Nova Patents
EP3437293B1

Securing remote authentication

Abstract

This record has no abstract on file.

EP3437293B1, drawing sheet 1
Sheet 1 of 10

Term

10.5 yearsleft in the term

Expires 23 March 2037.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

8 claims: 2 independent, 6 dependent

  1. 1
    A system comprising a first user entity (104), an identity provider (110) and a second user entity (116), each of the identity provider (110), first user entity (104) and second user entity (116) comprising respective one or more processors, and one or more computer-readable media having stored thereon instructions that when executed by the respective one or more processors, cause the respective one or more processors to authenticate a secure session between a first user entity (104) and an identity provider (110) using a second user entity (116), including instructions causing the respective one or more processors to perform at least the following:receiving (902), by the identity provider, a request for a session from an entity that purports to be the first user entity;sending (904), from the identity provider to the entity, authentication context (114) for the request;sending, by the entity, the authentication context to the second user entity;verifying, at the second user entity, that the authentication context sent by the entity corresponds to the first user entity;once the authentication context has been verified at the second user entity, signing, by the second user entity, the authentication context and passing, by the second user entity, the signed authentication context to the entity;passing, by the entity, the signed authentication context to the identity provider;verifying, by the identity provider, that the authentication context sent by the identity provider matches the signed authentication context;and as a result, authenticating (908) a secure session between the entity and the identity provider or approving a secure transaction, wherein authenticating or approving comprises sending a token from the identity provider to the entity.
  2. 4
    A method for use in a computing system for authenticating a secure session between a first user entity (104) and an identity provider (110) using a second user entity (116), the method comprising:receiving (902), by the identity provider, a request for a session from an entity that purports to be the first user entity;sending (904), from the identity provider to the entity, authentication context (114) for the request;sending, by the entity, the authentication context to the second user entity;verifying, at the second user entity, that the authentication context sent by the entity corresponds to the first user entity;once the authentication context has been verified at the second user entity, signing, by the second user entity, the authentication context and passing, by the second user entity, the signed authentication context to the entity;passing, by the entity, the signed authentication context to the identity provider;verifying, by the identity provider, that the authentication context sent by the identity provider matches the signed authentication context;and as a result, authenticating (908) a secure session between the entity and the identity provider or approving a secure transaction, wherein authenticating or approving comprises sending a token from the identity provider to the entity.