EP2425583B1

Out of ban system and method for authentication

Abstract

This record has no abstract on file.

EP2425583B1, drawing sheet 1
Sheet 1 of 3

Term

3.6 yearsleft in the term

Expires 30 April 2030.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

8 claims: 1 independent, 7 dependent

  1. 1
    A method for an out of band authentication of a user with a device (150, 160, 200, 150') who is attempting a first transaction over an authentication server (131, 131') via a network server (130, 130') comprising the steps of:i) establishing the asserted identity (10) of the user;ii) sending (40) an out of band one-time passcode (180) to the device registered to the user;iii) entering (50) the one-time passcode into an authentication server dialogue characterised by further comprising the step of: iv) informing (20) the authentication server (131) that the user is attempting to conduct a transaction and prompting the user to enter the token (170);v) conducting (30) a second transaction with the user's device and the authentication server to verify that the user is in possession of the device, wherein the second transaction comprises providing an out of band authentication notification message (140) via a short message service (SMS) or a channel to the device indicating that the transaction is being conducted and prompting entry of a personal knowledge token (170), whereby the token (170) is returned to the authentication server as a response using the same channel from which the prompt to enter the token was received, wherein sending the out of band one-time passcode is in response to the authentication server receiving the personal knowledge token;vi) validating (60) the one-time passcode by the authentication server (130);and;vii) authorizing (90) the transaction by the release of a symmetric or asymmetric key to the network server;wherein the symmetric or asymmetric key is representative of the network server on which the authentication transaction was conducted, and can be tied to the unique user through non-repudiatory log and audit capabilities.
  2. 2
    The method of Claim 1, wherein the symmetric or asymmetric key is released by a key server.
  3. 3
    The method of Claim 1 or 1, wherein the key is released to an application server (133, 133').
  4. 4
    The method of any of the Claims 1 to 4, wherein the release of the symmetric or asymmetric key is representative of an individual conducting the authentication transaction.
  5. 6
    The method of any of the Claims 1 to 5, wherein conducting the second transaction further comprises the device sending a secure message to the Authentication Server and Key Server (131) confirming that the user is in possession of the device.