EP1363424A2

Authentication method and system encrypting a ticket with an symmetric key, said symmetric key being encrypted with an asymmetric key

Abstract

A security authentication method and system. After authenticating a user, an authentication server generates a ticket including information associated to the user. The authentication server encrypts the ticket using a symmetric key shared with an affiliated server. The affiliate server has a private key associated with the public key that the authentication server uses to encrypt the symmetric key. The authentication server uses the private key for creating a signature of the ticket. The affiliate server decrypts the symmetric key with its private key and then decrypts the ticket using the decrypted symmetric key. The affiliate server validates the signature by using the authentication server's public key.

EP1363424A2, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Projected expiry passed 9 April 2023, 3.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

32 claims: 4 independent, 28 dependent

  1. 1
    A method of securing information in a multi-site authentication system, said method comprising:generating an authentication ticket from a first network server, said ticket including information associated with a user of a client computer, said first network server and said client computer being coupled to a data communication network;encrypting content of the ticket, by the first network server, using a shared symmetric key, said shared key being shared by the first network server and a second network server, said second network server also being coupled to the data communication network;encrypting the shared key, by the first network server, using a public key associated with the second network server;and directing the client computer along with the ticket from the first network server to the second network server.
  2. 16
    A system of securing information comprising an authentication server associated with a multi-site user authentication system, said authentication server retrieving login information from a user of a client computer for authenticating the user, said authentication server further generating an authentication ticket after authenticating the user, said ticket including information associated with the user of the client computer, said authentication server having a shared symmetric key for encrypting content of the ticket, said shared key being shared by the authentication server and an affiliate server, said affiliate server having a public key and said authentication server using the public key to encrypt the shared key.
  3. 26
    A method of securing information in a multi-site authentication system, said method comprising:generating an authentication ticket from a first network server, said ticket including information associated with a user of a client computer, said first network server and said client computer being coupled to a data communication network;generating a signature for the ticket using a private key associated with the first network server, said signature including address information for a second network server, said second network server also being coupled to the data communication network;directing the client computer along with the ticket from the first network server to the second network server over a privacy-enhanced protocol;and identifying, by the second network server, its own address information in the signature to validate the signature.
  4. 28
    A security protocol for use in a multi-site authentication system comprising:a shared symmetric key, said shared key being shared by a first network server and a second network server, said first network server encrypting content of an authentication ticket that includes information associated with a user of a client computer using the shared key, said first and second network servers and said client computer being coupled to a data communication network;a public key associated with the second network server, said first network server encrypting the shared key using the public key;and a private key associated with the second network server;said second network server decrypting the encrypted shared key using the private key and decrypting the content of the ticket using the decrypted shared key.