US20060248333A1

Laddered authentication security using split key asymmetric cryptography

Claim Score by NHIP

Read claim 13, the broadest

Abstract

A user has two asymmetric crypto-keys, the first having a first private key and the second having a second private key, both of which are split into a first private key portion corresponding to a password of the user and to a computation. However, the computation of the first private key portion of the first and the second private keys have different levels of complexity. First and second messages from the user encrypted with the first private key portion of, respectively, the first private key and the second private key, are received centrally. A second private key portion of, respectively, the first private key and the second private key is applied to the received first and the received second messages, as applicable, to authenticate the user at, respectively, a first level of authentication security and a second level of authentication security which is greater than the first level.

US20060248333A1, drawing sheet 1
Sheet 1 of 16

Term

Term ended

Projected expiry passed 24 October 2021, 4.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

20 claims: 3 independent, 17 dependent

  1. 1
    A network station for providing multiple different levels of authentication security for a user associated with (i) a first asymmetric crypto-key including a first private key and a first public key, with the first private key split into a first private key portion corresponding to a password of the user and to a first computation having a first level of complexity, and a second private key portion, and (ii) a second asymmetric crypto-key including a second private key and a second public key, with the second private key split into a first private key portion corresponding to the password and a second computation having a second level of complexity greater than the first level of complexity, and a second private key portion, the server comprising:a communications network interface configured to receive a first message from the user encrypted with the first private key portion of the first private key, and a second message from the user encrypted with the first private key portion of the second private key;and a processor configured to apply (i) the second private key portion of the first private key to the received first message, to authenticate the first user at a first level of authentication security, and (ii) the second private key portion of the second private key to the received second message, to authenticate the second user at a second level of authentication security which is greater than the first level of authentication security.
  2. 13
    Broadest claimClaim Score 28, narrow(NHIP)A method for providing multiple different levels of authentication security for a user associated with (i) a first asymmetric crypto-key including a first private key and a first public key, with the first private key split into a first private key portion corresponding to a password of the user and to a first computation having a first level of complexity, and a second private key portion, and (ii) a second asymmetric crypto-key including a second private key and a second public key, with the second private key split into a first private key portion corresponding to the password and a second computation having a second level of complexity greater than the first level of complexity, and a second private key portion, the method comprising:centrally receiving a first message from the user encrypted with the first private key portion of the first private key, and a second message from the user encrypted with the first private key portion of the second private key;applying the second private key portion of the first private key to the received first message, to authenticate the user at a first level of authentication security;and applying the second private key portion of the second private key to the received second message, to authenticate the user at a second level of authentication security which is greater than the first level of authentication security.
  3. 17
    A networked system for providing multiple different levels of authentication security for a user having (i) an associated first asymmetric crypto-key including a first private key and a first public key, with the first private key split into a first private key portion corresponding to a password of the user and a first computation having a first level of complexity, and a second private key portion, and (ii) an associated second asymmetric crypto-key including a second private key and a second public key, with the second private key split into a first private key portion corresponding to the password and a second computation having a second level of complexity greater than the first level of complexity, and a second private key portion, the system comprising:a first network device, representing the user, configured to transmit a first message encrypted with the first private key portion of the first private key, and a second message encrypted with the first private key portion of the second private key;and a second network device, representing an authenticating entity, configured to apply (i) the second private key portion of the first private key to the transmitted first message, to authenticate the user at a first level of authentication security, and (ii) the second private key portion of the second private key to the transmitted second message, to authenticate the user at a second level of authentication security which is greater than the first level of authentication security.