US20020078344A1

System and method for generation and use of asymmetric crypto-keys each having a public portion and multiple private portions

Claim Score by NHIP

Read claim 9, the broadest

Abstract

A system for authentication of network users which is operable in multiple modes, includes a plurality of user network stations and at least one sponsor network station representing a sponsor. Each network station represents a user associated with an asymmetric crypto-key having either a first or second number of private portions, the second number being greater than the first number. The one or more sponsor network stations receive authentication requests from the user network stations, determine the identity of a user associated with each of the received authentication requests, select from two or more available modes of operation based upon the determined identity. If operation in one mode is selected, the sponsor network station signs a particular received authentication request using one private portion of an asymmetric crypto-key having a first number of private portions. However, if another mode is selected, the sponsor network station signs that particular authentication request using one private portion of an asymmetric crypto-key having a second number of private portions.

US20020078344A1, drawing sheet 1
Sheet 1 of 16

Term

Term ended

Projected expiry passed 15 December 2022, 3.8 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

13 claims: 4 independent, 9 dependent

  1. 1
    A system for authentication of network users, the system operable in multiple modes, comprising:a plurality of user network stations, each representing a user, and each associated with an asymmetric crypto-key having one of a first number of private portions and a second number of private portions, the second number of private portions greater than the first number of private portions;at least one sponsor network station representing a sponsor and configured to (i) receive a plurality of authentication requests from the plurality of user network stations, (ii) determine the identity of a user associated with each of the received plurality of authentication requests, (iii) select one of at least a first mode of operation and a second mode of operation based upon the determined identity, and (iv) if operating in the first mode of operation, sign an authentication request using one private portion of an asymmetric crypto-key having a first number of private portions, and if operating in the second mode of operation, sign the authentication request using one private portion of an asymmetric crypto-key having a second number of private portions.
  2. 2
    A system for generating asymmetric crypto-keys associated with network users, operable in multiple modes, comprising:a first processor configured to transmit a request for generation of an asymmetric crypto-key;a second processor representing a sponsor and configured to (i) receive the request for generation of an asymmetric crypto-key, (iii) select one of at least a first operational mode and a second operational mode, (iv) generate a first asymmetric crypto-key having a public portion and a first number of private portions if the second processor selected the first mode of operation, generate a second asymmetric crypto-key having a public portion and a second number of private portions, the second number of private portions greater than the first number of private portions, if the second processor selected the second mode of operation.
  3. 8
    A method of authentication of network users in which each network user is associated with a crypto-key having a public portion and at least one private portion, comprising:receiving an authentication request from a network user;determining the identity of the network user;selecting one of at least a first mode of operation and a second mode of operation based upon the determined identity of the network user;signing the authentication request with one private portion of a first asymmetric crypto-key having a public portion and a first number of private portions if the first mode of operation is selected, and signing the authentication request with one private portion of a second asymmetric crypto-key having a public portion and a second number of private portions if the second mode of operation is selected, the second number greater than the first number.
  4. 9
    Broadest claimClaim Score 59, broad(NHIP)A method for generating an asymmetric crypto-key associated with a network user, comprising:receiving a request for generation of an asymmetric crypto-key;selecting one of at least a first operational mode and a second operational mode;and generating a first asymmetric crypto-key having a public portion and a first number private portions if the first operational mode is selected, and generating a second asymmetric crypto-key having a public portion and a second number of private portions if the second operational mode is selected, the second number of private portions greater than the first number of private portions.