US20030191964A1

Method for verifying the identity of a user for session authentication purposes during web navigation

Claim Score by NHIP

Read claim 10, the broadest

Abstract

A network-based software application for enabling remote authentication of a user during a network session has a server portion for serving session validation information and additional user information when queried, a client portion for configuring and submitting parameters constraining what and how data is to be shared with a querying entity or entities, and a distributed portion for distribution and application at various connected network nodes for enabling those nodes to recognize and interact with the server portion. The application is characterized in that the server portion generates a temporary session token after a first successful authentication by the user at a web site during a network session, the token cached at the host machine of the server portion and at the user's machine or proxy machine and wherein upon navigation by the user to a next web site or form requiring secure authentication, the token is used to identify the user and a remote call is used to validate the user session instead of requiring manual authentication procedures.

US20030191964A1, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 23 June 2024, 2.3 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

18 claims: 2 independent, 16 dependent

  1. 1
    A network-based software application for enabling remote authentication of a user during a network session comprising:a server portion for serving session validation information and additional user information when queried;a client portion for configuring and submitting parameters constraining what and how data is to be shared with a querying entity or entities;and a distributed portion for distribution and application at various connected network nodes for enabling those nodes to recognize and interact with the server portion;characterized in that the server portion generates a temporary session token after a first successful authentication by the user at a web site during a network session, the token cached at the host machine of the server portion and at the user's machine or proxy machine and wherein upon navigation by the user to a next web site or form requiring secure authentication, the token is used to identify the user and a remote call is used to validate the user session instead of requiring manual authentication procedures.
  2. 10
    Broadest claimClaim Score 64, broad(NHIP)A method for verifying an on-line user remotely comprising steps of:(a) generating a token for a user session the token containing at least one set of authentication data just entered to gain access to a first secure site or function during the session;(b) storing the generated token at the user machine or proxy machine and at the issuer site;(c) delivering the generated token from the user to the first site;(d) recognizing the generated token at the site and using the token information to validate the user as the user navigates the site;(e) delivering the token to a new site navigated to wherein the new site is hosted by a new sever;and (f) recognizing the generated token at the new site and using the token information to validate the user as the user navigates the new site.