US20080098464A1

Two-channel challenge-response authentication method in random partial shared secret recognition system

Claim Score by NHIP

Read claim 37, the broadest

Abstract

Random partial shared secret recognition is combined with using more than one communication channel between server-side resources and two logical or physical client-side data processing machines. After a first security tier, a first communication channel is opened to a first data processing machine on the client side. The session proceeds by delivering an authentication challenge, identifying a random subset of an authentication credential, to a second data processing machine on the client side using a second communication channel. Next, the user enters an authentication response in the first data processing machine, based on a random subset of the authentication credential. The authentication response is returned to the server side on the first communication channel for matching. The authentication credential can be a one-session-only credential delivered to the user for one session, or a static credential used many times.

US20080098464A1, drawing sheet 1
Sheet 1 of 40

Term

2.9 yearsto projected expiry

Projected expiry 4 September 2029, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

56 claims: 11 independent, 45 dependent

  1. 1
    An interactive, computer implemented method for execution by server side computer resources in a client-server system to authenticate a client having access to a first data processing machine and a second data processing machine, comprising:maintaining a database in the server side computer resources including authentication credentials for clients, authentication credentials for a particular client in the database including a client identifier;establishing a first communication channel including a connection to the first data processing machine;receiving an input client identifier from the first data processing machine via one or more data communications on the first communication channel;verifying the input client identifier, and after said verifying, initiating a current authentication session and providing an authentication credential for the current authentication session;establishing a second communication channel including a connection to the second data processing machine;sending a session authentication challenge for the current authentication session to the second data processing machine via one or more data communications on the second communication channel, the session authentication challenge identifying a subset of the authentication credential;accepting an authentication response from the first data processing machine via one or more data communications on the first communication channel;and determining whether the authentication response matches the subset of the authentication credential identified by the session authentication challenge.
  2. 12
    An interactive, computer implemented method for execution by server-side computer resources in a client-server system to authenticate a client having access to a first data processing machine and a second data processing machine, comprising:maintaining a database in the server-side computer resources including authentication credentials for clients, authentication credentials for a particular client in the database including a client identifier;establishing a first communication channel including a connection to the first data processing machine;receiving an input client identifier from the first data processing machine via one or more data communications on the first communication channel;verifying the input client identifier, and after said verifying, initiating a current authentication session, and based on a shared-secret ordered set of data fields in a memory, where the data fields in the ordered set include field contents comprising one or more storage elements represented by corresponding graphical objects on a graphical menu, presenting to the client via one or more data communications on the first communication channel an input construct for entry of field contents of said random subset of data fields, the input construct including a plurality of content entry data fields, and at least one instance of the graphical menu for selecting one or more graphical objects to cause entry of corresponding storage units into respective content entry data fields in the plurality of content entry data fields;establishing a second communication channel including a connection to the second data processing machine;sending a session authentication challenge for the current authentication session to the second data processing machine via one or more data communications on the second communication channel, the session authentication challenge identifying positions in said ordered set of a random subset of data fields from said ordered set, including one position in the random subset for each of the plurality of content entry data fields;accepting an authentication response from the first data processing machine via one or more data communications on the first communication channel based on entries in the plurality of content entry data fields;and determining whether the authentication response matches the subset of the authentication credential identified by the session authentication challenge.
  3. 15
    An interactive, computer implemented method for execution by server-side computer resources in a client-server system to authenticate a client having access to a first data processing machine and a second data processing machine, comprising:maintaining a database in the server-side computer resources including authentication credentials for clients, authentication credentials for a particular client in the database including a client identifier;establishing a first communication channel including a connection to the first data processing machine;receiving an input client identifier from the first data processing machine via one or more data communications on the first communication channel;verifying the input client identifier, and after said verifying, initiating a current authentication session and providing an authentication credential for the current authentication session, the authentication credential comprising a data set in a memory, the data set including a plurality of data fields having respective positions in said data set and having field contents identifying a plurality of said pre-defined locations having an order along a path known to the client on the frame of reference;presenting to the client via one or more data communications on the first communication channel an input construct for entry of field contents of said random subset of data fields, the input construct including a plurality of content entry data fields, and at least one an instance of said graphical representation of the frame of reference configured as a graphical menu for selecting one or more graphical objects to cause entry of corresponding storage units identifying coordinates on the frame of reference into respective content entry data fields in the plurality of content entry data fields;establishing a second communication channel including a connection to the second data processing machine;sending a session authentication challenge for the current authentication session to the second data processing machine via one or more data communications on the second communication channel, the session authentication challenge identifying positions of a random subset of data fields in said data set, including more than one position in the random subset for at least one content entry data field of the plurality of content entry data fields;accepting an authentication response from the first data processing machine via one or more data communications on the first communication channel, the authentication response being based on selection of graphical objects for each content entry data field, using the graphical menu associated with the plurality of content entry data fields on said input construct, including selection of more than one graphical object for at least one of the plurality of content entry data fields;and determining whether the authentication response matches the subset of the authentication credential identified by the session authentication challenge.
  4. 19
    A client-server authentication system to authenticate a client having access to a first data processing machine and a second data processing machine, comprising:data processing resources, including one or more processors, memory and a communication interface;data stored in said memory defining including authentication credentials for clients, authentication credentials for a particular client in the database including a client identifier;the data processing resources including executable instructions stored in said memory adapted for execution by the processor, including logic to establish a first communication channel including a connection to the first data processing machine;receive an input client identifier from the first data processing machine via one or more data communications on the first communication channel;verify the input client identifier, and after said verifying, initiating a current authentication session and providing an authentication credential for the current authentication session;establish a second communication channel including a connection to the second data processing machine;send a session authentication challenge for the current authentication session to the second data processing machine via one or more data communications on the second communication channel, the session authentication challenge identifying a random subset of the authentication credential;accept an authentication response from the first data processing machine via one or more data communications on the first communication channel;and determine whether the authentication response matches the random subset of the authentication credential identified by the session authentication challenge.
  5. 30
    A client-server authentication system to authenticate a client having access to a first data processing machine and a second data processing machine, comprising:data processing resources, including one or more processors, memory and a communication interface;data stored in said memory defining including authentication credentials for clients, authentication credentials for a particular client in the database including a client identifier;the data processing resources including executable instructions stored in said memory adapted for execution by the processor, including logic to maintain a database in the server-side computer resources including authentication credentials for clients, authentication credentials for a particular client in the database including a client identifier;establish a first communication channel including a connection to the first data processing machine;receive an input client identifier from the first data processing machine via one or more data communications on the first communication channel;verify the input client identifier, and after said verifying, to initiate a current authentication session, and based on a shared-secret ordered set of data fields in a memory, where the data fields in the ordered set include field contents comprising one or more storage elements represented by corresponding graphical objects on a graphical menu, to present to the client via one or more data communications on the first communication channel an input construct for entry of field contents of said random subset of data fields, the input construct including a plurality of content entry data fields, and at least one instance of the graphical menu for selecting one or more graphical objects to cause entry of corresponding storage units into respective content entry data fields in the plurality of content entry data fields;establish a second communication channel including a connection to the second data processing machine;send a session authentication challenge for the current authentication session to the second data processing machine via one or more data communications on the second communication channel, the session authentication challenge identifying positions in said ordered set of a random subset of data fields from said ordered set, including one position in the random subset for each of the plurality of content entry data fields;accept an authentication response from the first data processing machine via one or more data communications on the first communication channel based on entries in the plurality of content entry data fields;and determine whether the authentication response matches the subset of the authentication credential identified by the session authentication challenge.
  6. 33
    A client-server authentication system to authenticate a client having access to a first data processing machine and a second data processing machine, comprising:data processing resources, including one or more processors, memory and a communication interface;data stored in said memory defining including authentication credentials for clients, authentication credentials for a particular client in the database including a client identifier;the data processing resources including executable instructions stored in said memory adapted for execution by the processor, including logic to maintain a database in the server-side computer resources including authentication credentials for clients, authentication credentials for a particular client in the database including a client identifier;establish a first communication channel including a connection to the first data processing machine;receive an input client identifier from the first data processing machine via one or more data communications on the first communication channel;verify the input client identifier, and after said verifying, to initiate a current authentication session and to provide an authentication credential for the current authentication session, the authentication credential comprising a data set in a memory, the data set including a plurality of data fields having respective positions in said data set and having field contents identifying a plurality of said pre-defined locations having an order along a path known to the client on the frame of reference;present to the client via one or more data communications on the first communication channel an input construct for entry of field contents of said random subset of data fields, the input construct including a plurality of content entry data fields, and at least one an instance of said graphical representation of the frame of reference configured as a graphical menu for selecting one or more graphical objects to cause entry of corresponding storage units identifying coordinates on the frame of reference into respective content entry data fields in the plurality of content entry data fields;establish a second communication channel including a connection to the second data processing machine;send a session authentication challenge for the current authentication session to the second data processing machine via one or more data communications on the second communication channel, the session authentication challenge identifying positions of a random subset of data fields in said data set, including more than one position in the random subset for at least one content entry data field of the plurality of content entry data fields;accept an authentication response from the first data processing machine via one or more data communications on the first communication channel, the authentication response being based on selection of graphical objects for each content entry data field, using the graphical menu associated with the plurality of content entry data fields on said input construct, including selection of more than one graphical object for at least one of the plurality of content entry data fields;and determine whether the authentication response matches the subset of the authentication credential identified by the session authentication challenge.
  7. 37
    Broadest claimClaim Score 40, average(NHIP)A computer program stored on a computer readable medium and executable by the computer to authenticate a client having access to a first data processing machine and a second data processing machine, comprising instructions to:establish a first communication channel including a connection to the first data processing machine;receive an input client identifier from the first data processing machine via one or more data communications on the first communication channel;verify the input client identifier, and after said verifying, initiating a current authentication session and providing an authentication credential for the current authentication session;establish a second communication channel including a connection to the second data processing machine;send a session authentication challenge for the current authentication session to the second data processing machine via one or more data communications on the second communication channel, the session authentication challenge identify a random subset of the authentication credential;accept an authentication response from the first data processing machine via one or more data communications on the first communication channel;and determine whether the authentication response matches the random subset of the authentication credential identified by the session authentication challenge.
  8. 48
    A computer program stored on a computer readable medium and executable by the computer to authenticate a client having access to a first data processing machine and a second data processing machine, comprising instructions to:maintain a database in the server-side computer resources including authentication credentials for clients, authentication credentials for a particular client in the database including a client identifier;establish a first communication channel including a connection to the first data processing machine;receive an input client identifier from the first data processing machine via one or more data communications on the first communication channel;verify the input client identifier, and after said verifying, to initiate a current authentication session, and based on a shared-secret ordered set of data fields in a memory, where the data fields in the ordered set include field contents comprising one or more storage elements represented by corresponding graphical objects on a graphical menu, to present to the client via one or more data communications on the first communication channel an input construct for entry of field contents of said random subset of data fields, the input construct including a plurality of content entry data fields, and at least one instance of the graphical menu for selecting one or more graphical objects to cause entry of corresponding storage units into respective content entry data fields in the plurality of content entry data fields;establish a second communication channel including a connection to the second data processing machine;send a session authentication challenge for the current authentication session to the second data processing machine via one or more data communications on the second communication channel, the session authentication challenge identifying positions in said ordered set of a random subset of data fields from said ordered set, including one position in the random subset for each of the plurality of content entry data fields;accept an authentication response from the first data processing machine via one or more data communications on the first communication channel based on entries in the plurality of content entry data fields;and determine whether the authentication response matches the subset of the authentication credential identified by the session authentication challenge.
  9. 51
    A computer program stored on a computer readable medium and executable by the computer to authenticate a client having access to a first data processing machine and a second data processing machine, comprising instructions to:maintain a database in the server-side computer resources including authentication credentials for clients, authentication credentials for a particular client in the database including a client identifier;establish a first communication channel including a connection to the first data processing machine;receive an input client identifier from the first data processing machine via one or more data communications on the first communication channel;verify the input client identifier, and after said verifying, to initiate a current authentication session and to provide an authentication credential for the current authentication session, the authentication credential comprising a data set in a memory, the data set including a plurality of data fields having respective positions in said data set and having field contents identifying a plurality of said pre-defined locations having an order along a path known to the client on the frame of reference;present to the client via one or more data communications on the first communication channel an input construct for entry of field contents of said random subset of data fields, the input construct including a plurality of content entry data fields, and at least one an instance of said graphical representation of the frame of reference configured as a graphical menu for selecting one or more graphical objects to cause entry of corresponding storage units identifying coordinates on the frame of reference into respective content entry data fields in the plurality of content entry data fields;establish a second communication channel including a connection to the second data processing machine;send a session authentication challenge for the current authentication session to the second data processing machine via one or more data communications on the second communication channel, the session authentication challenge identifying positions of a random subset of data fields in said data set, including more than one position in the random subset for at least one content entry data field of the plurality of content entry data fields;accept an authentication response from the first data processing machine via one or more data communications on the first communication channel, the authentication response being based on selection of graphical objects for each data entry window, using the graphical menu associated with the plurality of content entry data fields on said input construct, including selection of more than one graphical object for at least one of the plurality of content entry data fields;and determine whether the authentication response matches the subset of the authentication credential identified by the session authentication challenge.
  10. 55
    A method for authenticating an on-line user to a server comprising:(a) choosing prior to an authentication session a client identifier, such as a user name or a user ID, and a shared secret between a user and a server such as a PIN or password, a graphical path on a reference grid of fields, or graphical pattern of data fields with content;(b) creating prior to an authentication session a record of a client identifier and a shared secret in a database or a directory service connected to a server, including a shared secret and information such as any of the following: a PIN or password made of alphanumeric characters and special marks, each of them having in the record consecutive position numbers along the PIN or password, a graphical path on a reference grid of fields with each field along a graphical path having in the record fixed field's coordinates and a field's consecutive position number, or a graphical pattern of fields with data field content having in the record each data field contents associated with a consecutive field position number in the ordered set of graphical pattern data field contents;(c) entering the client identifier into the graphical user interface at any client computing platform connected to the server and sending it to the server to begin an authentication session, and (d) verifying validity of a client identifier at the server, and (e) generating at the server a one time authentication challenge such as any of the following: a session only random subset of consecutive alphanumeric character and special mark position numbers in PIN or password, a session only random subset of consecutive field position numbers along the graphical path, or a session only random subset of consecutive data field content position numbers in the graphical pattern;(f) generating at the server a combination of fields containing graphical constructs that match the one time authentication challenge generated at the server for the same authentication session and would allow the user to enter a one time authentication response;and (g) sending a one time authentication challenge by the server to a personalized “what user has” hardware device, such as a mobile phone or a software client such as email, using another communication channel than the communication channel connecting the user's graphical user interface and the server, and (h) sending by the server to the user's graphical user interface a combination of fields containing graphical constructs that match the one time authentication challenge generated at the server for the same authentication session and would allow the user to enter a one time authentication response, and (i) entering into the user's graphical user interface the one time authentication response based on the cognitive association of a one time authentication challenge and the user's secret shared with the server, and (j) sending the one time authentication response from the user's graphical user interface to the server, and (k) verifying at the server the one time authentication response, and (l) sending to the user's graphical user interface a positive or negative user authentication session result.
  11. 56
    A method for authenticating an on-line user to a server comprising:(a) choosing prior to an authentication session a client identifier, such as a user name or a user ID, and a shared secret between a user and a server such as a PIN or password, a graphical path on a reference grid of fields, or graphical pattern of data fields with content;(b) creating prior to or during the authentication session, a session authentication credential such as: a PIN or password made of alphanumeric characters and special marks, each of them having in the record consecutive position numbers along the PIN or password, a graphical path on a reference grid of fields with each field along a graphical path having in the record fixed field's coordinates and a field's consecutive position number, or a graphical pattern of fields with data field content having in the record each data field contents associated with a consecutive field position number in the ordered set of graphical pattern data field contents;(c) entering the client identifier into the graphical user interface at any client computing platform connected to the server and sending it to the server to begin an authentication session, and (d) verifying validity of a client identifier at the server, and (e) generating at the server a one time authentication challenge such as any of the following: a session only random subset of consecutive alphanumeric character and special mark position numbers in PIN or password, a session only random subset of consecutive field position numbers along the graphical path, or a session only random subset of consecutive data field content position numbers in the graphical pattern;(f) generating at the server a combination of fields containing graphical constructs that match the one time authentication challenge generated at the server for the same authentication session and would allow the user to enter a one time authentication response;and (g) sending a one time authentication challenge by the server to a personalized “what user has” hardware device, such as a mobile phone or a software client such as email, using another communication channel than the communication channel connecting the user's graphical user interface and the server, and (h) sending by the server to the user's graphical user interface the session authentication credential, and a combination of fields containing graphical constructs that match the one time authentication challenge generated at the server for the same authentication session and would allow the user to enter a one time authentication response, and (i) entering into the user's graphical user interface the one time authentication response based on the cognitive association of a one time authentication challenge and the user's secret shared with the server, and (j) sending the one time authentication response from the user's graphical user interface to the server, and (k) verifying at the server the one time authentication response, and (l) sending to the user's graphical user interface a positive or negative user authentication session result.