System and method for authentication in a crypto-system utilizing symmetric and asymmetric crypto-keys
Claim Score by NHIP
Abstract
A system and method for authentication of a crypto-system user is provided. A user is authenticated by the use of both symmetric and asymmetric crypto-keys. A user associated with a first asymmetric crypto-key having a public portion and multiple private portions is represented by a first network station. The user transmits a first request for authentication to a second network station. The second network station is associated with a second asymmetric crypto-key having a public portion and at least one private portion. A first one of the multiple private portions of the first crypto-key is stored at the second network station. The second network station generates a shared symmetric crypto-key and encrypts the shared crypto-key with the first private portion of the first crypto-key to form a first message. The second network station signs the first message with a private portion of the second crypto-key and transmits the first message to the first network station. The second network station also encrypts the shared crypto-key with the public portion of a third crypto-key to form a second message. The second network station signs the second message and transmits it to a third network station. The third network station, associated with the third crypto-key, authenticates the second network station, further encrypts the second message with a second private portion of the first crypto-key stored at the third network station, forming a third message. The third network station transmits the third message to the first network station. The first network station authenticates the first network station, combines the first and third messages to form a fourth message, further encrypts the fourth message with another private portion of the first crypto-key, forming a fifth message. The first network station applies the public portion of the first crypto-key to the fifth message to recover the shared crypto-key. The first network station encrypts a second authentication request with the shared crypto-key to form a sixth message, and transmits the sixth message to authenticate the user.

Term
Term ended
Projected expiry passed 3 November 2022, 3.9 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
21 claims: 3 independent, 18 dependent
- 1A system for authentication of network stations utilizing symmetric and asymmetric crypto-keys, each network station being associated with a different asymmetric crypto-key having a public portion and at least one private portion, comprising:a first network station associated with a first asymmetric crypto-key having multiple private portions, configured to transmit a first request for authentication;a second network station associated with a second asymmetric crypto-key, having a first private portion of the first asymmetric crypto-key stored thereat, configured to (i) generate a shared symmetric crypto-key, (ii) encrypt the shared symmetric crypto-key with the first private portion of the first asymmetric crypto-key to form a first message and sign the first message with the private portion of the second asymmetric crypto-key, (iii) transmit the signed first message to the first network station responsive to the transmitted request for authentication, (iv) encrypt the shared symmetric crypto-key with a public portion of a third asymmetric crypto-key to form a second message and sign the second message with a private portion of the second asymmetric crypto-key, and (v) transmit the second message;and a third network station associated with the third asymmetric crypto-key, a second private portion of the first asymmetric crypto-key stored thereat, configured to (i) authenticate the second network station by applying the public portion of the second asymmetric crypto-key to the second message, (ii) recover the shared symmetric crypto-key by applying a private portion of the third asymmetric crypto-key to the second message, (iii) encrypt the recovered shared symmetric crypto-key by applying the second private portion of the first asymmetric crypto-key to the recovered shared symmetric crypto-key to form a third message, and (iv) transmit the third message;wherein the first network station is further configured to (i) authenticate the second network station by applying the public portion of the second asymmetric crypto-key to the first message, (ii) combine the first message and the third message to form a fourth message, (iii) further encrypt the fourth message by applying a third private portion of the first asymmetric crypto-key to the fourth message to form a fifth message, (iv) recover the shared symmetric crypto-key by applying the public portion of the first asymmetric crypto-key to the fifth message, (v) encrypt a second authentication request with the shared symmetric crypto-key to form a sixth message, and (vi) transmit the sixth message to authenticate the first network station.
- 10A system for authentication of network stations utilizing symmetric crypto-keys and asymmetric crypto-keys, comprising:a user network station associated with an asymmetric crypto-key having multiple private portions and a public portion, configured to transmit a request for authentication to any one of a plurality of authentication network stations;and a plurality of authentication network stations, each associated with an asymmetric crypto-key including a public portion and a private portion and each having a different private portion of the multiple private portions of the asymmetric crypto-key stored thereat, each configured to (i) generate a challenge, (ii) encrypt the challenge with that portion of the multiple private portion asymmetric crypto-key stored thereat, sign the encrypted challenge with the private portion of the asymmetric crypto-key associated with that authentication network station and transmit the signed and encrypted challenge to the user network station in response to the request for authentication from the user network station, (iii) encrypt the challenge with the public portion of the asymmetric crypto-key associated with each of the other of the plurality of authentication network stations, sign each encrypted challenge with the private portion of the asymmetric crypto-key associated with that authentication network station, and transmit each signed and encrypted challenge to the respective others of the plurality of authentication network stations associated with the public portion of the asymmetric crypto-key used to encrypt each respective challenge, and (iv) receive a signed and encrypted challenge from each of the other of the plurality of authentication network stations and verify the signature of each received challenge;wherein the user network station is further configured to (i) verify each of a plurality of signed and encrypted challenges, (ii) combine the plurality of signed and encrypted challenges to form a single encrypted challenge, (iii) further encrypt the single encrypted challenge with yet another private portion of the multiple private portion asymmetric crypto-key, (iv) decrypt the further encrypted single encrypted challenge with the public portion of the multiple private portion asymmetric crypto-key, and (v) encrypt a second authentication request with the decrypted challenge and transmit the encrypted second authentication request to at least one of the plurality of authentication network stations to authenticate the user network station.
- 14Broadest claimClaim Score 21, narrow(NHIP)A method for authentication of network users in a cryptosystem in which each network user is associated with a crypto-key having a public portion and at least one private portion, comprising:receiving a first request for authentication from a first network user by a second network user;generating a shared symmetric crypto-key;encrypting the shared symmetric crypto-key with a first private portion of a first crypto-key to form a first message, the first asymmetric crypto-key associated with the first network user, the first asymmetric crypto-key having multiple private portions and a public portion;signing the first message with a private portion of a second asymmetric crypto-key associated with the second network user;transmitting the signed first message to the first network user responsive to the request for authentication;encrypting the shared symmetric crypto-key with a public portion of a third asymmetric crypto-key associated with a third network user to form a second message;signing the second message with the private portion of the second asymmetric crypto-key;transmitting the signed second message to the third network user;authenticating the second network user by applying the public portion of the second asymmetric crypto-key to the signed second message;recovering the shared symmetric crypto-key by applying a private portion of the third asymmetric crypto-key to the second message;encrypting the recovered shared symmetric crypto-key by applying a second private portion of the first asymmetric crypto-key to the recovered shared symmetric crypto-key to form a third message;transmitting the third message to the first network station;authenticating the first network user by applying the public portion of the first asymmetric crypto-key to the signed first message;combining the first message and the third message to form a fourth message;further encrypting the fourth message by applying a third private portion of the first asymmetric crypto-key to the fourth message to form a fifth message;recovering the shared symmetric crypto-key by applying the public portion of the first asymmetric crypto-key to the fifth message;encrypting a second authentication request with the shared symmetric crypto-key to form a sixth message;and transmitting the sixth message to at least one of the second user station and the third user station.
Independent claims3
138 paragraphs in 6 sections, as filed
TECHNICAL FIELD
[0001] This invention relates to cryptosystems. More particularly, the present invention relates to cryptosystem authentication.
BACKGROUND ART
[0002] Today, computing devices are almost always interconnected via networks. As these networks can be large closed networks, as within a corporation, or truly public networks as the Internet is, the network itself might have hundreds, thousands or even millions of potential users. Consequently it is often required to restrict access to any given computer or service, or a part of a computer or service to a subset of the users on the public or closed network. For instance, a brokerage might have a public website accessible to all, but would like to only give Ms. Alice Smith access to Ms. Alice Smith's brokerage account.
[0003] This is an old problem, tracing its roots to the earliest days of computers, and passwords were among the first techniques used, and to this day remain the most widely used technique for protecting resources on a computer or service.
[0004] In its simplest form, every user has a unique password and the computer has knowledge of the user password. When attempting to log on Alice would enter her userid, say alice, and password, say apple<b>23</b>, the computer would compare the pair, i.e. alice, apple<b>23</b>, with the pair it had stored for Alice, and if there is a match would establish a session and give Alice access.
[0005] This simple scheme suffers from two problems. First, the table containing the passwords is stored on the computer, and represents a single point of compromise. If Eve could somehow steal this table, she would be able to access every user's account. A second problem with this approach is that when Alice enters her password it travels from her terminal to the computer in the clear, and Eve could potentially eavesdrop. For instance the “terminal” could be Alice's PC at home, and the computer could be a server on the Internet, in which case her password travels in the clear on the Internet.
[0006] Various solutions have been proposed and implemented to solve these two issues. For instance, to solve the first problem of storing the password on the computer, the computer could instead store a one way function of the password. E.g. F(apple<b>23</b>)=XD<b>45</b>DTY, and the pair {alice, XD<b>45</b>DTY}. In this example as F( ) is a one way function, computing XD<b>45</b>DTY from apple<b>23</b> is easy, but as it is a “one way function”, the reverse is believed to be difficult or close to impossible. So when Alice logs on and sends the computer {alice, apple<b>23</b>}, the computer can compute F(apple<b>23</b>) and compare the result with XD<b>45</b>DTY. The UNIX operating system was among the first to implement such a system in the late 1970's .
[0007] Before discussing more sophisticated conventional techniques for solving this problem, let us briefly describe symmetric, asymmetric and ‘split private key’ cryptography.
[0008] In symmetric key cryptography, the two parties who want to communicate in private share a common secret key, say K. the sender encrypts messages with K, to generate a cipher, i.e. C=Encrypt (M, K). The receiver decrypts the cipher to retrieve the message, i.e. D=Decrypt(C, K). An attacker who does not know K, and sees C, cannot successfully decrypt the message, if the underlying algorithms are strong. Examples of such systems are DES and RC<b>4</b>. Encryption and decryption with symmetric keys provide a confidentiality, or privacy service.
[0009] Symmetric keys can also be used to provide integrity and authentication of messages in a network. Integrity and authentication means that the receiver knows who sent a message and that the message has not been modified so it is received as it was sent. Integrity and authentication is achieved by attaching a Message Authentication Code (MAC) to a message M. E.g., the sender computes S=MAC(M, K) and attaches S to the message M. When the message M reaches the destination, the receiver also computes S′=MAC(M, K) and compares S′ with the transmitted value S. If S′=S the verification is successful otherwise verification fails and the message should be rejected. Early MACs were based on symmetric encryption algorithms such as DES whereas more recently MACs are constructed from message digest functions, or “hash” functions, such as MD<b>5</b> and SHA-<b>1</b>. The current Internet standard for this purpose is known as hash-based MAC (HMAC).
[0010] By combining confidentiality with integrity and authentication, it is possible to achieve both services with symmetric key cryptography. It is generally accepted that different keys should be used for these two services and different keys should be used in different directions between the same two entities for the same service. Thus if Alice encrypts messages to Bob with a shared key K, Bob should use a different shared key K′ to encrypt messages from Bob to Alice. Likewise Alice should use yet another key K″ for MACs from Alice to Bob and Bob should use K′″ for MACs from Bob to Alice. Since this is well understood by those skilled in the art, we will follow the usual custom of talking about a single shared symmetric key between Alice and Bob, with the understanding that strong security requires the use of four different keys.
[0011] Symmetric key systems have been in use for literally thousands of years, and have always suffered from a major problem—namely how to perform key distribution. How do Bob and Alice agree on K? Asymmetric key cryptography was invented to solve this problem. Here every user is associated with two keys, which are related by special mathematical properties. These properties result in the following functionality: a message encrypted with one of the two keys can then only be decrypted with the other.
[0012] One of these keys for each user is made public and the other is kept private. Let us denote the former by E, and the latter by D. So Alice knows Dalice, and everyone knows Ealice. To send Alice the symmetric key K, Bob simply sends C=Encrypt(K, Ealice). Alice, and only Alice (since no one else knows Dalice), can decrypt the ciphertext C to recover the message, i.e. Decrypt(C, Dalice)=K. Now both Alice and Bob know K and can use it for encrypting subsequent messages using a symmetric key system. Why not simply encrypt the message itself with the asymmetric system? This is simply because in practice all known asymmetric systems are fairly inefficient, and while they are perfectly useful for encrypting short strings such as K, they are inefficient for large messages.
[0013] The above illustrates how asymmetric cryptography can solve the key distribution problem. Asymmetric cryptography can also be used to solve another important problem, that of digital signatures. To sign a message M, Alice encrypts it with her own private key to create S=Encrypt(M, Dalice). She can then send (M, S) to the recipient who can then decrypt S with Alice's public key to generate M′, i.e. M′=Decyrpt(S, Ealice). If M′=M then the recipient has a valid signature as only someone who has Dalice, by definition only Alice, can generate S, which can be decrypted with Ealice to produce M. To convey the meaning of these cryptographic operations more clearly they are often written as S=Sign(M, Dalice) and M′=Verify(M, S, Ealice). It is worth noting that asymmetric key digital signatures provide non-repudiation in addition to the integrity and authentication achieved by symmetric key MACs. With MACs the verifier can compute the MAC for any message M of his choice since the computation is based on a shared secret key. With digital signatures this is not possible since only the sender has knowledge of the sender's private key required to compute the signature. The verifier can only verify the signature but not generate it.
[0014] The RSA cryptosystem is one system that implements asymmetric cryptography as described above. In particular the RSA cryptosystem allows the same public-private key pair to be used for encryption and for digital signatures. It should be noted there are other asymmetric cryptosystems which implement encryption only e.g., ElGamal or digital signature only, e.g., DSA.
[0015] Finally, the above description does not answer the important question of how Bob gets Alice's public key Ealice. The process for getting and storing the binding [Alice, Ealice] which binds Ealice to Alice is tricky. The most practical method appears to be to have the binding signed by a common trusted authority. So such a “certificate authority” (CA) can create CERTalice=Sign([Alice, Ealice], Dca). Now CERTalice can be verified by anyone who knows the CA's public key Eca. So in essence, instead of everyone having to know everyone else's public key, everyone only need know a single public key, that of the CA. More elaborate schemes with multiple Certificate Authorities, sometimes having a hierarchical relationship, have also been proposed.
[0016] Asymmetric key cryptosystems have been around for a long time, but have found limited use. The primary reasons are twofold: (a) the private key D in most systems is long, which means that users cannot remember them, and they have to either be stored on every computer they use, or carried around on smart cards or other tokens; and (b) the infrastructure for ensuring a certificate is valid, which is critical, is cumbersome to build, operate and use. The first technique proposed to validate certificates was to send every recipient a list of all certificates that had been revoked. This clearly does not scale well to an environment with millions of users. The second method proposed was to require that one inquire about the validity of a certificate on-line, which has its own associated problems.
[0017] A system based on split private key cryptography has been developed to solve these two issues, among others. In this system the private key for Alice, i.e. Dalice, is further split into two parts, Daa which Alice knows, and a part Das which is stored at a security server. To sign a message, Alice could perform a partial encryption to generate a partial signature, i.e. PS=Sign(M, Das). Alice then sends the server PS which ‘completes’ the signature by performing S=Sign(PS, Dss). This completed signature S is indistinguishable from one generated by the original private key, so the rest of the process works as previously described. However, Daa can be made short, which allows the user to remember it as a password, so this system is consumer friendly. Further, if the server is informed that a particular ID has been revoked, then it will cease to perform its part of the operation for that user, and consequently no further signatures can ever be performed. This provides for instant revocation in a simple highly effective fashion.
[0018] Let us return now to password based systems. Challengeresponse systems solve the issue of having to send passwords in the clear across a network. If the computer and Alice share a secret password, P, then the computer can send her a new random challenge, R, at the time of login. Alice computes C=Encrypt(R, P) and sends back C. The computer decrypts Decrypt(C, P)=C′. If C=C′, then the computer can trust that it is Alice at the other end. Note however that the computer had to store P. A more elegant solution can be created using asymmetric cryptography. Now Alice has a private key Dalice, or in a split private key system she has Daa. The computer challenges her to sign a new random challenge R. She signs the challenge, or in the split private key system she interacts with the security server to create the signature, and sends it back to the computer which uses her public key, retrieved from a certificate, to verify the signature. Observe that the computer does not have to know her private key, and that an eavesdropper observing the signature on R gains no knowledge of her private key.
[0019] The SSL system, which is widely used on the Internet in effect implements a more elaborate method of exactly this protocol. SSL has two components, ‘server side SSL’ in which a server proves its identity by signing a particular message during connection set-up. As browsers such as Netscape and Microsoft Internet Explorer come loaded with the public keys of various CAs, the browser can verify the signature of the server. This authenticates the server to the client, and also allows for the set-up of a session key K, which is used to encrypt all further communications. Server side SSL is widely used, as the complexity of managing certificates rests with system administrators of web sites who have the technical knowledge to perform this function. The converse function in SSL, client side SSL, which lets a client authenticate herself to a server is rarely used, because although the technical mechanism is exactly the same, it now requires users to manage certificates and long private keys which has proven to be difficult, unless they use the split private key system. So in practice, most Internet web sites use server side SSL to authenticate themselves to the client, and to obtain a secure channel, and from then on use Userid, Password pairs to authenticate the client.
[0020] So far from disappearing, the use of passwords has increased dramatically. Passwords themselves are often dubbed as inherently “weak” which is inaccurate, because if they are used carefully passwords can actually achieve “strong” security. As discussed earlier passwords should not be sent over networks, and if possible should not be stored on the receiving computer. Instead, in a “strong” system, the user can be asked to prove knowledge of the password without actually revealing the password. And perhaps most critically passwords should not be vulnerable to dictionary attacks.
[0021] Dictionary attacks can be classified into three types. In all three cases the starting point is a ‘dictionary’ of likely passwords. Unless the system incorporates checks to prevent it, users tend to pick poor passwords, and compilations of lists of widely used poor passwords are widely available.
[0022] 1) On line dictionary attack. Here the attacker types in a guess at the password from the dictionary. If the attacker is granted access to the computer they know the guess was correct. These attacks are normally prevented by locking the user account if there are an excessive number of wrong tries. Note that this very commonly used defense prevented one problem, but just created another one. An attacker can systematically go through and lock out the accounts of hundreds or thousands users. Although the attacker did not gain access, now legitimate users cannot access their own accounts either, creating a denial of service problem.
[0023] 2) Encrypt dictionary attacks: If somewhere in the operation of the system a ciphertext C=Encrypt(M, P) was created, and the attacker has access to both C and M, then the attacker can compute off-line C<b>1</b>=Encrypt(M, G<b>1</b>), C<b>2</b>=Encrypt(M, G<b>2</b>), . . . where G<b>1</b>, G<b>2</b>, . . . etc. are the guesses at the password P from the dictionary. The attacker stops when he finds a Cn=C, and knows that Gn=P. Observe that the UNIX file system, which uses a one way function F( ) instead of an encryption function E( ), is vulnerable to this attack.
[0024] 3) Decrypt dictionary attacks: Here the attacker, does not know M, and only sees the ciphertext C (where C=Encrypt (M, P). The system is only vulnerable to this attack IF it is true that M has some predictable structure. So the attacker tries M<b>1</b>=Decrypt(C, G<b>1</b>), M<b>2</b>=Decrypt(C, G<b>2</b>) . . . , and stops when the Mi has the structure he is looking for. For instance Mi could be known to be a timestamp, English text, or a number with special properties such as a prime, or a composite number with no small factors.
[0025] It is possible to design strong password based systems but the password should not be stored on the computer in any form, ever communicated to it, and should be protected from all three types of dictionary attacks.
[0026]FIG. 1 depicts the operations of Server-Side-Authentication during a communications session between network users, in this instance a client device such as a personal computer and a host device such as a server. It will be understood that software is resident on the client device and this software directs communications on the client side of the communication session. It will also be understood that software is resident on the server and that this software directs communications on the server side of the communication session. Furthermore, it should be understood that while in this example the server is associated with a merchant, the server could be associated with any type of entity. As used here, server designates any networked device capable of presenting information to another network device via the network. Also, it should be understood that while the client device in this example is associated with an individual user, the client device may be associated with an entity other than an individual user. Also, a client device may be any networked device capable of accessing information via a network.
[0027] At step <b>100</b> the client device transmits a message to the server. This message includes a first random number generated by the software and an indication of the types of cryptography the client device is capable of supporting. This message can be called a ‘hello’ message. The server then selects one of the types of cryptography and includes a second random number and the server's certificate in a transmission to the client device, step <b>110</b>. This transmission can be called ‘message two’. A certificate contains information certifying that an entity is who that entity claims to be. The client device then obtains the public portion of the server's asymmetric key from the certificate and verifies the certificate by verifying the certificate issuer's signature on the certificate, step <b>115</b>. The client device then generates and encrypts a symmetric session key with the public portion of the server's asymmetric key and transmits the encrypted symmetric session key to the server, step <b>120</b>. The server then decrypts the symmetric session key with the private portion of the server's asymmetric key and encrypts the first random number using the symmetric key and transmits the encrypted random number to the client device, step <b>125</b>. The client device then decrypts the random number using its copy of the symmetric key, step <b>130</b>. If the original first random number is recovered, the server has authenticated itself to the client device. All further communication between the server and client device are secured using the symmetric session key. It will be recognized that SSL server-side-authentication in current use does not actually follow steps <b>125</b> and <b>130</b>. Rather these steps are representative of how the shared symmetric key could be used for server to client authentication.
[0028] Client-Side-Authentication is designed to operate similar to Server-Side-Authentication as is depicted in FIG. 2. At step <b>200</b>, the server transmits a 36 byte hash to the client device and requests the client device to sign it with the private portion of the client device's asymmetric key. Also, the server will request that the client device return the client device's certificate. The client device signs the 36 byte hash and sends the signed 36 byte hash and the client device certificate to the server, step <b>210</b>. The server then verifies that the client device's certificate is valid and obtains the public portion of the browser's asymmetric key from the authority issuing the certificate, step <b>215</b>. The server then uses the public portion of the client device's asymmetric crypto-key to verify the client device signature, step <b>220</b>. If the server recovers the original 36 byte hash, the client device has authenticated itself to the server. It will be recognized here also that SSL client-side-authentication currently in use does not actually follow these precise steps. Rather these steps are representative of how the user's asymmetric public and private keys could be used for client to server authentication.
[0029] In practice, only Server-Side-Authentication is generally implemented today. Most servers which require authentication of other network users utilize passwords. As discussed above, after Server-Side-Authentication is completed, both the server and the client device are in possession of a symmetric session key. All subsequent communications between the parties during the present communication session are secured with the symmetric session key. Typically, the server requests the client device to supply a valid user ID and password. This information is provided by the user and transmitted from the client device to the server, encrypted with the symmetric session key. Each server must maintain a database of associated users. These databases contain passwords and information identifying the holders of the passwords. This requires the server to gather or dispense passwords and to manage stored passwords. If the password is valid, that is, it is included in the database, the client device has authenticated itself to the server.
[0030] Accordingly, a need exists for a technique whereby a first network user can obtain verifiable authentication from a second network user without the first network user having to maintain, process and utilize a password system.
[0031] A certificate issuing authority includes information about the user in the user's certificate. This information may include associations the user maintains, personal information, or even financial information. A certificate issuing authority may include information that a user does not want disclosed. Or, user information included in a certificate may change. Presently, a user cannot update or change information in an issued certificate. A user can at best revoke a certificate and obtain a new one which includes the changed information. When a new certificate is obtained, new keys must be generated. Any entity who has previously obtained the user's certificate and public key must now reobtain the new certificate and key. Thus, there is no way to modify a certificate without revoking the corresponding key pair.
[0032] Accordingly, a need exists whereby a certificate can be modified, while retaining the associated key pair.
[0033] A single user may have associations with multiple servers. Each of the multiple servers may require the user to maintain a password and client ID. Thus, a single user may be required to remember a plurality of passwords.
[0034] Oftentimes a user may attempt to establish the same client ID and password with several unrelated servers. This cannot always be accomplished. Some servers require a password to meet certain quality standards not be a ‘bad’ password, as discussed above. Thus a password that the user may wish to use may not be acceptable to certain servers. Also, a password that a user may wish to use may already be in use by another user of a server, and the server may not allow more than one user to use the same password.
[0035] Even if a user is able to use the same client ID and password for access to multiple servers, other problems with using passwords for authentication arise. For instance, a user's password may become compromised. That is, the password may become known to another individual. That individual can then impersonate the user to multiple servers. The user must obtain a new password with each server with which the user uses the now compromised password. Furthermore, if a user's password is compromised and a first server recognizes this fact, there is currently no method whereby this first server can notify other servers at which the user uses this same password that the password has been compromised.
[0036] Yet another problem with the use of passwords in providing authentication is that a user must provide a password to each and every server requiring authentication. If a user is fortunate enough to obtain the same password with several servers, the user still must provide the password to each server to which the user seeks access. Thus, every time a user wishes to perform communications with a server, that user must cause his or her password to be transmitted to the server. Furthermore, when a user ends an authenticated communication with a server and immediately attempts to reestablish an authenticated communication, the user must again provide his or her password to the server for authentication.
[0037] Accordingly, a need exists for a technique whereby a network user can utilize a single password to access a plurality of networked devices and enter that single password only once to gain access to any of the plurality of networked devices.
[0038] SSL as deployed in current systems is based upon the RSA public key cryptosystem. As introduced above, RSA relies upon the use of products of large prime numbers which are not easily factorable. If the RSA technique should be broken, that is, if an algorithm for factoring large prime numbers is found, SSL and any cryptosystem based on RSA would be useless. An attacker would have access to communications in any RSA based cryptosystem. Secure and trusted communications in SSL and other public key cryptosystems would become impossible. Accordingly, a need exists for a technique whereby a public key based cryptosystem could provide secure communications if RSA were to become unusable.
OBJECTIVES OF THE INVENTION
[0039] It is an object of the present invention to provide a system and method for improving conventional public cryptosystems such that the identity of a user can be verified without the use of passwords known to the verifier.
[0040] Additional objects, advantages, novel features of the present invention will become apparent to those skilled in the art from this disclosure, including the following detailed description, as well as by practice of the invention. While the invention is described below with reference to preferred embodiment(s), it should be understood that the invention is not limited thereto. Those of ordinary skill in the art having access to the teachings herein will recognize additional implementations, modifications, and embodiments, as well as other fields of use, which are within the scope of the invention as disclosed and claimed herein and with respect to which the invention could be of significant utility.
SUMMARY DISCLOSURE OF THE INVENTION
[0041] According to the invention, a method and system for user authentication in a crypto-system is provided. In a hardware embodiment, users of a network are each represented on the network by a network station. A network station may be a simple device capable of performing computing tasks, such as a networked personal digital assistant or digital telephone. The network station may be a more powerful device such as a personal computer, high powered workstation, network server, or mainframe computer. In any event, each network station, no matter the hardware forming a network station, must be capable of performing the operations necessary to achieve the results herein described. The network itself may be a private network, a public network, such as the Internet, or a wireless network.
[0042] A symmetric crypto-key is a key used to transform messages, such as to encrypt a message, decrypt a message and authenticate a message. A symmetric crypto-key has at least two identical portions. A message encrypted with one portion of a symmetric crypto-key can be decrypted using another portion, or the same portion, of the symmetric crypto-key.
[0043] An asymmetric crypto-key is a key used to transform messages, such as to encrypt a message, decrypt a message, or form a digital signal on a message. An asymmetric crypto-key has a public portion and at least one private portion. The public portion is widely known or available. In a single private portion asymmetric crypto-key, the private portion is known only to the user with whom the asymmetric crypto-key is associated. In a multiple private portion asymmetric crypto-key, at least one private portion is known to the user with whom the key is associated. Other portions of the key are known by other network stations trusted by the associated users. A message encrypted with the public portion can be decrypted with the private portion, and vice-versa. A message signed with the private portion can be authenticated with the public portion. When an asymmetric crypto-key has more than one private portion, all private portions must be used to decrypt a message encrypted with the public key or to sign a message wherein the signature can be verified by the public key. Each network station is associated with an asymmetric crypto-key having at least one private portion.
[0044] A first request for authentication of a first network user at a first network station is received by a second network station. The first network station is associated with a first asymmetric crypto-key having multiple private portions, preferably three private portions. The second network station generates a shared symmetric crypto-key. This shared symmetric crypto-key can also be called a challenge. The shared symmetric crypto-key can be generated before or after receipt of the first request. The second network station encrypts the generated shared symmetric crypto-key with a private portion of the first asymmetric crypto-key in response to receipt of the first request. This encrypted symmetric crypto-key is a first message. Preferably, this private portion of the first asymmetric crypto-key is known to the second network station before receiving the first authentication request from the first network station.
[0045] The second network station is associated with a second asymmetric crypto-key having preferably one private portion, though it could have more. The second network station then signs the first message with a private portion of the asymmetric crypto-key. The second network station then transmits this first signed message to the first network station.
[0046] The second network station then encrypts another copy of the shared symmetric crypto-key with the public portion of a third asymmetric crypto-key. This encrypted copy of the shared symmetric crypto-key is a second message. The second network station signs this second message with a private portion of the second asymmetric crypto-key and transmits the signed second message to a third network station. The third network station is associated with the third asymmetric crypto-key.
[0047] The third network station then authenticates the identity of the second network station by applying the public portion of the second asymmetric crypto-key to the second message. The act of authentication is also referred to as verification. The third network station then recovers the shared symmetric crypto-key by applying a private portion of the third asymmetric crypto-key to the second message. Preferably, the third asymmetric crypto-key has only one private portion, though it can have more than one private portion. If the second and third asymmetric crypto-keys have multiple private portions, each of the multiple private portions must be used to transform messages.
[0048] The third network station then encrypts the shared symmetric crypto-key with a second portion of the first asymmetric crypto-key. This forms a third message. This second private portion is different than the first portion. Preferably, the second private portion is known to the third network station prior to receiving the second message. The third network station then transmits the third message to the first network station.
[0049] The first network station receives the first and third messages. Thus, the first network station has two copies of the shared symmetric crypto-key, each encrypted with a different portion of the first asymmetric crypto-key. To authenticate himself to the second and third network stations, the first network station must recover the shared symmetric crypto-key.
[0050] The first network station authenticates the second network station by applying the public portion of the second crypto-key to the first message. The first network station then combines the first and third messages to form a fourth message. The fourth message remains encrypted with the first and second portions of the first asymmetric crypto-key.
[0051] The first network station then further encrypts the fourth message using a third private portion of the first asymmetric crypto-key. Preferably, this third private portion of the first asymmetric crypto-key is not stored in a persistent state. In the first embodiment, the first asymmetric crypto-key having three private portions, once the first network station further encrypts with the third private portion, the fourth message is fully encrypted with each portion of the first asymmetric crypto-key. This is a fifth message. To recover the shared symmetric crypto-key the first network station then applies the public portion of the first asymmetric crypto-key to the fully encrypted fifth message. This reveals the shared symmetric crypto-key to the first network station. Now, the first, second, and third network stations each know the shared symmetric crypto-key. This shared symmetric crypto-key can then be used to transform messages sent between these network stations.
[0052] The first network station then encrypts a second authentication request with the shared symmetric crypto-key to form a sixth message. This sixth message is then sent to one or both of the second and third network stations. By applying the shared symmetric crypto-key to the sixth message, the second and/or third network station authenticates the first network station.
[0053] Advantageously, the first network station may transmit the first authentication request to either of the second and third network stations. The network station receiving the first authentication request is the network station which generates and distributes the shared symmetric crypto-key. Thus, both the second and third network stations can perform identical operations.
[0054] In one beneficial aspect of the invention, the sixth message may be transmitted to only one of the second and third network stations. The first network station may transmit the sixth message to either the second or third network station. For example, if the sixth message is transmitted to the second network station, the second network station will apply the shared symmetric crypto-key to the sixth message to recover the second authentication request. This authenticates the first network station to the second network station. This also authenticates the third network station to the first network station, as the second network station now knows that the third network station successfully recovered the shared symmetric crypto-key.
[0055] The second network station then encrypts the second authentication request with a first private portion of the first asymmetric crypto-key. This is a seventh message. The second network station then transmits the seventh message to the third network station. The third network station then further encrypts the seventh message with a second private portion of the first asymmetric crypto-key. This is an eighth message. The third network station then transmits the eighth message to the first network station. The first network station then further encrypts the eighth message with the third and, in the first embodiment, final private portion of the first asymmetric crypto-key. This forms a ninth message. The second authentication request is now signed by each private portion of the first asymmetric crypto-key. The first network station can then present this fully encrypted second authentication request to yet another network station to authenticate himself, as the other network station need only apply the public portion of the first asymmetric crypto-key to the ninth message to recover the second authentication request. Of course, the second and third network stations can also sign the second authentication request with a private portion of the asymmetric crypto-key associated with that network station to authenticate themselves to other network stations.
[0056] In another beneficial aspect of the invention, the sixth message can be transmitted to both the second and third network stations. In this instance, both the second and third stations apply the shared symmetric crypto-key to the sixth message to recover the second authentication request. They both apply a different private portion of the first asymmetric crypto-key to the second authentication request, forming, respectively, a seventh and eighth message. Both these messages are transmitted to the first network station. The first network station then combines these messages to form a ninth message. Then he applies a third portion of the first asymmetric crypto-key to the ninth message, forming a tenth message. In the first embodiment, the tenth message is then fully encrypted or signed with the complete private portion of the first asymmetric crypto-key.
[0057] In alternative embodiments, the first asymmetric crypto-key may have more than three private portions. Each of these additional portions will be known or available to a different network station. For instance, if the first asymmetric crypto-key has four private portions, the second network station will also encrypt the shared symmetric crypto-key with the public portion of a fourth asymmetric crypto-key associated with a fourth network station forming another message, sign that other message and transmit it to the fourth network station. The fourth network station will authenticate the second network station, recover the shared symmetric crypto-key, encrypt it with the fourth portion of the first asymmetric crypto-key and transmit this to the first network station. The first network station will combine this with the first and third messages, further transform this combination with the third private portion and then recover the shared symmetric crypto-key, as described above.
[0058] Each network station applying a private portion of the first asymmetric crypto-key is capable of receiving the first authentication request, and generating and distributing the shared asymmetric crypto-key. Each of these network stations are also capable of receiving the second authentication request, and each are capable of determining which of the other network stations have not yet transformed the second authentication request and transmitting the second authentication request to those stations.
[0059] In yet another aspect of the invention, the first authentication request can include information identifying the first network station. The second authentication request can include a request to sign a hash. Signing the hash with a portion of the first asymmetric crypto-key forms a partial signature on the hash. When each of multiple private portions of the first asymmetric crypto-key has been used to progressively sign the hash, the hash has a complete signature. The hash may be provided by another network station other than those signing the hash. When this network station applies the public portion of the first asymmetric crypto-key to the fully signed hash and verifies the signature, the first network station is authenticated to this network station.
[0060] In another aspect of the present invention, the second and third network stations are associated. They are known to each other. They preferably are associated with a sponsor. A sponsor is an entity controlling generation, assignment, and distribution of the asymmetric crypto-keys. Furthermore, either the first or the second network station can be the network station having generated the asymmetric crypto-keys.
[0061] The present invention also provides for authentication of the third network station to the first network station. In such a case, the third network station signs the third message with a private portion of the third asymmetric crypto-key. The first network station applies the public portion of the third asymmetric crypto-key to the third message to authenticate the third network station.
BRIEF DESCRIPTION OF DRAWINGS
[0062]FIG. 1 is a flow chart showing the operations of a prior art cryptographic system in performing authentication of a server to a client.
[0063]FIG. 2 is a flow chart showing the operations of a prior art cryptographic system in performing authentication of a client to a server.
[0064]FIG. 3 depicts an exemplary network of the present invention, including networked devices of the present invention.
[0065]FIGS. 4<i>a</i>-<b>4</b><i>c </i>is a flow chart showing the operations which are performed by a user and the sponsor station of the present invention for the user to log on with the sponsor station.
[0066]FIGS. 5<i>a</i>-<b>5</b><i>b </i>is a flow chart showing the operations which are performed by a user and the sponsor station of the present invention for a user to authenticate himself or herself to a server.
[0067]FIGS. 6<i>a</i>-<b>6</b><i>c </i>is a flow chart showing the operations which are performed by a user and a distinguished server and sponsor station of the present invention in associating an asymmetric key pair with the user.
[0068]FIG. 7 depicts the exemplary network and networked devices of FIG. 1, in addition to another network, including networked devices according to the present invention present on the other network.
[0069]FIG. 8 depicts the exemplary network of FIG. 3, including alternative networked devices according to the present invention.
[0070]FIG. 9 depicts a computer suitable for use by a user to access a network in accordance with the invention.
[0071]FIG. 10 is an exemplary block diagram of components of the computer depicted in FIG. 9.
[0072]FIG. 11A depicts a server suitable for use by the sponsor station, distinguished entities, and merchants in accordance with the present invention.
[0073]FIG. 11B is an exemplary block diagram of components of the server depicted in FIG. 11A.
BEST MODE FOR CARRYING OUT THE INVENTION
[0074]FIG. 3 illustrates a network <b>10</b>, which could be the Internet. As shown, the network <b>10</b> is an interconnection of networked devices in communication with each other. These networked devices include networked devices <b>30</b>-<b>33</b> associated with individual network users, networked device <b>40</b>-<b>41</b> associated with a merchant network user, a sponsor station <b>50</b> associated with a sponsor, and networked devices <b>60</b>-<b>62</b> associated with entities known to and trusted by the sponsor.
[0075] Networked devices <b>30</b>-<b>33</b> will be referred to as user devices. These network devices are typically personal computers. Networked devices <b>40</b>-<b>41</b> will be referred to as merchant servers. Networked devices <b>60</b>-<b>62</b> will be referred to as distinguished servers. It will be understood that a network may consist of more networked devices than depicted in FIG. 3.
[0076]FIGS. 9 and 10 depict an exemplary personal computer suitable for use by individual users to access the network <b>10</b> in the below-described invention. The computer is preferably a commercially available personal computer. It will be recognized that the computer configuration is exemplary in that other components (not shown) could be added or substituted for those depicted and certain of the depicted components could be eliminated if desired.
[0077] The computer functions in accordance with stored programming instructions which drive its operation. Preferably, the computer stores its unique programming instructions on an EPROM, or hard disk. It will be recognized that only routine programming is required to implement the instructions required to drive the computer to operate in accordance with the invention, as described below. Further, since the computer components and configuration are conventional, routine operations performed by depicted components will generally not be described, such operations being well understood in the art.
[0078] Referring to FIG. 9, the computer <b>1000</b> includes a main unit <b>1010</b> with slots <b>1011</b>, <b>1012</b>, and <b>1013</b>, respectively provided for loading programming or data from a floppy disk and/or compact disk (CD) onto the computer <b>1000</b>. The computer <b>1000</b> also includes a keyboard <b>1030</b> and mouse <b>1040</b> which serve as user input devices. A display monitor <b>1020</b> is also provided to visually communicate information to the user.
[0079] As depicted in FIG. 10, the computer <b>1000</b> has a main processor <b>1100</b> which is interconnected via bus <b>1110</b> with various storage devices including EPROM <b>1122</b>, RAM <b>1123</b>, hard drive <b>1124</b>, which has an associated hard disk <b>1125</b>, CD drive <b>1126</b>, which has an associated CD <b>1127</b>, and floppy drive <b>1128</b>, which has an associated floppy disk <b>1129</b>. The memories, disks and CD all serve as storage media on which computer programming or data can be stored for access by the processor <b>1100</b>. The memory associated with a personal computer here after will collectively be referred to as Memory <b>1170</b>. A drive controller <b>1150</b> controls the hard drive <b>1124</b>, CD drive <b>1126</b> and floppy drive <b>1128</b>. Also depicted in FIG. 10 is a display controller <b>1120</b> interconnected to display interface <b>1121</b>, a keyboard controller <b>1130</b> interconnected to keyboard interface <b>1131</b>, a mouse controller <b>1140</b> interconnected to mouse interface <b>1141</b> and a modem <b>1160</b> interconnected to I/O port <b>1165</b>, all of which are connected to the bus <b>1110</b>. The modem <b>1160</b> and interconnected I/O port <b>1165</b> are used to transmit and receive signals via the Internet <b>100</b> as described below. It will be understood that other components may be connected if desired to the bus <b>1110</b>. By accessing the stored computer programming, the processor <b>1100</b> is driven to operate in accordance with the present invention.
[0080] Sponsor station <b>50</b>, the merchant users and the distinguished entities are preferably represented on network <b>10</b> by an Internet server of the applicable type shown in FIGS. 11A and 11B, as will be described further below. However, here again, any network compatible device which is capable of functioning in the described manner could be substituted for the servers shown in FIGS. 11A and 11B.
[0081]FIGS. 11A and 11B depict an exemplary network server suitable for use by the sponsor, merchants, and distinguished entities to access the network <b>10</b> in the below-described invention. The server is preferably a commercially available high power, mini-computer or mainframe computer. Here again, it will be recognized that the server configuration is exemplary in that other components (not shown) could be added or substituted for those depicted and certain of the depicted components could be eliminated if desired.
[0082] The server functions as described below in accordance with stored programming instructions which drive its operation. Preferably, the server stores its unique programming instructions on an EPROM or hard disk. It will be recognized that only routine programming is required to implement the instructions required to drive the server to operate in accordance with the invention, as described below. Further, since the server components and configuration are conventional, routine operations performed by depicted components will generally not be described, such operations being well understood in the art.
[0083] Referring to FIG. 11A, the server <b>1000</b>′ includes a main unit <b>1010</b>′ with slots <b>1011</b>′, <b>1012</b>′, <b>1013</b>′ and <b>1014</b>′, respectively provided for loading programming or data from a floppy disk, CD and/or hard disk onto the server <b>1000</b>′. The server <b>1000</b>′ also includes a keyboard <b>1030</b>′ and mouse <b>1040</b>′, which serve as user input devices. A display monitor <b>1020</b>′ is also provided to visually communicate information to the user.
[0084] As depicted in FIG. 11B, the server <b>1000</b>′ has a main processor <b>1100</b>′ which is interconnected via bus <b>1110</b>′ with various storage devices including EPROM <b>1122</b>′, RAM <b>1123</b>′, hard drive <b>1124</b>′, which has an associated hard disk <b>1125</b>′, CD drive <b>1126</b>′, which has an associated CD <b>1127</b>′, and floppy drive <b>1128</b>′, which has an associated floppy disk <b>1129</b>′. The memories, disks and CD all serve as storage media on which computer programming or data can be stored for access by the processor <b>1100</b>′. The stored data includes one or more databases containing information associated with network users. The memories associated with a server hereafter will be collectively referred to as memory <b>1170</b>′. A drive controller <b>1150</b>′ controls the hard drive <b>1124</b>′, CD drive <b>1126</b>′ and floppy drive <b>1128</b>′. Also depicted in FIG. 11B is a display controller <b>1120</b>′ interconnected to display interface <b>1121</b>′, a keyboard controller <b>1130</b>′ interconnected to keyboard interface <b>1130</b>′, a mouse controller <b>1140</b>′ interconnected to mouse interface <b>1141</b>′ and a modem <b>1160</b>′ interconnected to I/O port <b>1165</b>′, all of which are connected to the bus <b>1110</b>′. The modem <b>1160</b>′ and interconnected I/O port <b>1165</b>′ are used to transmit and receive signals via the network <b>10</b> as described above. It will be understood that other components may be connected if desired to the bus <b>1110</b>′. By accessing the stored computer programming, the processor <b>1100</b>′ is driven to operate in accordance with the present invention.
[0085] An asymmetric crypto-key is associated with at least each individual network user, and each distinguished server. If desired, an asymmetric crypto-key can also be associated with each merchant user. Each asymmetric crypto-key consists of two portions, a public portion and a private portion. The public portion of each asymmetric crypto-key is known to at least each merchant user. If desired, the public portion of each asymmetric crypto-key can also be known to each individual user. Each of these public portions can be stored on each merchant server, or on each merchant server and each individual device. The private portion of each asymmetric crypto-key consists of at least a first private portion and a second private portion. The first private portion is retained by the individual or merchant user with whom the asymmetric crypto-key is associated. The first private portion of the asymmetric crypto-key key will be referred to as Dxx and is derived from the user's password, as will be discussed below. The second private portion of each asymmetric crypto-key is retained by the sponsor station <b>50</b> and will be referred to as Dxs.
[0086] The asymmetric crypto-keys are used in transforming information. Preferably, the asymmetric crypto-keys are used in providing trusted authentication of an individual user to a merchant user. Also, the asymmetric crypto-keys can be used in providing trusted authentication of an individual user to another individual user, or of a merchant user to another merchant user.
[0087] In the case of providing trusted authentication of an individual user, in this instance, the individual user associated with user device <b>30</b>, to a merchant user, in this instance, the merchant user associated with merchant server <b>40</b>, the following operations, as shown in FIGS. 4 and 5, are performed by networked devices <b>30</b> and <b>40</b>.
[0088] A communication session between user device <b>30</b> and merchant server via network <b>10</b> is established, step <b>401</b> of FIG. 4. Merchant server <b>40</b> transmits a request via network <b>10</b> to user device <b>30</b> requesting that the individual user authenticate himself or herself to the merchant user, step <b>410</b>. As described above, this request typically is a request for the party being authenticated to sign a 36 bit hash provided by the authenticating party or otherwise determined by the user-merchant communication.
[0089] In response to this request, the user device <b>30</b> determines if a logged-in ticket is stored on memory <b>1170</b> at the user device <b>30</b>, step <b>415</b>. If so, operations continue as described below and shown at step <b>510</b> of FIG. 5<i>a. </i>If not, user device <b>30</b> requests the individual user to enter his or her user ID and password into the user device <b>30</b> to begin a log on protocol, step <b>420</b>.
[0090] Alternatively, a user associated with an asymmetric crypto-key may contact the sponsor station <b>50</b>, via the network <b>10</b>, to log on prior to establishing a communications session with another network station. In this instance, processing begins with establishing a communications session between the user device and the sponsor station <b>50</b>, step <b>405</b>. Processing in this instance continues with step <b>420</b> as herein described.
[0091] User device <b>30</b> processes the entered password to obtain Dxx, the first private portion of the asymmetric crypto-key, step <b>425</b>. Processing of the entered password to obtain Dxx is discussed below. User device <b>30</b> then transmits a log-in request to sponsor station <b>50</b>, step <b>430</b>. The log-in request includes at least the user's user ID. It should be understood that step <b>425</b> can occur previous to step <b>430</b>, concurrent with step <b>430</b>, or subsequent to step <b>430</b>, though it is shown previous to step <b>430</b> in FIG. 4a.
[0092] Sponsor station <b>50</b> receives and processes the log-in request to generate a challenge to the user device <b>30</b>, step <b>435</b>. Use of a challenge will be understood by one skilled in the art. The challenge is transmitted to the user device <b>30</b>, step <b>440</b>. The login request and challenge are preferably each transmitted in the clear. That is, neither of these messages are protected. However, as will be discussed below, optional operations can be performed to protect these messages.
[0093] The user device <b>30</b> receives the challenge and generates a random number R<b>1</b> and a time stamp, step <b>445</b>. Preferably, R<b>1</b> is a 192 bit number. Next, the user device <b>30</b> encrypts the challenge, time stamp and R<b>1</b> with Dxx, forming a first encrypted message, step <b>450</b>. User device <b>30</b> transmits the first message to sponsor station <b>50</b>, step <b>451</b>.
[0094] Sponsor station <b>50</b> decrypts the first encrypted message using the second portion of the user's private key and the user's public key to recover the challenge, time stamp and R<b>1</b>, step <b>455</b>. This operation authenticates the user device <b>30</b> to the sponsor station <b>50</b>. If this authentication fails, that is, the challenge, time stamp and R<b>1</b> are not encrypted with Dxx and therefore are unrecoverable using the second portion of the user's private key and the user's public key, sponsor station <b>50</b> transmits a notice to the user device <b>30</b> causing the user device <b>30</b> to prompt the user to reenter his or her password, and user ID, step <b>460</b>, and operations continue with step <b>420</b>.
[0095] If authentication is successful, the sponsor station <b>50</b> generates a second random number R<b>2</b>, computes the function XOR of R<b>1</b> and R<b>2</b>, generates a time stamp, and determine a lifetime-value, step <b>465</b>. As with R<b>1</b>, R<b>2</b> is preferably a 192 bit number. The lifetime-value is the life span of the logged-in ticket. This value may be a finite time period, such as 1 hour or any other finite time period so desired, or this value may be an end time such that the logged-in ticket expires upon that time being reached. Next, the sponsor station <b>50</b> encrypts R<b>2</b>, the time stamp, and the lifetime-value with R<b>1</b>, forming a second encrypted message, step <b>470</b>. The sponsor station <b>50</b> transmits this second encrypted message to the user device <b>30</b>, step <b>471</b>.
[0096] The user device <b>30</b> decrypts the second encrypted message using R<b>1</b>, recovering R<b>2</b>, the time stamp, and the lifetime-value, step <b>475</b>. This operation authenticates the sponsor station <b>50</b> to the user device <b>30</b>. The user device <b>30</b> computes function XOR of R<b>1</b> and R<b>2</b> which is called R<b>12</b>, encrypts Dxx with R<b>1</b>, and then destroys R<b>1</b> and the unencrypted Dxx, step <b>480</b>. The user device <b>30</b> then stores the encrypted Dxx, user ID, time stamp, and the lifetime-value on memory <b>1170</b>, forming the logged-in ticket, step <b>485</b>. The user device <b>30</b> then transmits a message to the sponsor station <b>50</b> which includes a ‘done’ indication and a time stamp which are encrypted using R<b>12</b>, step <b>490</b>. The sponsor station <b>50</b> stores an indication in memory <b>1170</b>′ that the user is logged in. The user has now successfully logged in and can use the services of the sponsor station <b>50</b> to sign the 36 byte hash. As will be shown below, if the user has an unexpired logged-in ticket, the user need not provide the user's client ID or password again to provide authentication to another network station requesting authentication.
[0097] Once the user is successfully logged in, to complete the authentication of user to the merchant, the user device <b>30</b> transmits an authorization request to the sponsor station <b>50</b>, step <b>510</b> of FIG. 5. The authorization request includes the user's user ID which is stored as part of the logged-in ticket on memory <b>1170</b>. The user device <b>30</b> retrieves the user ID from memory <b>1170</b>, the user device <b>30</b> does not prompt the user to enter the user ID. This transmission is sent using a Message Authentication Code (MAC) using R<b>12</b>. As will be understood by one skilled in the art, a MACed message is not encrypted, rather it includes a number string appended to the message which authenticates the sender of the message to the receiver of the message and assures integrity of the message content. The user device <b>30</b> MACs the authorization request with R<b>12</b>. The sponsor station <b>50</b> processes the received message to authenticate the user based upon the MACed message, step <b>515</b>. Then, the sponsor station <b>50</b> generates and transmits an acknowledgement message to the user device <b>30</b>. This is also MACed with R<b>12</b>, step <b>516</b>.
[0098] The user device <b>30</b> authenticates the received acknowledgment and encodes a 36 byte hash, provided by the merchant server <b>40</b>, step <b>520</b>. Preferably, the 36 byte hash is encoded using the PKCS<b>1</b> algorithm, though other well known algorithms could be used. Next, the user device <b>30</b> encrypts the 36 byte hash and a time stamp with R<b>12</b> and transmits both to the sponsor station <b>50</b>, step <b>525</b>.
[0099] The sponsor station <b>50</b> decrypts encoded 36 byte hash and time stamp using R<b>12</b>, step <b>530</b>. Next, the sponsor station <b>50</b> signs the encoded 36 byte hash with Dxs, the second private portion of the asymmetric crypto-key, step <b>535</b>. The sponsor station <b>50</b> generates a fresh time stamp, recalls R<b>1</b> from memory <b>1170</b>′, and transmits the time stamp, the signed encoded 36 byte hash, and R<b>1</b> to the user device <b>30</b>, all encrypted with R<b>12</b>, step <b>540</b>.
[0100] The user device <b>30</b> decrypts the time stamp, the signed encoded 36 byte hash, and R<b>1</b> using R<b>12</b>, step <b>545</b>. Then, the user device <b>30</b> recalls encrypted Dxx from the memory <b>1170</b> and decrypts Dxx using R<b>1</b> obtained from the sponsor box <b>50</b>, step <b>550</b>. The user device <b>30</b> then uses Dxx to complete the signature of the encoded 36 byte hash and transmits the fully signed 36 byte hash to the merchant server <b>40</b>, step <b>555</b>. To complete the transaction, the user device <b>30</b> transmits a ‘done’ message to the sponsor station <b>50</b>, step <b>560</b>.
[0101] Alternately the encoded 36 byte hash could be first signed on the user device <b>30</b> using Dxx decrypted via R<b>12</b> and the signature completed on the sponsor station <b>50</b> using Dxs.
[0102] It will be understood by one skilled in the art that any or all of the communications depicted in FIGS. 4<i>a</i>-<b>4</b><i>c </i>and <b>5</b><i>a</i>-<b>5</b><i>b </i>between the user device <b>30</b> and sponsor station <b>50</b> could include a sequence number. It also will be understood that any or all of the communications depicted in FIGS. 5<i>a</i>-<b>5</b><i>b </i>could be encrypted with R<b>12</b>, MACed with R<b>12</b>, or both encrypted and MACed with R<b>12</b>. Also, further protection of encrypted messages can be obtained by use of a Salt, which will be understood by one skilled in the art.
[0103] To provide trusted authentication to yet another merchant server, or perhaps to merchant server <b>40</b> at a later time, operations continue as depicted in FIG. 4<i>a, </i>step <b>401</b>, and as discussed above. If, as depicted in step <b>415</b>, the user device <b>30</b> determines that an unexpired log-in ticket is stored in memory <b>1170</b>, operations continue as depicted in FIG. 5<i>a, </i>step <b>510</b>. Thus, the user associated with network station <b>30</b> need only enter his or her user ID and password once, while the user is able to provide trusted authentication to more than one merchant user.
[0104] The sponsor station <b>50</b> is responsible for creating the association between users and asymmetric crypto-keys. For a user to obtain an association with an asymmetric crypto-key, the user must have a relationship with an entity associated with a distinguished server. A distinguished server and sponsor station <b>50</b> maintain a trusted relationship. The sponsor station <b>50</b> will provide an asymmetric crypto-key only for those users referred to it by a distinguished server.
[0105] For instance, if the individual user associated with user device <b>31</b> wishes to obtain an association with an asymmetric crypto-key, yet does not have a preexisting relationship with any distinguished server, that user may choose to contact distinguished server <b>60</b> via the network <b>10</b> and provide identity information to the distinguished server <b>60</b>. In this case, the distinguished server <b>60</b> has the capabilities to verify identity information. This capability may be any well known method of verifying identify information, such as a database of credit information, a database of telephone account information, or a database of address information. If the distinguished server <b>60</b> verifies the provided information, the distinguished server <b>60</b> can refer the user to the sponsor station <b>50</b>.
[0106] If an individual user associated with user device <b>32</b> wishes to obtain an association with an asymmetric crypto-key and has a relationship with the distinguished server <b>61</b>, the individual user must request that the distinguished server <b>61</b> initiate the process of associating an asymmetric crypto-key with the individual user. Operations as described below and depicted in FIG. 6 will be performed.
[0107] Also, in yet another instance of initiation of asymmetric crypto-key association, distinguished server <b>62</b> may be associated with an entity wishing to associate an asymmetric crypto-key for each of a plurality of individuals already known to it. For instance, a merchant or bank may wish to provide to customers the opportunity to use the services of the sponsor station <b>50</b>. Or, an organization may wish to provide to its members the opportunity to use the services of the sponsor station <b>50</b>.
[0108] In any event, association of an asymmetric crypto-key is a three party process. As shown in step <b>601</b> of FIG. 6<i>a, </i>a distinguished server, in this instance distinguished server <b>62</b> logs in with the sponsor station <b>50</b>, as described above. Then, the distinguished server <b>62</b> transmits to the sponsor station <b>50</b> information identifying a new user with whom an asymmetric crypto-key will be associated, in this instance the individual user associated with user device <b>33</b>, step <b>605</b>. The sponsor box then generates a symmetric key pair and a user ID which will be associated with the new user, step <b>610</b>. This symmetric key pair will serve as a one time activation code. Preferably, the symmetric key is a short pronounceable word. This symmetric key and user ID is stored in the memory <b>1170</b>′ and is also transmitted to the distinguished server <b>62</b>, step <b>615</b>. The distinguished server <b>62</b> then causes the symmetric key and user ID to be delivered to the new user. This delivery may be via traditional postal delivery, via e-mail, or via other electronic delivery, such as via a web-page, step <b>617</b>. Preferably electronic or hard-copy delivery will be secured using techniques familiar to those skilled in the art.
[0109] The new user, after receiving the user ID and symmetric key, establishes a communication session with the sponsor station <b>50</b>, step <b>620</b>. The new user enters the user ID into his or her user device and transmits the same to the sponsor station <b>50</b>, step <b>625</b>.
[0110] The sponsor station <b>50</b> matches the received user ID with the user ID and symmetric key stored in memory <b>1170</b>′, step <b>630</b>. If the received user ID has a match, the sponsor station <b>50</b> generates a challenge and encrypts the challenge with the symmetric key/one time activation code, step <b>635</b>. The sponsor box transmits the encrypted challenge and a request for the new user to select a password to the user device <b>33</b>, step <b>638</b>. The user device <b>33</b> decrypts the challenge using the new user's symmetric key/one time activation code, step <b>640</b>.
[0111] The new user selects and enters a password which is then encrypted by the user device <b>33</b> using the symmetric key/one time activation code, and this is then transmitted to the sponsor station <b>50</b>, step <b>645</b>. The sponsor station <b>50</b> decrypts the password using the symmetric key/one time activation code, step <b>650</b>. The sponsor station <b>50</b> generates a new key set, step <b>651</b>. The new key set is keys Dx and Ex, the entire private and public portions of the asymmetric crypto-key. Then, the sponsor station <b>50</b> splits Dx into Dxx and Dxs, the first and second portions of the private portion, step <b>655</b>. Computation of Dxx will be further discussed below, as well as generation of yet another key, Dxx++, which is generated after Dxx is obtained. However, it should be understood that the sponsor station <b>50</b> bases Dxx on the password. After generating the keys, the sponsor station stores Dxs, Dxx++, and Ex in the memory <b>1170</b>′ and destroys the password, Dxx and Dx, step <b>660</b>. As a result, the user's entire private key is not stored at the sponsor station <b>50</b>.
[0112] It should be noted that sponsor station <b>50</b> does not distribute or otherwise supply Dxx to any user, including the user with whom it is associated, yet the associated user will be able to transform messages using Dxx. According to the present invention, Dxx is a long key for use by a system user, yet the system user need not store this long key, obviating the problems with long keys discussed above. Furthermore, because Dxx is generated each instance it is used from a short password, a user need only memorize a short password. Thus the present invention includes not only the benefits of short keys, but the protection of long keys.
[0113] It should also be noted that when a new user establishes his or her password with the sponsor station <b>50</b>, the new user is also prompted for information to be included in a certificate to be associated with the asymmetric crypto-key.
[0114] Each time a user desires to log on to the sponsor station <b>50</b>, the user enters his or her password into his or her network device and the network device then computes Dxx from the password, as introduced above. This computation is a computation based upon a one way function, preferably using the PKCS-5 algorithm. A one way function is a function that it is very difficult to reverse. Thus, it is difficult, if not impossible, to take a computed Dxx and determine the password from which it was computed. The computation performed by a user's networked device to obtain Dxx is the same computation performed by the sponsor station <b>50</b> to obtain Dxx during key association. At least one one-way function is stored on memory <b>1170</b> of each networked device. Each one way function stored on a networked device is also stored on memory <b>1170</b>′ at the sponsor station <b>50</b>.
[0115] The user password is preferably a short password which is easily remembered by the user, ideally approximately 8 characters in length. An eight character password is approximately between 56 and 72 bits in length. The one way computation takes this short password and transforms it into a long key, preferably 1024 bits long, but at least 257 bits long. Thus, the effective length of the first portion of the private key is not the bit length of the password, but the bit length of the computed Dxx. It will be recognized that advantages of generation of a long key from a short key, that is, a password, are equally beneficial to any cryptosystem, including symmetric and asymmetric cryptosystems.
[0116] The processing to obtain the long Dxx, whether it be PKCS-5 or some other processing, requires a time period for the computation to be completed. This time period, which can referred to as a system delay, serves to defend against dictionary attacks, which have been described above. For instance, if an attacker were to obtain a message M encrypted with Dxx, and even if the intruder had knowledge of the one way computation algorithm, the intruder would be required compute Dxx for each bad password in her arsenal of bad passwords and attempt to decrypt S using the Dxx obtained from each of the bad passwords. If the arsenal consisted of 40,000 bad passwords, and if the system delay to obtain Dxx is 10 seconds, at a minimum the attacker would have to invest over 111 hours of computing time to attack with each bad password in her arsenal.
[0117] The use of a computed Dxx also aids in defending against on-line guessing attacks for the same reason discussed above. An attacker would have to choose a user ID and a password with which to attempt to log in, establish a communication session with the sponsor station <b>50</b> and enter the selected user ID and password. The networked device the attacker is using would then have to compute Dxx from the password and transmit the same to the sponsor station <b>50</b>. The added computation time in obtaining Dxx would decrease the number of guesses an attacker could attempt in any time period. As will be understood by one skilled in the art, the sponsor station <b>50</b> may be configured to allow only a limited number password attempts.
[0118] The time for completion of the one way function computation can be varied. That is, the one way computation can be made more or less complex depending upon a number of factors. This complexity may be based on the number of iterations performed by a one way computation. Or, the complexity may be varied based upon selection of the one way function.
[0119] A first factor may be the user with whom the password is associated. For instance, a system administrator's password may be required to be processed by the one way computation such that a longer time delay is introduced.
[0120] A second factor may be the password itself. For instance, a password which meets certain prescribed criteria for quality, as discussed above, may not require a complex computation, as a quality password is less likely to be vulnerable to a dictionary attack.
[0121] A third factor may be type of system being accessed. For instance, operators of a system which provides access to sensitive financial data may wish to make compromising their system's integrity very difficult, thus requiring a long system delay for password conversion.
[0122] A fourth factor, which also focuses on the identity of the user, may be the location of the user, or networked device used by the user, seeking access to a given resource. For instance, FIG. 7 depicts the network of FIG. 3, with the addition of another network <b>70</b> in communication with network <b>10</b>. The other network <b>70</b> may be an intranet, a LAN, a WAN, or any other type of network. The other network <b>70</b> includes a second sponsor station <b>71</b> and a plurality of networked devices <b>72</b>-<b>74</b>. Sponsor station <b>71</b> may mandate a longer system delay for user devices <b>30</b>-<b>33</b> than for user devices <b>72</b>-<b>74</b>, as networked devices <b>30</b>-<b>33</b> are not a part of the other network <b>70</b>.
[0123] If the time of computation of the one way function is varied, stored on memory <b>1170</b>′ at sponsor station <b>50</b> is an indication of which one way function is associated with each user and/or the number of iterations of a one way function a particular user is required to perform.
[0124] The present invention also enables a user to manage his or her information with the sponsor station <b>50</b>. This includes changing the password should the user so desire. This may be due to the password becoming compromised, or for any other reason. A user is also able to change, delete or otherwise modify the information included in the user's certificate. Communications between a user and the sponsor station <b>50</b> to manage user information may be encrypted with R<b>12</b>, due to the sensitive nature of this operation.
[0125] It should be recognized that a user, prior to accessing any given networking device, may establish a communications session with the sponsor station <b>50</b> and change, delete or otherwise modify information included in the user's certificate. After accessing the given networking device, the user can reestablish a communication session with the sponsor station <b>50</b> and once again change the information included in the certificate. Thus, a user is able to access a plurality of networking devices using the same public crypto-key, while controlling information disclosed to each networking device about the user in the user's certificate.
[0126] The key Dxx++ was introduced above. Dxx++ is a key which is obtained by performing a predetermined number of additional iterations of a one way function on a password. As an example, if five iterations of a one way function are designated to obtain Dxx, seven iterations of the same one way function may be designated to obtain Dxx++. It should be remembered that it is difficult or impossible to reverse a one way function. The Dxx++ associated with each user is stored in memory <b>1170</b>′ at the sponsor station <b>50</b>. Dxx++ can be computed at each user's networked device from a user's password.
[0127] As discussed above, most public cryptosystems are based upon RSA. If RSA should become compromised, Dxx++ will be used to encrypt information between network users and the sponsor station <b>50</b> and between network users themselves. It will be apparent from the above discussion that Dxx++ is a shared secret symmetric key. Both the user and the sponsor station hold, or can easily obtain, Dxx++. Dxx++ provides a fall back symmetric cryptographic system.
[0128] If the sponsor station <b>50</b> determines that RSA has become compromised, the sponsor station <b>50</b> will direct that communications will be performed using symmetric key encryption. Thus, when a user establishes a communication session with the sponsor station <b>50</b>, the sponsor station <b>50</b> will transmit a message to the user device causing the user device to compute Dxx++ and to encrypt all further communications with the sponsor device using Dxx++. Thus even though RSA may become compromised the sponsor station <b>50</b> and a networked device can still conduct secure communications. A user will be able to use the same password created for use in an asymmetric cryptosystem in what may become a symmetric cryptosystem. In a fall back situation, the sponsor station, which holds Dxx++ for each user, can serve as a distributing agent for symmetric keys, enabling users to have secure communications with one another. It should be understood that use of Dxx++ as a fall back scheme is applicable to any cryptosystem based upon RSA. It is also applicable to public-key cryptosystems which are not based on RSA.
[0129] As shown in FIG. 8, the sponsor station <b>50</b> of FIG. 3 may be replaced by a plurality of sponsor stations. In this instance, <b>3</b> sponsor stations are shown, sponsor stations <b>80</b>, <b>81</b>, and <b>82</b>. Though these sponsor stations are shown communicating with networking devices via the network <b>10</b>, it should be understood that the plurality of sponsor stations may also communicate with one another via separate communications channels. Furthermore, the plurality of sponsor stations may be located in the same physical location, or they may be located in separate physical locations.
[0130] One or more sponsor stations may be used as back up for a failed sponsor station. Or, the operation of signing a 36 byte hash, as described above, may be performed by multiple sponsor stations. In such a case, alternative operations are set forth below.
[0131] In each alternative, the private key portion of the asymmetric key is split into more than two portions. That is, each of the multiple servers holds a Dxs. Thus, sponsor station <b>80</b> holds key Dxs<sub>1</sub>, sponsor station <b>81</b> holds key Dxs<sub>2</sub>, and sponsor station <b>82</b> holds key Dxs<sub>3</sub>. In such an alternative, any one of the sponsor stations can associate the keys with users, as described above. That sponsor station then must distribute the appropriate Dxs portion to each of the other sponsor station.
[0132] In the first alternative, which could be called a parallel method, to obtain a signature on a 36 byte hash, a user device must transmit a copy of the hash to each of the multiple sponsor stations. Each station applies that sponsor station's Dxs to the hash and transmits the signed hash back to the user device. The user device then multiplies each of the signed hashes together, relying on the commutative property of RSA, and signs this result with the user's portion of the private key. The user device can then transmit the signed 36 byte hash to the requesting merchant server, as described above.
[0133] In a second alternative, authentication of the user to each of the multiple sponsor stations can be provided. In this alternative a temporary shared secret key is established between the multiple sponsor stations and the user.
[0134] A user initiates a log-in with any of the multiple sponsor stations as described above, and in this instance with sponsor station <b>80</b>. The sponsor station <b>80</b> generates a challenge C<b>1</b> and signs C<b>1</b> with a private key associated with sponsor station <b>80</b>. This private key is verifiable by each of the other sponsor stations. That is, they each have the corresponding public key. Then, sponsor station <b>80</b> encrypts the challenge with its portion of the user's private key. The sponsor station <b>80</b> also encrypts a copy of C<b>1</b> with the public key of sponsor station <b>81</b> and encrypts a copy of C<b>1</b> with the public key of sponsor station <b>82</b>. The sponsor station <b>80</b> then transmits C<b>1</b> to the appropriate other sponsor station. Sponsor station <b>81</b> obtains C<b>1</b> using its private key, and sponsor station <b>82</b> obtains C<b>1</b> using its private key. At this point, each of the sponsor stations knows C<b>1</b>.
[0135] Sponsor station <b>80</b> encrypts C<b>1</b> with its portion of the user's private key and transmits the same to the user device. Sponsor station <b>81</b> encrypts C<b>1</b> with its portion of the user's private key and transmits the same to the user device. And, sponsor station <b>82</b> encrypts C<b>1</b> with its portion of the user's private key and transmits the same to the user device. The user device then multiplies each of the received encrypted C<b>1</b>s together and then recovers C<b>1</b> using the user's portion of the private key. C<b>1</b> can than be used as a shared secret key between the user and the sponsor stations. Thus, by demonstrating knowledge of C<b>1</b>, the user device can authenticate itself to each of the multiple sponsor stations. The user can then obtain the required signatures from each of the multiple sponsor stations, such communications being protected by C<b>1</b>.
[0136] In a third alternative, which could be called a series alternative, to obtain a signature on a 36 byte hash, a user device transmits the 36 byte hash to a sponsor station <b>80</b>, sponsor station <b>80</b> in this example. That sponsor station signs the hash and forwards it to sponsor station <b>81</b>. Sponsor station <b>81</b> signs the hash and forwards it sponsor station <b>82</b>. Sponsor station <b>82</b> signs the hash and returns it to the user. The user then applies his portion of the private key to the hash and transmits it to a merchant server.
[0137] This second alternative can be modified. The user could first be required to sign the hash and then forward it to sponsor station <b>80</b>. Operations continue at sponsor station <b>80</b> as described above. After sponsor station <b>82</b> signs the hash, the hash would have a complete private portion. The sponsor station <b>82</b> could verify the signature by using the user's public key. This adds an additional element of authentication to the process.
[0138] It will also be recognized by those skilled in the art that, while the invention has been described above in terms of one or more preferred embodiments, it is not limited thereto. Various features and aspects of the above described invention may be used individually or jointly. Further, although the invention has been described in the context of its implementation in a particular environment and for particular purposes, e.g. in providing security for Internet communications, those skilled in the art will recognize that its usefulness is not limited thereto and that the present invention can be beneficially utilized in any number of environments and implementations. Accordingly, the claims set forth below should be construed in view of the full breath and spirit of the invention as disclosed herein.
Contents6
16 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2006078560A2 | Cited by | World Intellectual Property Organization (WIPO) | Search report |
| US10516447B1 | Cited by | United States of America | Applicant |
| US7630493B2 | Cited by | United States of America | Applicant |
| US11245438B1 | Cited by | United States of America | Applicant |
| US10680824B2 | Cited by | United States of America | Applicant |
| US11100511B1 | Cited by | United States of America | Applicant |
| US10965465B2 | Cited by | United States of America | Applicant |
| US10554411B1 | Cited by | United States of America | Applicant |
| US11687930B2 | Cited by | United States of America | Applicant |
| US11297046B2 | Cited by | United States of America | Applicant |
| US11321546B2 | Cited by | United States of America | Applicant |
| US11922417B2 | Cited by | United States of America | Applicant |
| CN109861826A | Cited by | China | Search report |
| US2023291548A1 | Cited by | United States of America | Search report |
| US10657754B1 | Cited by | United States of America | Applicant |
| US8281130B2 | Cited by | United States of America | Search report |
| US10970712B2 | Cited by | United States of America | Applicant |
| US10630653B1 | Cited by | United States of America | Applicant |
| US9401902B2 | Cited by | United States of America | Search report |
| US11699047B2 | Cited by | United States of America | Applicant |
| US11463243B2 | Cited by | United States of America | Applicant |
| US10733645B2 | Cited by | United States of America | Applicant |
| US10862540B1 | Cited by | United States of America | Applicant |
| US2009308530A1 | Cited by | United States of America | Pre-grant |
| US7734045B2 | Cited by | United States of America | Search report |
| US11200563B2 | Cited by | United States of America | Applicant |
| US10467445B1 | Cited by | United States of America | Applicant |
| US11935041B2 | Cited by | United States of America | Applicant |
| US10623272B2 | Cited by | United States of America | Search report |
| US12125021B2 | Cited by | United States of America | Applicant |
| US10505738B1 | Cited by | United States of America | Applicant |
| US11770254B2 | Cited by | United States of America | Applicant |
| US10860814B2 | Cited by | United States of America | Applicant |
| US11373169B2 | Cited by | United States of America | Applicant |
| US11977635B2 | Cited by | United States of America | Search report |
| US11030339B1 | Cited by | United States of America | Applicant |
| US10778437B2 | Cited by | United States of America | Applicant |
| US11232272B2 | Cited by | United States of America | Applicant |
| WO2007088288A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US11961089B2 | Cited by | United States of America | Applicant |
| US11270291B2 | Cited by | United States of America | Applicant |
| US11063979B1 | Cited by | United States of America | Applicant |
| US11658997B2 | Cited by | United States of America | Applicant |
| US10579998B1 | Cited by | United States of America | Applicant |
| US11562358B2 | Cited by | United States of America | Applicant |
| CN112671804A | Cited by | China | Search report |
| US2021374245A1 | Cited by | United States of America | Search report |
| US10623393B1 | Cited by | United States of America | Applicant |
| US2009222658A1 | Cited by | United States of America | Pre-grant |
| US6988209B1 | Cited by | United States of America | Search report |
| US2011099379A1 | Cited by | United States of America | Pre-grant |
| US6499109B1 | Cited by | United States of America | Search report |
| US10701560B1 | Cited by | United States of America | Applicant |
| US12124903B2 | Cited by | United States of America | Applicant |
| US12010238B2 | Cited by | United States of America | Applicant |
| US10535062B1 | Cited by | United States of America | Applicant |
| US10733283B1 | Cited by | United States of America | Applicant |
| US12069178B2 | Cited by | United States of America | Applicant |
| US2017063817A1 | Cited by | United States of America | Pre-grant |
| US11037136B2 | Cited by | United States of America | Applicant |
| US10713649B1 | Cited by | United States of America | Applicant |
| US2018343262A1 | Cited by | United States of America | Search report |
| US10887106B2 | Cited by | United States of America | Applicant |
| US11792001B2 | Cited by | United States of America | Applicant |
| US11997208B2 | Cited by | United States of America | Applicant |
| US10542036B1 | Cited by | United States of America | Applicant |
| US11990955B2 | Cited by | United States of America | Applicant |
| US11694187B2 | Cited by | United States of America | Applicant |
| US12003490B2 | Cited by | United States of America | Applicant |
| US11301848B2 | Cited by | United States of America | Applicant |
| CN109120397A | Cited by | China | Search report |
| US11444775B2 | Cited by | United States of America | Applicant |
| US12041172B2 | Cited by | United States of America | Applicant |
| US7599493B2 | Cited by | United States of America | Search report |
| US11129019B2 | Cited by | United States of America | Applicant |
| US10909527B2 | Cited by | United States of America | Applicant |
| US11341480B2 | Cited by | United States of America | Applicant |
| US8015211B2 | Cited by | United States of America | Search report |
| CN110519046A | Cited by | China | Search report |
| US2022311475A1 | Cited by | United States of America | Applicant |
| US11843700B2 | Cited by | United States of America | Applicant |
| US11610195B2 | Cited by | United States of America | Applicant |
| CN104639516A | Cited by | China | Search report |
| US11632148B2 | Cited by | United States of America | Applicant |
| US11521213B2 | Cited by | United States of America | Applicant |
| US10686603B2 | Cited by | United States of America | Applicant |
| US10832271B1 | Cited by | United States of America | Applicant |
| US11182771B2 | Cited by | United States of America | Applicant |
| US11361302B2 | Cited by | United States of America | Applicant |
| US12062258B2 | Cited by | United States of America | Applicant |
| US11423452B2 | Cited by | United States of America | Applicant |
| CN112287399A | Cited by | China | Search report |
| US10915888B1 | Cited by | United States of America | Applicant |
| US9755825B2 | Cited by | United States of America | Search report |
| US10607214B1 | Cited by | United States of America | Applicant |
| US11233645B2 | Cited by | United States of America | Applicant |
| US11790187B2 | Cited by | United States of America | Applicant |
| US11120453B2 | Cited by | United States of America | Applicant |
| US12026707B2 | Cited by | United States of America | Applicant |
| US8125697B2 | Cited by | United States of America | Applicant |
5 members in 2 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 73911800 | United States of America | A | |
| US20000739118 | – | – | – |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| US2002078345A1 | United States of America | A1 | |
| WO0250677A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US7069435B2 | United States of America | B2 | |
| US2006248333A1 | United States of America | A1 | |
| US7447903B2 | United States of America | B2 |
60 transactions on the USPTO file
Allowed after 2 non-final rejections, 1 final rejection, 1 RCE and 1 appeal.
- Non-final rejections
- 2
- Final rejections
- 1
- RCEs
- 1
- Appeals
- 1
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 12th Year, Large EntityM1553 | M1553 | |
| Entity status set to undiscounted (initial default setting or status change)BIG. | BIG. | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Applicant Has Filed a Verified Statement of Small Entity Status in Compliance with 37 CFR 1.27SMAL | SMAL | |
| Correspondence Address ChangeC.ADB | C.ADB | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Workflow - Drawings FinishedDRWF | DRWF | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Mail Formal Drawings RequiredMN/DR | MN/DR | |
| Formal Drawings RequiredN/DR | N/DR | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Mail Appeals conf. Rej. withdrawnMAPCA | MAPCA | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Pre-Appeals Conference Decision - Rejection WithdrawnAPCA | APCA | |
| Request for Pre-Appeal Conference FiledAP.C | AP.C | |
| Notice of Appeal FiledN/AP | N/AP | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Miscellaneous Incoming LetterLET. | LET. | |
| Response after Final ActionA.NE | A.NE | |
| Mail Examiner Interview Summary (PTOL - 413)MEXIN | MEXIN | |
| Examiner Interview Summary Record (PTOL - 413)EXIN | EXIN | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow incoming amendment IFWWAMD | WAMD | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Correspondence Address ChangeC.AD | C.AD | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| New or Additional Drawing FiledC614 | C614 | |
| Correspondence Address ChangeC.AD | C.AD | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
13 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Fee paymentFPAY | FPAY | |
| Fee payment procedurePAT HOLDER NO LONGER CLAIMS SMALL ENTITY STATUS, ENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: STOL); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Fee payment procedurePAT HOLDER CLAIMS SMALL ENTITY STATUS, ENTITY STATUS SET TO SMALL (ORIGINAL EVENT CODE: LTOS); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| RefundREFUND - PAYMENT OF MAINTENANCE FEE, 4TH YEAR, LARGE ENTITY (ORIGINAL EVENT CODE: R1551); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYREFU | REFU | |
| Fee paymentFPAY | FPAY | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 2002078345
- Publication, EPODOC
- US2002078345
- Application
- 9739118
- Application, DOCDB
- 73911800
- Application, EPODOC
- US20000739118
Titles
- English
- System and method for authentication in a crypto-system utilizing symmetric and asymmetric crypto-keys
Patent term adjustment
- A delay
- +840 daysthe office missed an examination deadline
- Applicant delay
- −156 days
- Net adjustment
- 684 days
Classification
- CPC, 6
- H04L9/0894
- H04L9/0825
- H04L9/085
- H04L9/321
- H04L9/3247
- H04L9/3273
- IPC, 1
- H04L9 32
- USPC, 1
- 713155000