ES2279871T3

Authentification of a user across communicaqtion sessions

Abstract

A method to facilitate the reauthentication of a user using a client computer, in front of a server computer, comprising the steps of: a) establishing a first communication session between the client computer and the server computer, and generating a password (110) ; b) receive confidential information from the client computer; the method characterized by c) generating an identifier that identifies the first communication session (120) d) encrypting the confidential information with the key, to create the encrypted confidential information (115), and associating the identifier with the encrypted confidential information ( 125); e) store the encrypted confidential information on the server computer; f) transmit the key and the identifier to the client computer (135); and g) delete the key on the server computer (145); h) establish a second communication session after deleting the password on the server computer; i) receive the key associated with the encrypted confidential information and the identifier, from the client computer, during the second communication session; j) use the identifier to locate the encrypted confidential information before using the key to decrypt the encrypted confidential information; and k) use the key on the server computer, to decrypt the encrypted confidential information.

ES2279871T3, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Projected expiry passed 11 June 2022, 4.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

13 claims: 2 independent, 11 dependent

  1. 1
    ES 2 279 871 T3 ES 2 279 871 T3 CLAIMS REIVINDICACIONES 1. A method to facilitate the re-authentication of a user who uses a client computer, in front of a server computer, comprising the steps of:1. Un método para facilitar la reautenticación de un usuario que utiliza un ordenador cliente, frente un ordenador servidor, que comprende las etapas de: a) establecer una primera sesión de comunicación entre el ordenador cliente y el ordenador servidor, y generar una clave (110);a) establishing a first communication session between the client computer and the server computer, and generating a key (110);b) receive confidential information from the client computer;the method being characterized by b) recibir información confidencial desde el ordenador cliente;estando el método caracterizado por c) generar un identificador que identifica la primera sesión de comunicación (120) c) generate an identifier that identifies the first communication session (120) d) cifrar la información confidencial con la clave, para crear la información confidencial cifrada (115), y asociar el identificador con la información confidencial cifrada (125);d) encrypting the confidential information with the key, to create the encrypted confidential information (115), and associating the identifier with the encrypted confidential information (125);e) almacenar la información confidencial cifrada, en el ordenador servidor;e) storing the encrypted confidential information on the server computer;f) transmitir la clave y el identificador al ordenador cliente (135);y f) transmitting the key and identifier to the client computer (135);Y g) deleting the key on the server computer (145);g) suprimir la clave en el ordenador servidor (145);h) establecer una segunda sesión de comunicación después de suprimir la clave en el ordenador servidor;h) establishing a second communication session after deleting the key on the server computer;i) receiving the key associated with the encrypted confidential information and the identifier, from the client computer, during the second communication session;i) recibir la clave asociada con la información confidencial cifrada y el identificador, desde el ordenador cliente, durante la segunda sesión de comunicación;j) use the identifier to locate the encrypted confidential information before using the key to decrypt the encrypted confidential information;Y j) utilizar el identificador para localizar la información confidencial cifrada antes de utilizar la clave para descifrar la información confidencial cifrada;y k) use the key on the server computer to decrypt the encrypted confidential information. k) utilizar la clave en el ordenador servidor, para descifrar la información confidencial cifrada.
  2. 12
    A system to facilitate the re-authentication of a user who uses a client computer, against a server computer, the system comprising:12. Un sistema para facilitar la reautenticación de un usuario que utiliza un ordenador cliente, contra un ordenador servidor, comprendiendo el sistema: a client computer (10) and a server computer (15) comprising a memory (30);the system being characterized in that the server computer comprises an identifier generator (38), a key generator (35), a key destroyer (45), an encryption device (40), and a decryption device (48), the server computer being in electrical communication with the client computer;un ordenador cliente (10) y un ordenador servidor (15) que comprende una memoria (30);estando el sistema caracterizado porque el ordenador servidor comprende un generador de identificador (38), un generador de clave (35), un destructor de clave (45), un dispositivo de cifrado (40), y un dispositivo de descifre (48), estando el ordenador servidor en comunicación eléctrica con el ordenador cliente;donde el ordenador servidor está configurado para recibir información confidencial procedente del ordenador cliente, durante una primera sesión de comunicación entre el ordenador servidor y el ordenador cliente, donde el generador de clave está configurado para generar una clave, donde el generador de identificador está configurado para generar un identificador asociado con la primera sesión de comunicación, donde el dispositivo de cifrado está configurado para cifrar la información confidencial recibida desde el cliente, con la clave, para crear información confidencial cifrada, donde el dispositivo de cifrado está además dispuesto para almacenar la información confidencial cifrada, en la memoria del ordenador servidor, donde el identificador está asociado con la información confidencial cifrada, donde el servidor está configurado para transmitir la clave y el identificador, al cliente, donde el destructor de clave está configurado para destruir la clave después de la transmisión de la clave al ordenador cliente, donde el servidor está configurado para recibir la clave y el identificador durante una segunda sesión de comunicación, y utilizar el identificador recibido para localizar la información confidencial cifrada, antes de utilizar la clave recibida para descifrar la información confidencial cifrada;y donde el dispositivo de descifre está configurado para descifrar la información confidencial cifrada en la memoria, utilizando la clave recibida. where the server computer is configured to receive confidential information from the client computer, during a first communication session between the server computer and the client computer, where the key generator is configured to generate a key, where the identifier generator is configured to generate an identifier associated with the first communication session, where the encryption device is configured to encrypt the confidential information received from the client, with the key, to create encrypted confidential information, where the encryption device is further arranged to store the encrypted confidential information, in the memory of the server computer, where the identifier is associated with the encrypted confidential information, where the server is configured to transmit the key and identifier, to the client, where the key destroyer is configured to destroy the key after transmission of the key to the client computer, where the server is configured to receive the key and identifier during a second communication session, and use the received identifier to locate the information encrypted confidential, before using the received key to decrypt the encrypted confidential information;and where the decryption device is configured to decrypt the confidential information encrypted in memory, using the received key.