Web site authentication
Abstract
This record has no abstract on file.
Term
1.1 yearsto projected expiry
Projected expiry 5 November 2027, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
15 claims: 6 independent, 9 dependent
- 1Patent claims Zastrzeżenia patentowe 1. A method of authenticating a website (301) to a user (302), including:1. Sposób uwierzytelniania witryny WWW (301) użytkownikowi (302), obejmujący: odbiór w serwerze uwierzytelniania (304) strony trzeciej żądania z komputera użytkownika, przy czym żądanie jest oparte na URL zawartym na stronie wysłanej z serwera sieci WWW d o komputera użytkownika (302), przy czym URL wskazuje serwer uwierzytelniania i zawiera podpis cyfrowy utworzony z wykorzystaniem klucza kryptograficznego serwera sieci WWW (301);odbiór identyfikatora użytkownika z komputera użytkownika;receiving a request from a third party authentication server (304) from a user's computer, the request being based on a URL contained on the page sent from the web server to the user's computer (302), wherein the URL pointing to the authentication server and containing a digital signature created using the key cryptographic web server (301);receiving the user identifier from the user's computer;digital signature authentication;uwierzytelnienie podpisu cyfrowego;if the digital signature has been successfully authenticated, then a copy of the authentication device has been sent to the user's computer (302), the authentication device being a "shared secret" between the user and the authentication server. jeśli podpis cyfrowy został pomyślnie uwierzytelniony, wówczas wysłanie kopii urządzenia uwierzytelniającego do komputera użytkownika (302), przy czym urządzenie uwierzytelniające stanowi „sekret dzielony" między użytkownikiem i serwerem uwierzytelniania.
- 5The method according to claim Wherein the authenticating device comprises components of the group:text string, audio segment, video segment, and animation segment, graphic segment and distortion pattern, and wherein the authenticating device comprises a digital signature hidden in at least one of said components. 5. Sposób według zastrz. 1, którym urządzenie uwierzytelniające zawiera komponenty z grupy: tekstowego ciągu znaków, segmentu audio, segmentu video, i segmentu animacji, segmentu grafiki i wzoru zniekształcenia, i w którym urządzenie uwierzytelniające zawiera podpis cyfrowy ukryty w przynajmniej jednym ze wspomnianych komponentów.
- 6A system for authenticating a website (301) to a user (302), comprising;6. System do uwierzytelniania witryny WWW (301) użytkownikowi (302), zawierający;procesor (305);processor (305);memory (306) coupled to said processor, said memory storing instructions (307) adapted to be executed by said processor for receiving a URL from a user's computer, the URL containing a digital signature created using a cryptographic key on a web server for authentication signature pamięć (306) sprzężoną ze wspomnianym procesorem, przy czym wspomniana pamięć przechowuje instrukcje (307) przystosowane do wykonywania ich przez wspomniany procesor dia odbioru URL z komputera użytkownika, przy czym URL zawiera podpis cyfrowy utworzony z wykorzystaniem klucza kryptograficznego na serwerze sieci WWW, dla uwierzytelniania podpisu - U _ cyfrowego, i, jeśli podpis został uwierzytelniony, dla wysłania do komputera użytkownika (302) urządzenia uwierzytelniającego opartego na identyfikatorze użytkownika odebranym z komputera użytkownika, przy czym urządzenie uwierzytelniające stanowi „sekret dzielony" między użytkownikiem i systemem (304). U digital, and if the signature has been authenticated, to send to the user's computer (302) an authentication device based on the user ID received from the user's computer, wherein the authenticating device is a "shared secret" between the user and the system (304).
- 7System according to claim Wherein the digital signature is created using a symmetric cryptographic key on a web server (301), said memory stores a copy of the symmetrical cryptographic key and said instructions are adapted to be executed by said processor for authenticating the digital signature using a symmetrical cryptographic key. 7. System według zastrz. 6, w którym podpis cyfrowy jest utworzony z użyciem symetrycznego klucza kryptograficznego na serwerze sieci WWW (301), przy czym wspomniana pamięć przechowuje kopię symetrycznego klucza kryptograficznego i przy czym wspomniane instrukcje są przystosowane do wykonywania ich przez wspomniany procesor dla uwierzytelnienia podpisu cyfrowego z użyciem symetrycznego klucza kryptograficznego.
- 8System according to claim Wherein the digital signature is created using a private cryptographic key on a web server (301), said memory stores a copy of the public puff corresponding to the private one and said instructions are adapted to be executed by said processor for authenticating the digital signature from using the public key. 8. System według zastrz. 6, w którym podpis cyfrowy jest utworzony z użyciem prywatnego klucza kryptograficznego na serwerze sieci WWW (301), przy czym wspomniana pamięć przechowuje kopię kiucza publicznego odpowiadającego kiuczowi prywatnemu i przy czym wspomniane instrukcje są przystosowane do wykonywania ich przez wspomniany procesor dla uwierzytelnienia podpisu cyfrowego z użyciem klucza publicznego.
- 12A medium storing instructions adapted to be executed by a processor for the implementation of stages including:12. Nośnik przechowujący instrukcje przystosowane do wykonywania ich przez procesor dia realizacji etapów obejmujących: odbiór w serwerze uwierzytelniania (304) strony trzeciej żądania z komputera użytkownika, przy czym żądanie jest oparte na URL zawartym na stronie wysłanej z serwera sieci WWW (301) do komputera użytkownika (302), przy czym URL wskazuje serwer uwierzytelniania i zawiera podpis cyfrowy utworzony z wykorzystaniem klucza kryptograficznego serwera sieci WWW;odbiór identyfikatora użytkownika z komputera użytkownika (302);receiving a request from a third party authentication server (304) from a user's computer, the request being based on a URL contained on a page sent from the web server (301) to the user's computer (302), wherein the URL pointing to the authentication server and having a digital signature created using the cryptographic key of the web server;receiving a user identifier from the user computer (302);digital signature authentication;uwierzytelnianie podpisu cyfrowego;if the digital signature has been successfully authenticated, then a copy of the authentication device is sent to the user's computer (302), the authentication device being the "secret of the day" between the user and the authentication server (304). jeśli podpis cyfrowy został pomyślnie uwierzytelniony, wówczas wysłanie kopii urządzenia uwierzytelniającego do komputera użytkownika (302), przy czym urządzenie uwierzytelniające stanowi „sekret dzieiony” między użytkownikiem i serwerem uwierzytelniania (304). - 12 - 12
Independent claims6
83 paragraphs, as filed
Technical field [0001] The field of the invention is authentication, and in particular the authentication of a service provided to users over a network.
Background Art [0002] WO 01/18636 A1 discloses an embodiment in which an icon is provided with an additional level of functionality that allows the user to confirm that the current information (e.g. website) is from the true owner of the icon and is not just a copy of the method contains a user's request for a web page from a web site using a web browser. The web server receives the request, downloads the web page and passes it to the authentication server. The authentication server places the authenticity key on the web page, then the page (along with the authenticity key) is returned to the user. If the page contains an authenticity key, the authenticity is verified on the user's computer because the user's computer contains logic (e.g. software) for authenticity verification. In the configuration process, the user defines the sign of authenticity, which determines the format of the authenticated page.
[0003] A user who wants to use the services provided by a secure website (such as, for example, online banking support) must usually authenticate with the website. This is often done by the public user entering the user's name together with a secret password only known to the user and the bank. If the bank positively verifies the correctness of the password for the corresponding username, then the user can use services such as checking account balances, making payments to third parties, etc.
[0004] A more complex user authentication scheme may require providing the user with a token adapted to generate one-time passwords (OTP), which change with time or events, such as pressing a button on a token. An OTP-based password can be sent to the site along with a secret password (such as a Personal Identification Number) and username. The site verifies the OTP password, username and all other secret passwords before allowing the user to access the site's services.
[0005] The main problem is user authentication. Over the past few years, scammers have become increasingly proficient in providing pages that pretend to be third party websites. Usually, links to these fake pages are distributed via emails that suggest some problem with the user account and ask users for sensitive data such as usernames and passwords to log in to fix the problem. For example, a user may receive an email that appears to be from his bank stating that his statement is ready to view the rope by clicking on the link from the email. When the user clicks on the link, he is redirected to a website that looks like a bank's website, but is in fact operated by a fraudster. The user can enter their username and password, which is then obtained by the scammer. The scammer can sell this information or use it himself to log in to the real bank website as a user and obtain information about funds or money from the user's bank account. This procedure is known as phrshing and is becoming more and more
- and more widespread. There are known cases of its use for auction sites, brokerage house sites, enterprise extranet networks and other types of sites available on the network. Information sought by users of this technique includes usernames, passwords, credit card numbers, bank account numbers, and the like.
[0006] A reliable and robust technique is needed to guarantee the user that the site he is viewing is the real and authentic site of the site he wants to use.
Description of the figures [0007]
Fig. 1 shows an embodiment of a CAPTCHA image according to prior art.
Fig. 2 shows another embodiment of a CAPTCHA image.
Fig. 3 shows a system in accordance with an embodiment of the present invention.
Fig. 4 shows an information flow in accordance with an embodiment of the present invention. Fig. 5 shows a flow chart of registration in accordance with an embodiment of the present invention.
Fig. 6 shows a flowchart of registration in accordance with another embodiment of the present invention.
Fig. 7 shows a flowchart of verification in accordance with an embodiment of the present invention.
Fig. 8 is a flowchart of positioning an artifact in accordance with an embodiment of the present invention.
Description of Embodiments [0008] According to an embodiment of the present invention, a user may register an alphanumeric string of characters that can be selected by the user and an image. One or both string and image - can be created or provided by the user or selected by the user from a predefined set of strings or images presented to the user. The user can also register a sound fragment that can be created or provided by the user or selected by the user from a predetermined set of sound fragments. Such selection or delivery should be made by a secure method, e.g. by SSL or TSL connection. This user information may be stored as attributes of the user profile, e.g. the user's account directory or database. The profile can be maintained by the owner of the site to be authenticated or by a trusted third party that provides site authentication services.
[0009] The information indicated by the user may be used separately, in combination with each other or in combination with other information specified by the website or a third party to obtain an "authentication device", i.e. a discernible entity presented to the user for authenticating the site to the user. The authentication device generally contains a "secret" that can be "shared" by the user and the website and which allows the website to confirm its identity with the user. Because "shared secret" or "secrets" are known only to the legitimate site and
-2 the user, if the user notices such a "secret" when getting a page from the site, he may conclude that the site is legal.
[0010] According to embodiments of the present invention, user selected information may be combined to increase authentication security. For example, the user can select a text string and distortion pattern that can be combined to provide a substantially unique authentication graphic, for use by the user on "secret sharing" and the authentic site. For example, a device can be created that contains the user-selected image / image as the background. Various textual elements carrying additional information can be dynamically imposed on this background. Additional text elements can be generated by the user or they can be selected text strings or information generated by the system. For example, the device may be a picture that contains, for example,
User-selected text string Time stamp (to indicate how new the picture is)
The name of the website (to confirm the identity of the website the user is visiting).
[0011] An example of such an image can be created using the CAPTCHA technique. CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart. It is used to protect servers against overload by machine-generated requests from bots and other vending machines. It presents an automatically generated distorted text string and asks the requesting entity to enter the text correctly using the keyboard into the form field on the page as a condition for processing the request. Automata cannot read the text because it is distorted while a real person can. In this way, machine-generated requests are not processed, while man-generated requests can be processed.
[0012] According to an embodiment of the present invention, the CAPTCHA technique can be used in a new way to help authenticate the site to the user instead of filtering selected types of users (i.e. automata) using the site. Fig. 1 is a CAPTCHA image created by the user who provided the text "NSF" and selected a distortion pattern from a set of distortion patterns to obtain a distorted "NSF" 100 image. Fig. 2 shows another example where the user selected the "PLUS" string from a set of predefined strings and selected a distortion pattern from the set of such patterns to obtain a CAPTCHA 200 image. When a user visits a legitimate website, the site can show the user a user-registered image based on CAPTCHA. The user can recognize the image and be sure that the site is legal. Allowing the user to combine information, such as strings and patterns, increases system security by creating personalized, unique and user-distinguishable images that can be easier for the user to remember.
[0013] The CAPTCHA technique can be applied using user-selected information, distorted by a randomly selected CAPTCHA pattern, which can change each time the user visits the page. This can change the form of this information to help defeat automated attacks on the authentication system. In accordance with embodiments of the present invention, an audio fragment as well as video, animation, graphics, photographs, etc. can be added to the authenticating device. The user can specify which, if any, parts of the content may constitute authentication as well as the order of their appearance. up in time. On
- example, the user can indicate a photo of his dog and after a certain delay (e.g. three seconds after the picture appears) a sound recording of the barking dog can be played. Similarly, a video clip can be played back with synchronized sound. Series of observable events can be presented in the order dictated by the user. This can be indicated by the user through a convenient interface that, transparently for the user, creates a script describing the behavior of the device as a function of time, i.e. what is to be presented, when and how. This script can be sent and played on the user's computer with a positive authentication result. ! ub components can be sent from the authentication server in the correct order and at the right times.
[0014] Information selected by the user may be combined by other methods to increase system security. For example, a set of user-selected graphics can be shown together when the user visits the site. Such an aggregated image may be more unique and therefore more difficult for an attacker to overcome. Aggregated images, however, are more complex and may be more difficult for the user to remember.
[0015] For proper authentication, it is important that the user accurately remembers the information they have registered for the site's authentication. For example, the user, for authenticating the site of his credit card issuer, can choose pictures of cat, zebra and giraffe. If he rarely visits this site, he may remember that he chose animal pictures, but forget which ones. In addition, if a user selects similar images on other websites operated by other credit card issuers, they may be confused which images correspond to which website. In this way, the site authentication scheme may lose its effectiveness.
[0016] According to an embodiment of the present invention, the user may register a single authentication device which may be provided on any number of websites, even if these websites are owned and operated by various entities. This can minimize or eliminate the need for the user to remember several different authentication devices for the authentication of many user sites. This can improve the reliability with which the user recognizes the authentication, and can distinguish the correct device from the incorrect one. It can also reduce the administrative burden on each site due to the need to authenticate users by moving this feature to a third party trusted site authentication site.
[0017] A system in accordance with such an embodiment is shown in Fig. 3. The set of web servers 301 is connected to the set of client computers 301 and with the authentication server 304 through the network 303. The authentication server comprises a processor 305 connected to memory 306 which stores instructions 307 adapted to be performed by a processor 305 to perform at least part of the method, in accordance with an embodiment of the present invention. The 305 processor may be a general purpose microprocessor, such as the Pentium processor manufactured by Intel Corporation of Santa Clara, California. It can also be an ASiC (Application Specific Integrated Circuit) system that executes at least part of the instructions for implementing the method according to the present invention in hardware and / or software. Memory 306 can be any device adapted to store information in a digital form, such as RAM, flash memory, hard disk, CD, etc. The 305 processor can be connected to a 308 database that can store information about user registration, profile, device
- 4 authentication and other relevant information.
[0018] Website 301 may have a built-in URL image that points to a third-party website authentication service running on authentication server 303. Authentication server 303 may provide user 302 with pages for selecting and registering an authentication device. User 302 may interact with the authentication server 303 to create a personalized authentication device for use in authenticating websites 301. This can be done through a secure channel, such as an SSL or TSL connection, and the authentication server 303 may take additional steps for user 302 authentication. [0019] When user 302 visits website 301, the website may contain a link (e.g., a picture link) , pointing to 303 authentication server. The authentication server can authenticate the website and, if authentication is successful, provide a personalized authentication device registered to user 302. Alternatively, when user 302 visits website 301, website 301 may send a request to the authentication server 303 for a personalized user authentication device. If the 303 authentication server successfully authenticates the requesting web server 301, then the 303 authentication server can send a personalized user authentication device to the 301 web server. The web server 301 can then show this device to user 302.
[0020] In an embodiment of the present invention, the website 301 may include on its page a URL to an authentication server 303, wherein the URL includes a cryptographic token. The token may contain, without being limited to:
Temporary variable (nonce) and / or time stamp
Website ID 301 = member_site_id
The result of the hash function for the username, H (username) - uid_m
Digital signature based, for example, on an SSL certificate
An example of such a URL is:
http: // vipseaLverfS! gn.com/Shcwlrnage t <>
ken-MIIEFDCCA32gAwl8AgtQOCcFB3u15 kGCY0iLy0rK / jAN5gkqhkiG9w0BAQQFADC8232
7qZZEyWUWVDr0ukłVJoR + 5LwyNAp8
FPGqdGOakUvOU1T2UGs1 £ g- = [0021] After receiving the request generated when the user selects such a link, the authentication server 303 can verify the cryptographic token by verifying the signature and the time stamp. In one embodiment, the token signature is created using the website's private key. Any suitable public / private key scheme can be used, such as RSA, ECC, etc. When verifying, it can also be checked if a new time stamp is present, and a temporary (nonce) variable has not been used before.
[0022] Once the token has been successfully verified, the authentication server 303 may download and analyze an artifact that will help identify the user, which may be, for example. -5 cookie (cookie) stored on the user's computer 302. Based on the information contained in the artifact, the authentication server 303 can check the user's preferences (e.g. stored in database 308) and generate a website authentication device for the user. The device may include, but is not limited to:
User-selected text string
User selected background image (e.g. distortion pattern, graphics, video, sound, etc.)
Website name (which can be determined from the token)
Digital signature hidden in a picture, sound, video or other part
Executable or in rp retable code, such as a script, which describes how and when parts of the device are to be represented. Time stamp £ 0023] When the user sees the authentication device configured in this way, he can be sure that he is visiting the correct website, not the website "phishingującą." The digital signature can be hidden in the authentication element using steganographic techniques such as those known in the art. For example, a digital signature may be hidden in the background graphics, in the video segment, in the audio segment, etc. In some embodiments, the signature may be hidden in more than one component, e.g. the first part of the signature may be hidden in the graphic component, the second part of the signature can be hidden in the audio segment, the third part of the signature can be hidden in the video segment, etc. A digital signature can be created on the authentication server using the authentication server's private key. The signature can be verified on the user's computer to ensure that the authentication server is the true source of the device.
[0024] According to an embodiment of the present invention, the authentication server may register users and maintain a user preferences database. The primary key of the user preferences registry can be the user ID (uid). The authentication server may also maintain a registry of sites that have received a request from a given user. The authentication server may establish an artifact for the device, which may be a cookie on the user's computer. The artifact may contain information sufficient to identify the user, e.g. it may contain uid.
[0025] If the user results in the deletion of the artifact, the authentication server can recover it, for example by out-of-band authentication. Out-of-band authentication can be challenge-response authentication, phone verification, SMS, etc.
[0026] The authentication server also provides personalized authentication devices. Such devices can be personalized for the user and for the site the user is visiting. They can contain pictures, text, sound, video, animation or any other observable medium, both single and combined.
[0027] Another function of the authentication server may also be the establishment of preshared keys with websites that subscribe to the site authentication service (relying party sites). An SSL certificate can be used for this, especially if the authentication service is provided by a certified provider. This avoids the need to implement additional key management functionality when performing this task. Shared keys can be used to sign tokens. Of course, symmetrical keys can also be used to perform this function.
[0028] The authentication server may make available relevant reports and statistics available to dependent parties.
[0029] The website may use the SDK provided by the authentication service to register and maintain shared keys that the website can use to sign the token. The SDK can also be used by the site to create tokens and embed the URL containing the token on the appropriate pages of websites. The site can also change the way you work at log in to enable the display of the authentication device from the authentication server and monitor relevant reports and statistics from the authentication service.
[0030] The course of one transaction according to an embodiment of the present invention is shown in Fig. 4. The user can register on the authentication server by setting his preferences regarding the authentication device. The authentication server can set a cookie on the user's computer and display the selected device to the user to remember. When a user wants to log in to a website that subscribes to an authentication service, the site can return a login panel that contains a link (such as a URL) that displays the user the authentication device. This link may point to an authentication server and contain a token. When presenting the page, the user's browser may initiate a URL-based request for the authentication server, and artifacts may be sent to the authentication server (such as cookies and other information that is stored on the user's computer). The server can use artifacts (e.g. cookies) to identify the user and determine user preferences. The server can verify the token, e.g. by checking the signature. If the token is positively verified by the authentication server, the server can create an authentication device for the user and send it to the user's computer, where it can be included in the website obtained by the user from the website.
[0031] The course of the registration transaction is shown in Figs. 5 and 6. The registration website can be located either on the authentication server or on the website that subscribes to the authentication service. The user can be redirected to such registration site from the website. The redirect can contain member_sitejd, which can be an identifier that uniquely identifies this particular member site on the authentication server. It may also contain uid_m, which may be the result of a hash function for the user ID H (userid_member). It can be an opaque identifier, which can be derived from some unique user identifier on the member website, e.g. from the username or from the user's internal indicator.
[0032] If a given user has never registered to obtain a personal site mark on any of the participating member sites, then the user may be offered to configure various settings, for example:
by selecting one or more personalized images from the image library, by selecting a personalized text string, by selecting sound preferences [can it actually be the text string itself?], by determining a recovery mechanism, e.g. by providing answers to a set of questions (challenge challenge) or providing a telephone number for telephone or SMS
- 7 out of band authentication.
[0033] For security reasons, the picture library should be large enough. Alternatively, the user may be able to load images, video, sound clips, etc. To ensure a good distribution of selected images, when the user is asked to choose from a set of images, the registration server should use an algorithm that will ensure good distribution (e.g. random selection) of selection 'm' images from the library and then display them to the user so that he can make a selection.
[0034] Once the user selects a preference, a unique user identifier, uid_vtn, can be created. Preferences can be saved under uid_vtn. The service may also maintain a list of all member sites on which the user is "registered", eg by maintaining the mapping of uid_m identifiers for that particular uid_vtn. Hence, all or part of the following information may be saved in the database:
uid_vtn preferences for images preferences for video preferences for text strings preferences for sound device script (s) <uid_m_1, member_sitejd_1>, <uid__m_2, member_site_id_2>, ...
[0035] The device script may be a script describing combining elements in an authentication device. Such an example script stored in the pseudo-code is:
start show (picture_32) wait (3 seconds) play (sound_3456) effect (picture flickering) start (video_427) display (text_string_characters_75489 (pattern_distortion_56782)) end [0036] Markings such as picture_32, sound_3456, mean identifiers of individual parts of the content, e.g. picture and sound. Such parts of the content may be predefined parts selected and arranged by the user, loaded by the user and saved, or a combination thereof.
[0037] An artifact (such as a cookie) may be saved on the user's computer. This artifact may contain encrypted / encoded uid_vtn, which uniquely identifies the user and thus the user's preferences.
[0038] The registration service / server may then redirect the user back to the member web site. A member website may contain a URL displaying a personalized authentication device.
[0039] The course of the transaction displaying the authentication device is shown in Fig. 7. The website may include a URL on its website, for example as below.
http: ZMpseaLverisign.com/Showłmage? to 'ken = MllEFDCCA32gAwiBAglGOCcFł33tJl5 kGCY0iLy0rH / JAN8gkqhkiG9w0BAQQFADCB2327qZ Z Ey WU W VDr Ouk IV J oR + 5Lwy
FPGqdGOakUvOU1T2UGs1Eg = [0040] This URL may contain a cryptographic token. The token may contain a temporary variable (nonce) and / or a timestamp. Website member ID = member_site_id The result of the hash function for the username, H (username) = uid__m
Digital signature, e.g. using an SSL certificate, which can be issued to a website by an authentication service operator.
[0041] Upon receipt of the URL-based request, the authentication server may verify ("authenticate") the cryptographic token by verifying the signature and the time stamp. It can also check that the temporary (nonce) variable has not been used before. If the authentication server cannot successfully authenticate the token, then the user authentication device is not sent to the user's computer. Instead, a warning may be sent saying that the authentication was not successful and that the site may be fake, etc. In one embodiment, the user may select a second authentication device (e.g., a skull with crossbones) that will indicate a failed server authentication result authentication.
[0042] Once the token has been successfully verified, the service can download and analyze an artifact that will help identify the user. This artifact may contain uid_vtn. If for some reason the artifact cannot be found, then, in one of the possible scenarios, the user is not registered. In this case, the website may offer the user to register a personalized authentication device as described above. In another scenario, the user may have been registered but is using a new computer or has deleted the artifact. In this case, the user should go through the recovery process as described below. An example of the re-organization of the verification process is shown in Fig. 7. An example of the implementation of the process that can set a cookie or other artifact on the user's computer is shown in Fig. 8.
[0043] Based on the artifact obtained from the user's computer, the service can find the user's preferences and generate a personalized authentication device that can show the user the following information:
User-selected text string (s) of characters User-selected audio clip (s)
User selected video (one or more)
User-selected animation (s)
User-selected graphic (s)
User selected background image (s)
-9 User-specified script The name of the website (e.g., by token) Time stamp [0044] The above can be combined by the user, which can be registered in the script, which can be as described above. When the user sees the configured authentication device, they can be sure that they are visiting the correct web site, not the "phishing" site.
[0045] The course of the recovery transaction is shown in Fig. 8. The recovery process can be started if the user accesses the member site from another computer or if the user has deleted the artifact. If the user does not see the authentication device on the member website on which it was already registered, then the user identity should be verified before the recovery process is applied. One way to do this is to verify the user's identity by the member website, and then redirect the user to the authentication server with a security token that indicates that the user's identity has been confirmed. The redirection may contain uid_m for the user. Because the server maintains the mapping of the identifiers uid_m and uid__vtn, the server can determine u and d_vtn from this information. Alternatively, the member site may redirect the user to the authentication server (tub of the correct recovery server). The service can then verify the user's identity using information that the user provided during registration. This can help identify uid_vtn.
[0046] When the service has determined a valid uid_vtn, the authentication server may save an artifact on the user's computer, such as a cookie. This artifact may contain encrypted / encoded uid_vtn, which uniquely identifies the user and thus preferences.
[0047] After saving the artifact, the recovery service / server can redirect the user back to the member web site. This time, the member website may contain a URL displaying a personalized authentication device to the user. Now the user should be able to see the personal mark of the site as described above and can be sure that the site is real.
[0048] An embodiment of the present invention may establish a secret symmetric key that is shared between the website and the authentication service. The symmetric key (e.g. one used in an algorithm such as DES, AES, etc.) can be used by the website to sign the token, which is located in the URL sent to the user's computer when the user's browser loads the website's website. The URL that can point to the authentication server may cause the token to be sent from the user's computer to the authentication server, which can use its own copy of the symmetric key to authenticate the digital signature. If the signature is successfully authenticated, then the authentication server can send the authentication device to the user's computer.
[0049] The above-described embodiments of the present invention are provided for illustration and do not limit the scope of the claimed invention.
8 priority claims, no other members on record
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 59303606 | United States of America | A | |
| 59303606 | United States of America | A | |
| 07871366 | European Patent Office (EPO) | A | |
| 2007083624 | United States of America | W | |
| 2007083624 | United States of America | W | |
| EP20070871366 | – | – | – |
| US20060593036 | – | – | – |
| WO2007US83624 | – | – | – |
Numbers
- Publication, DOCDB
- 2087637
- Publication, EPODOC
- PL2087637T
- Application
- 871366
- Application, DOCDB
- 07871366
- Application, EPODOC
- PL20070871366T
Titles2
- English
- WEB SITE AUTHENTICATION
- Polish
- Uwierzytelnianie witryn WWW
Classification
- CPC, 8
- H04L9/3213
- H04L9/3247
- H04L63/126
- H04L63/08
- H04L63/1483
- H04L63/168
- G06F21/645
- G06F2221/2119
- IPC, 3
- H04L9 00
- H04L9 32
- H04L29 06