site but not by the user, and the secret is not shared or associated by the security server or the network site with the user, and (ii) a one-time-password generating algorithm, wherein the one-time-password is independently calculable by the network site based on the shared secret and the one-time-password generating algorithm;transmit, to the network site, a time stamp or counter value associated with the calculated one-time-password;and transmit the calculated one-time-password to authenticate the user to the network site.
  5. 10
    11. The article of manufacture of claim 10, wherein:the user is represented on the network by a user network device executing code embedded in a network page that is (i) associated with the network site and (ii) displayed by the user network device;and the authentication request is received from the user network device in accordance with the execution of the embedded network page code.
  6. 12
    13. The article of manufacture of claim 12, wherein the stored logic is further configured to cause the processor to operate so as to:receive, from the user network device, an identifier of the user network device and an identifier of the network site;and transmit, to the user network device in response to the receipt of the identifiers, an indication of legitimacy of the network site that will cause display of a corresponding legitimacy indicator on both the displayed network page and the displayed window.
  7. 13
    14. The article of manufacture of claim 13, wherein:the stored logic is further configured to cause the processor to operate se as to: CA 2811703 2017-12-01 store, on the user network device, a local session object;and determine the legitimacy of the network site based on the received network site identifier;the received user network device identifier includes the stored local session object;and the received network site identifier includes a network address of the network site included in the displayed network page,
  8. 15
    16. A system for authenticating a user on a network, comprising:a communications port configured to receive a request of a network site for authentication of the user;and a processor configured to calculate, in response to the receipt of the authentication request, a one-time-password based on (i) a secret shared by a security server and the network site, but not by the user, and the secret is not shared or associated by the security server or the network site with the user, and (ii) a one-timepassword generating algorithm and to direct transmission of the calculated one-timepassword and a time stamp or counter value associated with the calculated one-timepassword to authenticate the user to the network site;wherein the one-time-password is independently calculable by the network site based on the shared secret and the one-time-password generating algorithm.
  9. 16
    17. The system of claim 16, wherein:the user is represented on the network by a user network device executing code embedded in a network page that is (i) associated with the network site and (ii) displayed by the user network device;and the authentication request is received from the user network device in accordance with the execution of the embedded network page code. CA 2811703 2017-12-01
  10. 17
    18. The system of ciaim 16, wherein:the user is represented on the network by a user network device displaying a network page associated with the network site;and the calculated one-time-password is transmitted to the user network device for presentation on a window displayed by the user network device and entry by the user onto the displayed network page.
  11. 18
    19. The system of claim 18, wherein:tine communications port is further configured to receive, from the user network device, an identifier of the user network device and an identifier of the network site;and the processor is further configured to direct transmission, to the user network device in response to the receipt of the identifiers, of an indication of legitimacy of the network site that will cause display of a corresponding legitimacy indicator on both the displayed network page and the displayed window.
  12. 19
    20. The system of claim 19, wherein:the processor is further configured to direct storage of a local session object on the user network device, and determine the legitimacy of the network site based on the received network site identifier;the received user network device identifier includes the stored local session object;and the received network site identifier includes a network address of the network site presented in the displayed network page.
  13. 21
    22. A method of authenticating a user on a network, comprising:CA 2811703 2017-12-01 receiving, by a first user agent on a user network device from a network site, a request of the network site for the user to be authenticated;transmitting, by the first user agent to a security server, the network site request;receiving, by a second user agent on the user network device from the security server in response to transmission of the network site request, a one-time-password calculated based on (i) a secret shared by the security server and the network site, but not by the user, and the secret is not shared or associated by the security server or the network site with the user and (ii) a one-time-password generating algorithm;transferring the one-time-password from second user agent to first user agent;and transmitting, by the first user agent to the network site, the one-time-password to authenticate the user to the network site;wherein the one-time-password is independently calculable by the network site based on the shared secret and the one-time-password generating algorithm,
  14. 22
    23. The method of claim 22, further comprising:transmitting, by the first user agent to the network site, a request of the user to access the network site;wherein the network site request is received in response to the transmitted user request.
  15. 24
    25. The method of claim 24, wherein:the network page has embedded code;and the transmission of the network site request by the first user agent to the security server is based on execution of the embedded network page code by the user network device. CA 2811703 2017-12-01