EP2939166A2

Query system and method to determine authentication capabilities

Abstract

This record has no abstract on file.

Term

7.3 yearsto projected expiry

Projected expiry 26 December 2033, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

50 claims: 5 independent, 45 dependent

  1. 1
    Claims of equivalent WO 2014105994 A2 CLAIMS We claim:1 . A method comprising: receiving a policy identifying a set of acceptable authentication capabilities;determining a set of client authentication capabilities;filtering the set of acceptable authentication capabilities based on the determined set of client authentication capabilities to arrive at a filtered set of one or more authentication capabilities for authenticating a user of the client;and using the filtered set of one or more authentication capabilities to authenticate the user over a network.
  2. 9
    A method comprising:detecting N authentication devices on a client, wherein N > 1 ;generating a N cryptographic entities, one for each of the N authentication devices;transmitting a command to the client to register each of the N cryptographic entities into each of the N authentication devices;executing the command on the client and responsively registering each of the N cryptographic entities into each of the respective N authentication devices;and subsequently using at least one of the authentication devices and its associated cryptographic entity for authenticating a user of the client over a network.
  3. 19
    A method comprising:transmitting a random challenge and an indication of a timeout period associated with the random challenge from a server to a client within the context of a network registration or authentication process using authentication devices communicatively coupled to the client;automatically detecting that the random challenge is no longer valid based on the timeout period;and responsively transmitting a request for a new random challenge from the client to a server, wherein transmitting is performed transparently to a user of the client.
  4. 29
    A method comprising:transmitting a query for client information from a server to a client, the client information including information related to authentication devices coupled to the client;analyzing the query to determine an appropriate privacy class to be used for providing client information to the server;providing a subset of client information selected based on the determined privacy class, the subset of client information including the information related to the authentication devices coupled to the client;and using the subset of client information within an authentication framework to provide user authentication services over a network.
  5. 41
    A method comprising:executing an online transaction between a first server and a client;providing transaction details of the online transaction to a second server;generating a signature over the transaction details using a key at the second server;transmitting an authentication request to the client with the signature and the transaction details;authenticating a user on the client to generate authentication data, the authentication data specifying whether the user was successfully authenticated on the client;and transmitting the authentication data, the transaction details, and the signature to the second server;using the transaction details and the key to validate the signature and using the authentication details to authenticate the client at the second server, wherein upon validating the signature and authenticating the client, the second server transmits a confirmation for the transaction to the first server.