EP1551149B1

Universal secure messaging for remote security tokens

Abstract

This record has no abstract on file.

EP1551149B1, drawing sheet 1
Sheet 1 of 12

Term

Term ended

Expired 22 December 2024, 1.8 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

45 claims: 3 independent, 42 dependent

  1. 1
    A method for establishing a secure end-to-end communications connection between a security token enabled computer system (105) and a security token (75) associated with a wireless intelligent remote device (110) comprising the steps of:a. performing a first security transaction which authenticates said security token (75) to said security token enabled computer system (105), b. establishing a secure communications connection between said security token (75) and said security token enabled computer system (105) which incorporates a shared symmetric key set (285t, 285s) generated during said first security transaction, c. assigning at least one key (285t) from said shared symmetric key set (285t, 285s) to a dedicated communications channel (220w) between the security token enabled computer system (105) and the security token (75), accessible to said security token (751) and d. setting at least a first security state indicating that the secure dedicated communications channel (220) has been established, e. performing a second security transaction, following said first security transaction, which authenticates a user to said security token (75) by providing a critical security parameter (235) to said security token via said intelligent remote device (110), f. transmitting an affirmative result signal from the security token (75) to the security token enabled computer system (105) via the secure end-to-end communications connection if the user is authenticated and setting at least a second security state indicating that the user is authenticated by the security token (75), and g. enabling the use of said secure communications connection following the setting of said at least a second security state.
  2. 11
    A method recording to claim 1, further comprising the step of establishing a wireless communications connection between said intelligent remote device (110) and said security token enabled computer system (105).
  3. 20
    A system for establishing a secure end-to-end communications connection between a security token enabled computer system (105) and a security token (75) associated with a wireless intelligent remote device (110) comprising; said security token enabled computer system (105) including:a first security transaction, means for at least authenticating said security token (75) to said security token enabled computer System (105): a first secure communications connection means for at least establishing a secure communications connection between said security token enabled computer system (105) and said security token (75);wherein said intelligent remote device (110) includes;a security token interface (70r) means for at least operatively coupling said security token (75) to said intelligent remote device (110): a user interface (85r) means for at least receiving and routing a critical security parameter (235) provided by said user to said security token interface (70r) means: said security token (75) incudes: a second secure communications connection means for at least establishing said secure communications connection in conjunction with said first secure communications connection means;a dedicated communications channel (220w) means for preventing a concurrent secure communications connection from being established with said security token (75);and a second security transaction means for at least authenticating said user to said security token (75), after said first security transaction, using at least said critical security parameter (235);in that the system comprises means for activating said user interface means (85r) for receiving and routing said critical security parameter (235), once said first secure communications connection means have established said secure communications connection;and in that the system comprises means for transmitting an affirmative result signal from the security token (75) to the security token enabled compute system (105) via the secure end-to-end communications connection if the user is authenticated.